Alerts and notifications
When the reputation feed pushes a new detection for one of your monitored domains, Umbra stores the exposure and raises an alert. This page covers where alerts land and how to route them.
:::caution Free plan Free includes no alerts at all — no in-console notifications, no email, no Slack, no webhooks. The Alerts page is a locked upsell, and the bell shows a lock instead of a badge. Alerting starts on Pro. See Plans and billing. :::
The bell and the Alerts feed
- The bell in the header shows the unread count and the most recent items, with mark-all-read.
- Alerts (in the sidebar's ENTITIES section) is the full feed of new-exposure notifications, each linking to the exposure behind it.
Org-wide routing — the Notifications page
The Notifications page (sidebar ACCOUNT section) configures where events go, for the whole organization:
- Rules — a matrix of event × channel, grouped by category: tick which events reach which channels. Events include new-exposure and critical-exposure detections (a detection is critical when the feed's risk band for it is high or critical), domain verifications, and team invites.
- Channels — the destinations: Slack, webhook, and email. A default "Account email" channel pointing at the organization creator's address is seeded on signup, routed for every event — so Pro alerting works before you configure anything.
Routing is org-wide, not per-user: one matrix describes how your organization is notified, and admins keep it in one place.
What reaches you where
| Surface | What arrives |
|---|---|
| Bell + Alerts feed | every routed in-console event, with unread tracking |
| Email channel | the same events, delivered to the channel's address |
| Slack channel | event messages posted to the configured Slack destination |
| Webhook channel | event payloads POSTed to your endpoint, for your own automation |
The whole routing block is Pro-locked on Free — Free has no alerts, so there is nothing to route.