Skip to main content
Back to Help Center
NEW

Real-Time Compliance Alerts

Instant Slack and email notifications for compliance events

Instant Slack NotificationsEmail AlertsSeverity RoutingCustom Rules

Why Real-Time Alerts Matter for CCO/CPO

72-Hour GDPR Deadline

Data breaches require notification to authorities within 72 hours. Instant alerts ensure you never miss a deadline.

Control Test Failures

Immediate notification when SOC 2/ISO 27001 control tests fail. Fix issues before auditors find them.

Unusual Activity

Detect abnormal file processing patterns that may indicate insider threats or compromised accounts.

4 Alert Types Available

High-Risk File Processing

high_risk_files
CRITICAL

Triggers when files with GPS location data, personal identifiers, or critical-risk metadata are processed

Example: JPEG with GPS coordinates detected - potential location exposure

Unusual Processing Activity

unusual_activity
HIGH

Triggers when processing volume exceeds 5x normal hourly average (minimum 50 files)

Example: User processed 500 files in 1 hour (normal: 50/hour)

Compliance Policy Violation

compliance_breach
HIGH

Triggers when data handling policies are violated or retention limits exceeded

Example: Data retention policy exceeded for customer records

Usage Quota Exceeded

quota_exceeded
MEDIUM

Triggers when plan usage limits are exceeded

Example: Monthly file processing quota reached (5000/5000)

Setting Up Slack Notifications

1

Create Slack Webhook

  1. Go to api.slack.com/apps
  2. Click "Create New App" → "From scratch"
  3. Name it "Compliance Alerts" and select your workspace
  4. Under "Features" → "Incoming Webhooks" → Enable
  5. Click "Add New Webhook to Workspace"
  6. Select the channel (e.g., #compliance-alerts)
  7. Copy the Webhook URL
2

Configure in Platform

  1. Navigate to Organization Settings → Integrations
  2. Find "Slack Integration" section
  3. Paste your Webhook URL
  4. Select notification types (alerts, processing events)
  5. Click "Test Webhook" to verify
  6. Save your settings
3

Create Alert Rule with Slack

  1. Go to Compliance → Alerts
  2. Click "Create Alert Rule"
  3. Select trigger type and severity
  4. Under Notification Channels, check "Slack"
  5. Add email recipients as backup
  6. Set cooldown period (recommended: 15-60 minutes)
  7. Save the rule

Pro Tip: Channel Strategy

Create separate Slack channels for different severities: #compliance-critical (critical only), #compliance-alerts (high + medium), #compliance-notifications (all). Route alerts accordingly.

Setting Up Email Notifications

When Creating an Alert Rule:

  1. Under "Notification Channels", check "Email"
  2. Add recipient email addresses (multiple allowed)
  3. Recipients receive instant email when alert triggers
  4. Email includes: Alert title, message, severity, dashboard link

Best Practice: Escalation Chain

For CRITICAL alerts, add multiple recipients in order of escalation:analyst@company.com, cpo@company.com, ceo@company.com

Severity-Based Routing Guide

SeverityResponse TimeRecommended ChannelsCooldown
CRITICAL< 15 minutesSlack + Email + SMS (webhook)5 minutes
HIGH< 1 hourSlack + Email15 minutes
MEDIUM< 4 hoursEmail + Dashboard60 minutes
LOWNext business dayDashboard only240 minutes

Troubleshooting Common Issues

Slack notifications not arriving

  • Verify webhook URL is correct and active
  • Check if Slack app has proper permissions
  • Ensure "slack" is in notificationChannels for the alert rule
  • Check organization settings for slackWebhookUrl

Too many alerts (alert fatigue)

  • Increase cooldown period (recommended: 60+ minutes for non-critical)
  • Adjust trigger conditions to be more specific
  • Use severity-based routing to reduce noise
  • Consider dashboard-only for LOW severity

Alerts not triggering when expected

  • Verify alert rule is active (isActive: true)
  • Check if cooldown period has passed since last trigger
  • Review trigger conditions match the event
  • Check user has permission to trigger alerts

Email notifications in spam

  • Whitelist noreply@scrubmetadata.com in email client
  • Add to contacts list
  • Check spam/junk folder
  • Verify recipient email is correct