Alerts and the weekly digest

Alerts has three switches: attack spike, ready to promote, and the weekly digest. Each can be turned off. An alert does not change WAF mode.

Attack spike

The default is an email when a protected site blocks 200 or more requests in an hour. The Alerts page shows the threshold this install is using. After a spike alert, that site waits 6 hours before another one, unless this install uses a different cooldown. One burst sends one email. There are no quiet hours.

The mail names the site, how many requests were blocked, and the window. The next step is to review the site. The message says Promote Copilot never blocks on its own, and that you still click Promote.

Email uses the account address. Slack and a generic HTTPS webhook are attack-spike only. The webhook must be HTTPS and must not point at a private address. You can send a labeled test. A test says no attack was detected and that rules are unchanged.

Only the billing owner can edit alert settings.

Weekly digest

The digest is email, once every 7 days, and only when there is something to say. A quiet week does not send. The subject and body cover counted and blocked requests, rules ready to promote, rules on hold, rules that need an allowlist, and a known-good path that was hit after you promoted.

For an account that is trialing, the same weekly mail can include the trial recap. The recap is built from the protection report, not from a second set of numbers.

Unsubscribe is in the mail and on the Alerts page. Turning the digest off does not change any rule.

What an alert will not do

You still click Promote. Nothing is blocked automatically. Spike mail, the digest, and the ready-to-promote note are notifications. They do not promote, undo, or allowlist.

Related guides

More in this section