Notification integrations
Add email, Slack, Microsoft Teams, or webhook destinations, protect their addresses, and verify recorded delivery outcomes.
Choose where the team will follow upPermalink to Choose where the team will follow up
Use integrations to notify responsible reviewers when scans finish, cannot finish, or fail a policy. Destinations belong to the selected workspace. You need permission to change them and access to an appropriate mailbox, channel, or receiving endpoint. Repository connections are managed separately; adding a notification destination does not grant access to source code.
| Destination type | What you need |
|---|---|
| A recipient email address, entered on its own without a display name. No webhook URL is required. | |
| Slack | An incoming-webhook URL from your Slack workspace for the intended channel. |
| Microsoft Teams | A webhook URL from a Teams Workflows flow connected to your channel. The form includes a setup-help link. |
| Webhook | An internet-reachable HTTPS endpoint you control and intend to receive these notifications. |
URL destinations must use HTTPS and must not be local or private-network addresses or contain a username and password. If email is reported as unavailable, contact support rather than assuming a saved destination will make delivery available.
Add a destinationPermalink to Add a destination
Open Integrations
Confirm the workspace, then choose Add a destination.
Choose the type and name
Select Email, Slack, Microsoft Teams, or Webhook. Use a descriptive name such as Release security alerts so teammates can identify the destination later.
Enter the address or URL
Use the destination field for the selected type. Resolve validation messages before submitting.
Choose event subscriptions
Select Every event or choose the specific events your reviewers need. With Choose events, select at least one event.
Add and verify later
Choose Add destination and check that it appears. After a matching event, inspect the recorded delivery status and confirm receipt at the destination.
The address field clears after submission, including an unsuccessful attempt. If saving fails, read the message and re-enter the address before retrying. There is no test-send action in this console; adding a destination is not a delivery test.
Choose the events to receivePermalink to Choose the events to receive
| Event | What to review when notified |
|---|---|
| A scan finished | Open the result and read coverage, findings, and candidates. Finished is not the same as no issues found. |
| A scan could not finish | Read the failure explanation and decide whether access, configuration, or a retry needs attention. |
| A scan failed its policy | Read the actual policy verdict and each reason, including coverage failures with zero findings. |
No explicit events means every event
Use the event choices actually offered by the console. Do not assume that another workflow, such as preparing a fix, has a notification event merely because that workflow exists.
Treat destination details as protected informationPermalink to Treat destination details as protected information
Full destination addresses and webhook URLs are not shown again after submission. The list shows only the email domain or URL host, together with the destination name. Treat the original address and especially a channel webhook URL as protected information: do not place them in screenshots, support messages, or triage notes.
Keep the original details in your team's approved secure location if you need to recreate the destination. The console does not provide a reveal or edit action. To change the address, type, or subscription, add the replacement and remove the old destination. If both remain active, both may receive matching notifications.
Interpret delivery statusPermalink to Interpret delivery status
Search destinations by name or host, or filter by channel type and delivery status. The row describes the most recent recorded attempt, not continuous connectivity or proof that a person read the message.
| Status | Interpretation and next action |
|---|---|
| Delivered | The latest recorded attempt succeeded. Check the recipient mailbox or channel if the message is not visible. |
| Not delivered | The latest attempt failed. Read its detail, check the intended destination and permissions, and replace outdated destination details if needed. |
| Nothing sent yet or no reported outcome | Delivery has not been established. Check that a matching event occurred; do not infer either a successful test or a working connection. |
| Turned off | The destination is disabled. Do not interpret a past successful delivery as evidence that it is currently receiving new events. |
If an expected alert is missing, check the workspace, subscription, relevant scan outcome, and last delivery time. If the issue persists, give support the destination name, type, visible host, and event time without sharing the full protected address.
Remove a destinationPermalink to Remove a destination
Choose Remove on the destination and confirm the removal. New notifications will no longer be sent there; this does not recall messages already delivered. Re-adding it requires entering the address again. If removal fails, the destination remains listed, so retry rather than assuming notifications stopped.