Alerts
The Alerts page, under Planning, is one view over several kinds of alert. Each kind is still created and edited where it lives; the page brings them together.
Before you start
- Every team role can view the page. Creating, pausing and deleting alerts needs the Owner or Editor team role in a workspace your team can edit.
- Alerts that should reach Email, Slack, Microsoft Teams or a webhook need a notification channel.
Configured alerts
Configured alerts lists budgets' thresholds, spend thresholds and report schedules with their Name, Kind, Threshold, State and Last fired. The kinds are:
| Kind | What it watches | Where it is created |
|---|---|---|
| Budget threshold | Spend for a budget's period reaching a percentage of its amount | Budgets |
| Spend threshold | Spend passing an absolute amount | Public API |
| Unusual change | Spend rising by a percentage against a comparison period | Public API |
| Low tag coverage | Tag coverage falling below a percentage | Tags, with Set Alert |
| Report delivery | A scheduled cost report | Share and schedule reports |
What fired
What fired is one feed of alert events and detected anomalies, newest first. Where a baseline exists, an entry shows the observed and expected amounts: "Observed …, expected …". See Insights for how anomalies are detected and acknowledged.
Spend and change alerts through the API
Spend threshold and unusual change alerts are created through the Public API's cost alert endpoints. An alert names:
- a
thresholdType:absoluteorpercentageIncrease, with acomparisonPeriodofpreviousDay,previousWeek,previousMonthorsameDayLastMonthfor a percentage increase; - the
thresholdValue; - optionally the connections (
providerIds) and a costfilterit watches; - the notification channels to deliver to (
appIds); - how often to evaluate it,
evaluationFrequencyMinutes, between 15 and 1440 minutes.
See API authentication and the API reference.
Pause, resume or delete a cost alert
Spend, change and tag coverage alerts are listed on the Insights page's Alerts card, with actions to view, pause, resume and delete each one. Deleting stops evaluation immediately.
Where alerts are delivered
| Source | Delivered to |
|---|---|
| Budget thresholds | An in-product notification |
| Spend, change and tag coverage alerts | An in-product notification, plus the channels the alert names |
| Detected anomalies | An in-product notification, plus every enabled notification channel in the organization |
| Report delivery | The email destination chosen on the schedule |