Skip to content

Notifications

When users take actions in the platform — creating risks or incidents, updating fields, leaving comments — the system records events behind the scenes. A background process runs on a regular interval, collects pending events, and converts them into notifications for the relevant subscribers.

Subscribers are notified when an item first reaches a severity or urgency they follow, or is assigned a threat objective they follow — whether that happens when the item is created, or later when an existing risk or incident is scored or re-tagged.

Category Notification Types
Risk by urgency New Low Risk, New Medium Risk, New High Risk, New Critical Risk
Incident by severity New Severity 1 Incident, New Severity 2 Incident, New Severity 3 Incident
Incident by threat objective New Fraud Incident, New Extortion Incident, New Sabotage Incident, New Data Disclosure Incident, New Customer Targeting Incident, New Resource Hijacking Incident
Batch creation Risks Created, Incidents Created
Notification Type Trigger
Assigned Risk You are assigned to a risk
Assigned Incident You are assigned to an incident
Mentioned Someone @-mentions you in a comment on a risk or incident
Invited to Organization You are invited to join an organization
Notification Type Trigger
Risk Changed A risk you follow is updated, including new comments
Incident Changed An incident you follow is updated, including new comments

Mentions have their own delivery rules — see User Mentions.

User-level notification preferences are configured per user in Settings > Notifications.

User notification preferences page showing notification types with Platform and Email checkboxes
  • For each notification type, choose whether to receive it via Platform (in-app notification center), Email, or both.
  • Org-wide types — subscribe once and get notified about all matching items. For example, subscribing to “New Severity 1 Incident” delivers a notification every time an incident reaches SEV-1 in your organization.
  • Item-specific types — you must be following a specific risk or incident to receive change and comment notifications for it.
  • You start following an item when you follow it explicitly, when you are assigned to it, or when an incident is tagged with a threat objective you subscribe to. Commenting on an item, or being mentioned in one, does not start following it.
  • If no preferences are set, notifications default to in-platform delivery.

Org-level notifications deliver to shared Slack or Teams channels and are configured by admins. See Org-Level Notifications for setup instructions.