Notifications
Notifications post CyberOptix CTEM Platform activity into Slack or Microsoft Teams, so people hear about things without logging in to check.
Connecting a channel
Configure Slack or Teams under Administration → Notifications. Each platform is connected once per organization and posts into the channels you nominate.
Connections can be enabled and disabled without being removed, which is what you want for a maintenance window or a noisy period - disabling keeps the configuration for when you turn it back on.
Categories
Rather than one firehose, notifications are split by category, and each category is routed independently. That is the feature worth using: different categories have different audiences and wildly different volumes.
| Category | Covers |
|---|---|
| Alerts | Security alerts needing attention |
| Vulnerability management | New and changed findings |
| DevSecOps | Application and code security |
| SIEM | Security operations activity |
| Dark web | Identity exposure and breach data |
| Purple team | Assessment and validation activity |
| Executive | Summary-level activity |
| Weekly updates | Periodic digest |
Routing them well
The mistake is sending everything to one channel. It works for a week, then the channel becomes unreadable and people mute it - at which point the alerts you actually cared about are muted too.
A shape that survives:
- Alerts to the channel your responders actually watch, and nothing else there.
- Vulnerability management and DevSecOps to the teams that fix them.
- Executive and weekly updates to a low-traffic channel people read deliberately.
- Dark web wherever identity exposure gets handled, which is often not the same team.
If a category is noisy enough that people mute it, route it somewhere quieter rather than turning it off. Muting is invisible; disabling is not.
Notifications and severity
Notifications are a delivery mechanism, not a filter. If a category is too noisy, the usual fix is upstream - tuning detection rules, or raising the emission floor so low-severity matches never become alerts. See Detection engineering.
API
The endpoints behind this section are in the API reference.
Next
- Detection engineering - reducing noise at source
- Monitor and respond - what alerts look like in the product
- Webhooks - why these are not outbound webhooks