You decide where it lands
Rules decide what fires. Routing decides where it goes.
Detection is the product's judgment; where an alert lands is yours. The Alerting console lets an operator tune the packaged rules, route by severity, and record every exception — a save goes live on the engine's next evaluation cycle, with no service restart. Suppressions are exceptions on the record, never silent muting.
- Rules & routing — enable, disable and tune rules from the console; route by severity with quiet-hours, and re-notify an unacknowledged alert on an interval instead of firing once and forgetting.
- Suppressions on the record — silence a rule for a host pattern for a bounded window; if the rule evidences a control like NIST AU-6, the console requires a written justification and logs it as an explicit risk acceptance, so a silenced control is never an invisible gap.
- Snooze always expires — nothing gets silenced indefinitely by accident.
- Delivery health — see whether the SMTP relay or webhook actually accepted the last dispatch, so you learn about a broken channel from the console, not from a missed incident.