Alerts and attention
Route an observed issue to someone who can resolve it. /governance/alerts
| Rule | Severity | Scope | First seen | Last seen | Owner | State |
|---|
Alert counts can differ from asset exception counts: one alert can cover multiple assets (dedup + grouping), so one disconnected device does not create hundreds of notifications. Acknowledging an alert does not repair the underlying condition. A resolved condition keeps its history and can reopen if it recurs.
Data states
When no rule is firing, the list is explicitly empty with an all-clear, never a blank space mistaken for a broken feed.
A rule whose source has not reported is shown as evaluating on partial data, not silently passing.
Suppressed until a stated time; it reappears automatically when the window ends. Suppression is not resolution.
Each alert carries a rule, severity, first and last seen, affected scope, current evidence, owner, state, and a recommended action. States are Open, Acknowledged, In progress, Resolved, and Suppressed until a specified time. Rule detail shows the threshold, evaluation window, data source, minimum sample size, and recipients. Synthetic fixture data, not a real customer's figures.