Every notification Oneleet sends, and whether you can configure it. Names match
the rows on your preferences page and in the
workspace defaults matrix.
Delivered by email or Slack according to your preferences, the
workspace default for your role, or — if neither is set — email only.
| Notification |
Sent when |
| Monitor alerts |
Monitors detect non-compliant assets |
| Monitor at risk warnings |
Monitors are at risk of breaching your service level agreements |
| SLA breach alerts |
Monitors breach your service level agreements |
| Monitor review reminders |
It’s time to review monitor status and results |
| Notification |
Sent when |
| Code security findings |
New security vulnerabilities are detected in your code |
| Dependency vulnerability findings |
New vulnerabilities are detected in your dependencies — limited to high-severity, known-exploited, or high-probability findings |
| Attack surface scan complete |
Your first attack surface scan finishes and your inventory is ready |
| Notification |
Sent when |
| Activity comments |
A comment is added to a control or activity |
| Control changes requested |
Changes to a control have been requested |
| Evidence is due during observation period |
You’re in an observation period and need to submit evidence for a control |
| Notification |
Sent when |
| Trust Center Document Requests |
A visitor requests documents through your trust center |
| Trust center security reports |
A security issue is reported through your trust center |
| Notification |
Sent when |
| Integration updates |
An integration is updated or requires attention |
| Notification |
Sent when |
| Report published |
A compliance or security report becomes available |
These are delivered by email regardless of preferences, so they don’t appear on
the preferences page or in the workspace defaults matrix. Invitations reach
people who aren’t members of the workspace yet; the rest are time-sensitive
security and audit messages.
| Notification |
Sent when |
| Team member invitations |
You’re invited to join a workspace |
| Employee invitations |
Employees are invited to the portal |
| Workspace access granted |
You’re granted access to a workspace |
| Exposed account alerts |
Your accounts are found in a data breach |
| Vendor access review due |
A vendor access review assigned to you is due within the month |
Delivered to audit firm users working in the auditor portal.
| Notification |
Sent when |
| Audit firm invitations |
You’re invited to join an audit firm on Oneleet |
| Auditor portal mentions |
You’re @mentioned in an audit message |
| Auditor portal evidence-request submissions |
An auditor submits an evidence request for your review |
| Auditor portal evidence submissions |
A customer submits evidence on a request awaiting your review |
| Auditor portal evidence-request updates |
A request you raised is accepted, withdrawn, or needs more information |
| Auditor portal evidence approvals |
Evidence you requested is approved and ready for your review |
Visitors who request documents through your trust center also receive an email
when you approve or deny their request. It goes to the requester, not to anyone
in your workspace.
The digest email is configured on its own, separately from the types above. See
Digest emails.