Alert Center

Brings the alerts from the tools you already have into one feed, translated into language you can act on without being technical.

Last reviewed:

The alerts your tools already generate usually live in separate consoles nobody opens. The problem is rarely a shortage of alerts: it is that they are scattered and written for specialists.

What it measures

Nothing on its own — and that is worth understanding up front. This module collects what other tools detect, brings it into a single feed, sorts it by severity, and rewrites it in plain language so someone on the business side can decide what to do.

How to set it up

The module does nothing until you connect at least one source. Three connect today:

SourceWhat you need
Generic firewallA webhook URL the platform generates and you configure in your firewall.
WordPress siteThe same webhook mechanism, from your security plugin.
CloudflareYour account email, the Zone ID, and an API token with read-only Zone → Analytics → Read permission.

Give the Cloudflare token only the analytics read permission listed above. It needs nothing more, and a token with more permissions than necessary is a risk not worth taking.

How to read the result

Each alert arrives with a severity (Low, Medium, High, or Critical) and a status you control: Open, Acknowledged, Resolved, or False positive. The summary at the top separates open criticals and highs from everything else, because those are the only two numbers that justify interrupting what you were doing.

Under each alert's title there is a plain-language explanation of what it means and why it matters. If you need the raw data exactly as the original tool sent it, the technical detail is still on the same screen — tucked away, not up front.

What to do with an alert

  • Acknowledge — you have seen it and you are on it. This is what stops two people from working the same alert.
  • Resolve — the underlying problem is fixed, not just the alert closed.
  • False positive — the tool got it wrong. Mark it as such rather than resolving it: it is different information and it is worth keeping straight in the history.
  • Escalate or request expert attention — when the decision goes beyond what your team can settle today.

It all lands in the alert's history, with who did what and when. Comments are internal: your team sees them and nobody else. In practice that record is the evidence that your organization responds to what it detects — which is exactly what an auditor asks about.