Skip to content

Overview

Oneleet sends a notification when something in your security program needs attention — a monitor starts failing, a new vulnerability is found, an auditor asks for evidence, a document is requested through your trust center.

This section covers the channels notifications are delivered on, how you choose what you receive, and what workspace admins can set on everyone’s behalf.

Notifications are delivered on two channels:

  • Email — sent to the address on your Oneleet account.
  • Slack — posted to a shared notifications channel, and delivered as a direct message to individual members. Both require the Slack integration.

Each notification type is configured per channel, so you can take monitor alerts in Slack and everything else over email.

What Where Who can change it
Your own notification preferences and digest Settings > My Account > Notifications Every member, for themselves
Workspace defaults, digest defaults, and Slack channel routing Settings > Workspace > Notifications Admins
Turning all notifications off for one member Members, row action menu Admins

For a given member, notification type, and channel, the first rule that applies wins:

  1. The member has notifications disabled. An admin can switch a member off entirely from the Members page (row action menu > Disable notifications). Nothing that follows preferences is sent to them.
  2. The member’s own setting. Anything you change on your notification preferences page applies to you and overrides the workspace default.
  3. The workspace default for the member’s role. Admins set these per role — see workspace defaults.
  4. The Oneleet default — enabled, email only.

Workspace defaults only fill in the gaps. Once you change a toggle on your own page, that row is yours — a later change to the workspace default won’t move it. Use Use workspace default to hand the row back.

A few notifications ignore preferences and are always delivered by email: invitations, workspace access grants, exposed-account alerts, and the auditor portal notifications. Invitations reach people who aren’t members yet, and the rest are time-sensitive security or audit messages.

These don’t appear on the preferences page, since a toggle there would have no effect. The full list is in the notification catalog.