Skip to content

Notification integrations

Add email, Slack, Microsoft Teams, or webhook destinations, protect their addresses, and verify recorded delivery outcomes.

Choose where the team will follow upPermalink to Choose where the team will follow up

Use integrations to notify responsible reviewers when scans finish, cannot finish, or fail a policy. Destinations belong to the selected workspace. You need permission to change them and access to an appropriate mailbox, channel, or receiving endpoint. Repository connections are managed separately; adding a notification destination does not grant access to source code.

Destination typeWhat you need
EmailA recipient email address, entered on its own without a display name. No webhook URL is required.
SlackAn incoming-webhook URL from your Slack workspace for the intended channel.
Microsoft TeamsA webhook URL from a Teams Workflows flow connected to your channel. The form includes a setup-help link.
WebhookAn internet-reachable HTTPS endpoint you control and intend to receive these notifications.

URL destinations must use HTTPS and must not be local or private-network addresses or contain a username and password. If email is reported as unavailable, contact support rather than assuming a saved destination will make delivery available.

Add a destinationPermalink to Add a destination

  1. Open Integrations

    Confirm the workspace, then choose Add a destination.

  2. Choose the type and name

    Select Email, Slack, Microsoft Teams, or Webhook. Use a descriptive name such as Release security alerts so teammates can identify the destination later.

  3. Enter the address or URL

    Use the destination field for the selected type. Resolve validation messages before submitting.

  4. Choose event subscriptions

    Select Every event or choose the specific events your reviewers need. With Choose events, select at least one event.

  5. Add and verify later

    Choose Add destination and check that it appears. After a matching event, inspect the recorded delivery status and confirm receipt at the destination.

The address field clears after submission, including an unsuccessful attempt. If saving fails, read the message and re-enter the address before retrying. There is no test-send action in this console; adding a destination is not a delivery test.

Choose the events to receivePermalink to Choose the events to receive

EventWhat to review when notified
A scan finishedOpen the result and read coverage, findings, and candidates. Finished is not the same as no issues found.
A scan could not finishRead the failure explanation and decide whether access, configuration, or a retry needs attention.
A scan failed its policyRead the actual policy verdict and each reason, including coverage failures with zero findings.

No explicit events means every event

Every event subscribes the destination to all available event types, including new types when they become available. An empty explicit subscription is not a way to silence notifications. Use Choose events for a subset, and remove a destination when it should stop receiving new notifications.

Use the event choices actually offered by the console. Do not assume that another workflow, such as preparing a fix, has a notification event merely because that workflow exists.

Treat destination details as protected informationPermalink to Treat destination details as protected information

Full destination addresses and webhook URLs are not shown again after submission. The list shows only the email domain or URL host, together with the destination name. Treat the original address and especially a channel webhook URL as protected information: do not place them in screenshots, support messages, or triage notes.

Keep the original details in your team's approved secure location if you need to recreate the destination. The console does not provide a reveal or edit action. To change the address, type, or subscription, add the replacement and remove the old destination. If both remain active, both may receive matching notifications.

Interpret delivery statusPermalink to Interpret delivery status

Search destinations by name or host, or filter by channel type and delivery status. The row describes the most recent recorded attempt, not continuous connectivity or proof that a person read the message.

StatusInterpretation and next action
DeliveredThe latest recorded attempt succeeded. Check the recipient mailbox or channel if the message is not visible.
Not deliveredThe latest attempt failed. Read its detail, check the intended destination and permissions, and replace outdated destination details if needed.
Nothing sent yet or no reported outcomeDelivery has not been established. Check that a matching event occurred; do not infer either a successful test or a working connection.
Turned offThe destination is disabled. Do not interpret a past successful delivery as evidence that it is currently receiving new events.

If an expected alert is missing, check the workspace, subscription, relevant scan outcome, and last delivery time. If the issue persists, give support the destination name, type, visible host, and event time without sharing the full protected address.

Remove a destinationPermalink to Remove a destination

Choose Remove on the destination and confirm the removal. New notifications will no longer be sent there; this does not recall messages already delivered. Re-adding it requires entering the address again. If removal fails, the destination remains listed, so retry rather than assuming notifications stopped.