Appearance
Set up AI alerts
An alert watches your AI spend and use, and tells the people you choose when something happens. Use alerts to hear about a spend spike or a leaked key without watching the Dashboard.
You need AI governance admin access — ask your Flowstate admin.
Create an alert
- Go to Insights → Agent insights → Alerts.
- Select New alert.
- Enter an Alert name.
- Under What should trigger this alert?, choose a trigger. See Choose a trigger.
- Under Trigger conditions, set when it should fire.
- Under Who should be notified?, search for a person and select Add. Repeat for everyone who should hear about it.
- Choose a Severity: Low, Medium or High.
- Select Create alert.
The alert appears in the list as Active.
Tip
An alert with nobody under Who should be notified? tells no one. Add at least one person.
Choose a trigger
| Trigger | Fires when | You set |
|---|---|---|
| Spend anomaly | Spend suddenly spikes or dips compared with your usual trend | Direction, Sensitivity and Baseline window |
| Budget exceeded | An initiative's AI spend reaches its AI budget | Warn at (% of budget) and Budget period |
| Forecast deviation | Where spend is heading drifts from plan, over or under | Deviation threshold (% vs plan) and Horizon |
| Data loss prevention | Customer data or API keys are detected going to an AI provider | Detectors: Customer PII, API keys & secrets, Source code |
| Unapproved AI usage | People use tools that aren't sanctioned, or personal credentials | Detect: New tool signups, Personal credentials, Shadow domains |
| New model releases | A lab you watch releases a new model | Labs & providers to watch and Notify on |
Budget exceeded, Forecast deviation, Data loss prevention and Unapproved AI usage need AI spend attribution. Until it's on, they're marked Enterprise.
Tip
- Budget exceeded and Forecast deviation only fire once there's an AI budget to compare against.
- Data loss prevention groups a day's detections into one alert, so a burst of detections doesn't flood anyone.
- New model releases tells people about each new model once.
How people are told
- Flowstate checks every alert once an hour.
- When the conditions are met, the alert shows Triggered and everyone on it is told once, in their Inbox and on the other channels your organisation uses for AI governance notifications. See Notifications.
- If the condition carries on, the count on the alert goes up but nobody is told again. When it stops, the Inbox item clears.
Find an alert
The list on the left of Alerts shows every alert, with All signals at the top.
- To find an alert by name, type in Search alerts….
- To show only some alerts, select a status. Each one shows how many alerts it has.
| Status | What it means |
|---|---|
| All | Every alert |
| Triggered | Its conditions have been met |
| Active | Switched on and watching |
| Paused | Switched off |
Read an alert
Select an alert in the list. Its details open on the right.
- Activity — a sentence saying what happened most recently and how many times it's been seen, then each occurrence that's still open. When nothing has happened, you'll see No alerts in this period.
- Configuration — the alert's Trigger, Conditions, Recipients and Severity.
Respond to an alert
- In the list, select Triggered, then the alert.
- Under Activity, read what happened.
- Select Acknowledge, or Snooze 24h to put it aside for a day.
- To see the detections behind it, select the View … signal(s) link.
Once you've acted, the occurrence shows Acknowledged or Snoozed instead of the buttons.
Change, pause or delete an alert
- Select the alert in the list.
- Choose what to do:
- To pause it, switch Enabled off. It shows Paused until you switch it back on.
- To change it, select Edit alert, make your changes and select Save changes.
- To remove it, select Delete alert.
Tip
To stop an alert for a while, pause it rather than deleting it.
See every detection
Select All signals at the top of the list to see every detection, including ones no alert watches.
- Choose the period at the top.
- Filter by Category, Status (Needs action or Reviewed) or Severity.
- Sort by Severity or When.
- Select a detection to open it.
Tip
An alert tells people; it doesn't stop anything.
Deal with a detection
A detection is a moment worth a look, such as customer data in a prompt. Most are a chance to point someone to an approved tool or a safer habit.
To mark a detection, you need access to update integrations — ask your Flowstate admin.
- Select All signals, then select a detection.
- Under What happened, read the details Flowstate has, such as Where it went, Data matched and Triggered by rule.
- Under What was shared (redacted), check the sample. Sensitive values are masked.
- To see who it was, select View person next to Who.
- Under Actions, write a Note saying what you found, if it helps the next person.
- Select one:
- Mark reviewed — you've looked at it and it's dealt with.
- False positive — it isn't a real problem.
The detection shows Resolved with the outcome, and moves to Reviewed in the list. It can't be reopened.
Tip
Select the rule next to Triggered by rule to open the rule that raised the detection. See Rules.
If something's not right
An alert never tells anyone — Check Recipients under Configuration. Nobody — this alert notifies no one means you need to add someone with Edit alert.
Search finds nothing — Search looks at alert names. Select All so a status isn't hiding the alert.
All signals is empty — Nothing was detected in the period you chose. Choose a longer period at the top.
There are no Mark reviewed or False positive buttons — The detection has already been dealt with and shows Resolved.
"Could not update the signal" — You may not have access to update integrations. Ask your Flowstate admin.