Skip to main content

Alerts and notifications

When the reputation feed pushes a new detection for one of your monitored domains, Umbra stores the exposure and raises an alert. This page covers where alerts land and how to route them.

:::caution Free plan Free includes no alerts at all — no in-console notifications, no email, no Slack, no webhooks. The Alerts page is a locked upsell, and the bell shows a lock instead of a badge. Alerting starts on Pro. See Plans and billing. :::

The bell and the Alerts feed

  • The bell in the header shows the unread count and the most recent items, with mark-all-read.
  • Alerts (in the sidebar's ENTITIES section) is the full feed of new-exposure notifications, each linking to the exposure behind it.

Org-wide routing — the Notifications page

The Notifications page (sidebar ACCOUNT section) configures where events go, for the whole organization:

  • Rules — a matrix of event × channel, grouped by category: tick which events reach which channels. Events include new-exposure and critical-exposure detections (a detection is critical when the feed's risk band for it is high or critical), domain verifications, and team invites.
  • Channels — the destinations: Slack, webhook, and email. A default "Account email" channel pointing at the organization creator's address is seeded on signup, routed for every event — so Pro alerting works before you configure anything.

Routing is org-wide, not per-user: one matrix describes how your organization is notified, and admins keep it in one place.

What reaches you where

SurfaceWhat arrives
Bell + Alerts feedevery routed in-console event, with unread tracking
Email channelthe same events, delivered to the channel's address
Slack channelevent messages posted to the configured Slack destination
Webhook channelevent payloads POSTed to your endpoint, for your own automation

The whole routing block is Pro-locked on Free — Free has no alerts, so there is nothing to route.