Skip to main content

How to view and review alerts

View, review, and take action on Sentinel compliance alerts.

H
Written by Harriet Christie

Summary

The Alerts page is where you review messages that have triggered Sentinel scenarios and record a compliance decision. For each alert you can read the message, see which scenarios and phrases matched, and mark it Compliant or Non-Compliant, escalate it, view it in context, or action similar alerts at once.

Prerequisites

  • Login credentials to MirrorWeb Insight

  • Access to an organisation that has Sentinel enabled

Step-by-Step Instructions

Step 1: Open the Alerts page

In the sidebar, under Sentinel, select Alerts. The page is headed "Alerts" with a summary line showing the number of new alerts for your organisation.

The Sentinel Alerts page heading and alert count

Step 2: Sort and filter alerts

Use the controls at the top of the page to focus the list:

  • A sort dropdown with the options Highest risk, Lowest risk, Newest, and Oldest.

  • A category dropdown (defaulting to All) listing each category with its alert count.

  • A date picker to restrict alerts to a date range.

The Alerts page sort, category, and date controls

Step 3: Review the alert details

Each alert shows the message content on one side and a detail panel on the other. The detail panel includes a Message Summary, the matched scenario phrases ("Triggered by"), and the associated scenario categories. The header shows a Score and a risk level badge. Hovering the score explains: "This is the total risk score, which we calculate based on the frequency and severity of potentially risky phrases in the message."

An alert showing the message content, score, risk badge, and match details

Step 4: Mark the alert compliant or non-compliant

In the alert header, use the action buttons:

  • Mark compliant — optionally add a comment. The dialog notes "This will be permanently stored in the history report for this message."

  • Mark non-compliant — select a Reason for marking as non-compliant (Advertising, Risk, or Other) and optionally add a comment, then Update.

The Mark non-compliant dialog showing the reason dropdown and comment field

Step 5: Escalate or action similar alerts (optional)

  • Use the escalate action to send the message for further review.

  • Use Action similar alerts to act on messages that share the same subject, sender, or thread (or channel on Slack) as the current alert. You can then Mark All Compliant or Mark All Non-Compliant.

The Action similar alerts dialog listing matching alerts

Notes

Note: Keyboard shortcuts are available while reviewing — by default a moves to the previous alert and d to the next, y marks compliant and n marks non-compliant. Compliant and non-compliant keybindings can be customised in your user preferences.

Note: Two alert layouts exist — a carousel view (one alert at a time, navigated with previous/next) and a list view. The list view and the comfy/compact toggle are available when the new alerts layout is enabled for your organisation.

Note: The Action similar alerts option only enables the relevant attributes when the message has them (for example, "Action by subject" is disabled if the message has no subject). On email, users with marketing-write access can also mark the sender as a marketing address while actioning by sender.

Did this answer your question?