Skip to main content
Essal Guard includes a rule-based threat detection engine that monitors activity across all apps for anomalous or suspicious patterns. When a rule matches, Guard creates an alert and routes it to configured notification channels.

Alert Rules

An alert rule defines what to watch for and what to do when it fires.

Built-In Rule Templates

Guard ships with pre-built rule templates for common threat patterns. Apply a template to quickly add coverage:
Available templates:

Alert Lifecycle

Alerts move through the following states:
Update an alert’s state via the API:

Notification Channels

Configure where alerts are routed:
Supported channel types: slack, email, pagerduty, webhook, ms_teams.
Route high-severity alerts (high, critical) to PagerDuty or an on-call system, and medium-severity alerts to a Slack channel for async review.

Viewing Active Alerts