- Help Center
- Monitoring
- Review monitoring alerts and evidence
Review monitoring alerts and evidence
Learn how to filter monitoring alerts, inspect supporting evidence, and resolve or reopen alerts with your team.
Last verified 1 day ago
The Monitoring Inbox brings detected changes, supporting evidence, and follow-up work into one review queue. Use it to decide which alerts need attention, which ones you have already read, and which ones your workspace has resolved.
Before you start
You need an Ampere workspace with at least one monitor. An alert appears after an active monitor completes a check and detects a change that matches its condition. Monitoring depends on the configured source and may return partial evidence or a check problem instead of an alert, so it cannot guarantee that every change will be detected immediately.
Find the alerts that need attention
Open Monitoring and use the Inbox. The status views separate alerts by review state:
- Open shows alerts that have not been resolved for the workspace.
- Unread shows alerts you have not marked as read.
- Resolved shows alerts the workspace has already handled.
- All shows open and resolved alerts together.
Use Search alerts to find an alert by its visible details. You can also narrow the Inbox by monitor or project. Select an alert to open its reading pane.
Read state is personal. Marking an alert read or unread changes how it appears to you. Resolution state is shared: resolving or reopening an alert changes its workflow state for the workspace.
Review what changed
Start with the alert header. It shows the alert title, lifecycle state, monitor name, and detection time. The Inbox row also shows how many changes, or findings, the check detected.
In Detected changes, review each finding separately. Depending on what the monitor checked, a finding can include:
- A plain-language claim and summary.
- When the change was observed.
- The changed value and the previous value for a snapshot comparison.
- Why this was flagged, including field-level reasoning and confidence when the source provides them.
- Source links, evidence excerpts, and additional sources.
An alert with several findings lists each detected change in the reading pane. Larger result sets also provide links for jumping directly to a finding. Open Show full evidence beneath a source when you need to read its saved excerpts, and follow the source link when you need the original page.
Historical alerts can preserve a simpler evidence summary without attribution for every individual finding. Provider-backed sources may also return incomplete or noisy information. Treat the displayed evidence as support for review, not as a guaranteed complete record of every change.
Check the monitor and follow-up details
The lower part of the reading pane connects the alert to the rest of the workflow:
- Watching for repeats the monitor condition that produced the alert.
- Joule follow-up shows the requested follow-up and its available result. If you have access to its session, select Open follow-up to continue there.
- Email notifications shows the outcome for each selected recipient when delivery information is available.
- View check opens the monitor check that detected the change.
Email outcomes describe the recorded delivery state; they do not guarantee that a message was opened or acted on. A recipient list can also be empty when no email recipients were selected for the monitor.
Mark an alert read or unread
Use Mark read after you have reviewed an alert. If you want it to return to your personal unread queue, use Mark unread.
Changing read state does not resolve the alert. This lets you clear your personal unread count without telling the rest of the workspace that the alert has been handled.
Resolve or reopen an alert
Select Resolve when the workspace has reviewed the change and no longer needs it in the Open view. The alert remains available in Resolved and All, along with its evidence and resolution details.
If you resolve an alert by mistake, use Undo in the confirmation message while it is available. You can also open the resolved alert later and select Reopen. Reopening returns the alert to the shared Open workflow so the team can continue reviewing it.
After these actions, expect read and unread changes to affect your own Inbox, while resolve and reopen actions update the shared alert state.
Was this article helpful?