Skip to main content

Notifications

Notifications post CyberOptix CTEM Platform activity into Slack or Microsoft Teams, so people hear about things without logging in to check.

Connecting a channel​

Configure Slack or Teams under Administration → Notifications. Each platform is connected once per organization and posts into the channels you nominate.

Connections can be enabled and disabled without being removed, which is what you want for a maintenance window or a noisy period - disabling keeps the configuration for when you turn it back on.

Categories​

Rather than one firehose, notifications are split by category, and each category is routed independently. That is the feature worth using: different categories have different audiences and wildly different volumes.

CategoryCovers
AlertsSecurity alerts needing attention
Vulnerability managementNew and changed findings
DevSecOpsApplication and code security
SIEMSecurity operations activity
Dark webIdentity exposure and breach data
Purple teamAssessment and validation activity
ExecutiveSummary-level activity
Weekly updatesPeriodic digest

Routing them well​

The mistake is sending everything to one channel. It works for a week, then the channel becomes unreadable and people mute it - at which point the alerts you actually cared about are muted too.

A shape that survives:

  • Alerts to the channel your responders actually watch, and nothing else there.
  • Vulnerability management and DevSecOps to the teams that fix them.
  • Executive and weekly updates to a low-traffic channel people read deliberately.
  • Dark web wherever identity exposure gets handled, which is often not the same team.

If a category is noisy enough that people mute it, route it somewhere quieter rather than turning it off. Muting is invisible; disabling is not.

Notifications and severity​

Notifications are a delivery mechanism, not a filter. If a category is too noisy, the usual fix is upstream - tuning detection rules, or raising the emission floor so low-severity matches never become alerts. See Detection engineering.

API​

The endpoints behind this section are in the API reference.

Next​