Integration alerts: what fires and when
Integration alerts are Current watching your customers' environments for you, so a problem doesn't wait for the next review to surface. They're deterministic — four plain rules with fixed thresholds, not a vague AI hunch — so when one fires you know exactly what tripped it. They read your monitoring, security, and backup feeds and show up on the company record.
The four rules
Each rule has a documented, deliberately conservative threshold — set high enough that a fired alert is worth your attention, not noise:
| Alert | Fires when | In plain language |
|---|---|---|
| Backups failing or unverified | A protected workload has been failing or unverified for 3 or more days. | Something that should be backing up hasn't had a confirmed good backup in days — the thing you never want to discover during a restore. |
| Critical detection open | A critical endpoint or SOC detection has been open for 48 hours or more. | A serious security detection has sat unaddressed for two days — long enough that it needs eyes on it now. |
| Phishing spike | Phishing volume over the last 7 days is at least 3× the customer's own 30-day baseline. | This customer is suddenly being hit far harder than normal — measured against their own baseline, not a generic number, so it catches a real surge for them. |
| Compliance slipping | Patch or Mac compliance drops below 80%, or offline devices jump 25% or more week-over-week. | The fleet is drifting out of a healthy state — either too many machines unpatched, or a sudden rise in devices going dark. |
Open once, resolve themselves
Alerts are open-once and self-resolving. When a rule trips, Current opens one alert — it won't open a second for the same condition while the first is still standing, so a backup that's been failing all week is one line on the record, not fifty. When the underlying condition clears — the backup succeeds, the detection is closed, the phishing surge subsides, compliance climbs back — the alert resolves itself automatically. There's nothing to dismiss by hand and no risk of a stale alert lingering after the problem is gone.
Where alerts appear
Open alerts show on the company record, in the open-alert strip above the Infrastructure & security group — the "what needs attention right now" line for that customer. See "The company page: Infrastructure & security" for how that group reads. Because the alerts read the same feeds the SBR does, they're also a useful pre-review check: a company with open alerts is one whose telemetry chapters will have something to say.
Notifications: in-app only for now, and off by default
Today, integration alerts are in-app only — they live on the company record, where you see them as you work the account, and any open alert on a company you own also lands in your morning daily brief as an attention item. The plumbing for outbound notifications (email or Teams when an alert fires) exists, but it's off by default: Current won't start emailing you about a customer's backups until you deliberately turn it on. That's intentional — alert-fatigue is real, and the thresholds are conservative precisely so that when outbound is switched on, what reaches your inbox is worth reading.
