28 Aug 14:20 UTC

Settings

Where findings go

3 of 7 connected
  • Slackoutbound#sony-one-alertsP1 and P2 findings with their evidence block, to a channel per fault domain.
  • Microsoft TeamsoutboundThe same routing as Slack, for readers who do not live in it.
  • JiraoutboundA ticket per confirmed finding, assigned to the owning fault domain.
  • ZendeskoutboundArcadian-hosted instanceThe automated L1 → provider push, replacing the manual forward.
  • PagerDutyoutboundP1 only, on the acknowledgement clock. Escalates on non-acknowledgement.
  • Email digestoutboundDaily, 07:00 UTCOne message each morning: what changed, what breached, what is still open.
  • WebhookoutboundRaw finding payloads to an endpoint of your own, for anything not listed here.

What the tool reads

governed by the access matrix
  • TableauinboundReads the tool's governed metric definitions, so BI and findings agree.Open question — BI may stay on Redshift. See api-contract.md AQ-29.unavailable
  • DatadoginboundAPM traces, RUM sessions and server metrics.Not connected — awaiting API key and instrumentation. AQ-8, AQ-21.unavailable

Connecting a destination here decides routing, not obligation. Whether SimpleStream or AWG have agreed to receive what lands there is a commercial question — an alert with no agreed intake goes into a void.