Notification catalog
Every notification Oneleet sends, and whether you can configure it. Names match the rows on your preferences page and in the workspace defaults matrix.
Configurable
Section titled “Configurable”Delivered by email or Slack according to your preferences, the workspace default for your role, or — if neither is set — email only.
Monitoring
Section titled “Monitoring”| Notification | Sent when |
|---|---|
| Monitor alerts | Monitors detect non-compliant assets |
| Monitor at risk warnings | Monitors are at risk of breaching your service level agreements |
| SLA breach alerts | Monitors breach your service level agreements |
| Monitor review reminders | A disabled monitor reaches its scheduled review time |
Emails for all four monitoring notifications are combined: events of the same type for the same workspace are collected into one email, sent 15 to 30 minutes after the first event (see delivery timing). A combined review reminder links to each monitor. Slack messages are sent immediately, one per event.
Security
Section titled “Security”| Notification | Sent when |
|---|---|
| Code security findings | New security vulnerabilities are detected in your code |
| Dependency vulnerability findings | New vulnerabilities are detected in your dependencies — limited to high-severity, known-exploited, or high-probability findings |
| Attack surface scan complete | Your first attack surface scan finishes and your inventory is ready |
Code security findings and dependency vulnerability findings emails are combined per workspace: repositories scanned around the same time are listed in one email with each repository’s new-finding count, sent 15 to 30 minutes after the first scan (see delivery timing). Slack messages are sent immediately, one per repository.
Collaboration
Section titled “Collaboration”| Notification | Sent when |
|---|---|
| Activity comments | A comment is added to a control or activity |
| Control changes requested | Changes to a control have been requested |
| Evidence is due during observation period | You’re in an observation period and need to submit evidence for a control |
Control changes requested emails are combined per workspace, sent 15 to 30 minutes after the first request (see delivery timing). Slack messages are sent immediately.
Trust Center
Section titled “Trust Center”| Notification | Sent when |
|---|---|
| Trust Center Document Requests | A visitor requests documents through your trust center |
| Trust center security reports | A security issue is reported through your trust center |
Integrations
Section titled “Integrations”| Notification | Sent when |
|---|---|
| Integration updates | An integration is updated or requires attention |
Reports
Section titled “Reports”| Notification | Sent when |
|---|---|
| Report published | A compliance or security report becomes available |
| Notification | Sent when |
|---|---|
| Organization role changes | Organization roles are assigned to you or removed |
Always sent
Section titled “Always sent”These are delivered by email regardless of preferences, so they don’t appear on the preferences page or in the workspace defaults matrix. Invitations reach people who aren’t members of the workspace yet; the rest are security and audit messages the recipient needs to act on.
| Notification | Sent when |
|---|---|
| Team member invitations | You’re invited to join a workspace |
| Employee invitations | Employees are invited to the portal |
| Workspace access granted | You’re granted access to a workspace |
| Exposed account alerts | Your accounts are found in a data breach |
| Vendor access review due | A vendor access review assigned to you is due within the month |
Exposed account alerts are combined per person: breaches found for the same email address are listed in one email, sent 15 to 30 minutes after the first breach is detected (see delivery timing).
Auditor portal
Section titled “Auditor portal”Delivered to audit firm users working in the auditor portal.
| Notification | Sent when |
|---|---|
| Audit firm invitations | You’re invited to join an audit firm on Oneleet |
| Auditor portal mentions | You’re @mentioned in an audit message |
| Auditor portal evidence-request submissions | An auditor submits an evidence request for your review |
| Auditor portal evidence submissions | A customer submits evidence on a request awaiting your review |
| Auditor portal evidence-request updates | A request you raised is accepted, withdrawn, or needs more information |
| Auditor portal evidence approvals | Evidence you requested is approved and ready for your review |
| Auditor portal request comments | Someone comments on an evidence request — the auditor who raised it and the audit’s Security Program Manager each hear about the other’s comments |
The five evidence-request emails above are combined per audit, sent 15 to 30 minutes after the first event. Invitations and mentions are sent right away.
Visitors who request documents through your trust center also receive an email when you approve or deny their request. It goes to the requester, not to anyone in your workspace.
Digest
Section titled “Digest”The digest email is configured on its own, separately from the types above. See Digest emails.