An alert rule says what to watch, how far ahead to warn, and where to send it. The scheduler checks every organisation each day at its send hour — 08:00 in the organisation's timezone by default, changeable in Settings.
Lead days
A rule's lead days are the countdown points it warns at — for example 90, 30, 7 and 1. On each scan the rule fires for the nearest point the countdown has passed, and only that one. An obligation added five days before it expires, under a 90/30/7/1 rule, alerts once at 7 days — not three times at once because it technically passed 90 and 30 as well.
Each point fires once per deadline. If the scan runs twice, or a delivery is retried, you still get one alert.
Filters
A rule can be narrowed by criticality, obligation type, category, site and framework. Clauses combine: a rule for two sites and critical assets means critical assets at either site. An empty filter watches everything.
Severity
- Critical — anything overdue, and anything on a critical asset.
- Warning — 7 days or fewer, and anything on a high-criticality asset.
- Info — everything else.
Escalation
A critical alert that has reached its due date and has not been acknowledged is sent again, at most once a day, until someone acknowledges it. Acknowledging is a technician's action from the Alerts screen, and it is recorded with the person's name.