Overview
Rescans tell you how a client’s posture has shifted over a period. Alerts tell you right now. When Telivy detects a specific security event (a new dark web breach, a string of M365 login failures, an admin account with MFA suddenly disabled), it fires a notification to whoever on your team needs to know. You define which events matter and which team members get notified. Alerts work across four coverage areas:- Internal Security: vulnerability changes on managed endpoints
- Dark Web: new breach and account exposures
- Microsoft 365: identity, access, and policy events across connected tenants
- Google Workspace: the same coverage for GWS environments
Configuring Alert Policies
Alert policies are configured at the agency level and apply across all your assessments. Navigate to Alerts → Alert Policies in the Telivy portal to manage them. To add a new policy:- Click Add Policy.
- In the Configure Alert Policy step, select the Alert Category you want to monitor.
- Set the condition that triggers the alert. For Internal Vulnerabilities, for example, you can trigger on severity level, CVSS score, EPSS score, or finding count above a threshold.
- Click Continue.
- In the Configure Alert Delivery step, select which team members on your agency account should receive the notification.
- Click Save.
Alert Categories
Internal Security
Dark Web
Microsoft 365
Google Workspace
Google Workspace alerts mirror the M365 coverage for organizations running GWS instead of (or alongside) Microsoft 365.FAQ
How quickly does an alert fire after an event is detected?
How quickly does an alert fire after an event is detected?
Cloud events (M365, Google Workspace) are evaluated on each sync cycle. Endpoint-based alerts (Internal Vulnerabilities) are evaluated after each completed agent scan. Manual rescans trigger alert evaluation immediately.
Can I notify multiple team members from the same policy?
Can I notify multiple team members from the same policy?
Yes. In the Configure Alert Delivery step, you can select as many agency users as needed. Each selected user is notified independently when the policy triggers.
Are alert policies scoped to individual clients?
Are alert policies scoped to individual clients?
No. Policies are configured at the agency level and apply across all assessments. You can view alert history filtered to a specific client from that assessment’s Alerts tab, but the policy itself is agency-wide.
Do alerts require Risk Monitoring to be enabled?
Do alerts require Risk Monitoring to be enabled?
No. Alerts are available independently of the automated rescan feature. You can configure alerts on any eligible Risk Assessment without enabling the monitoring cadence.
What's the difference between 'Failed Logins' and 'Conditional Access Violation'?
What's the difference between 'Failed Logins' and 'Conditional Access Violation'?
Failed Logins fire when a user fails to authenticate: wrong password, locked account, etc. Conditional Access Violation fires when the credentials are valid but the sign-in is blocked by a policy rule (e.g. the user is signing in from an unmanaged device or blocked location). Both matter; they indicate different threat patterns.
Can I use webhooks instead of email or SMS?
Can I use webhooks instead of email or SMS?
Yes. Telivy supports outbound webhooks for alert delivery to external systems. See the Webhooks integration guide for configuration details.