Browse
On this page

The Alerts Desk at a glance

The one page that reads every open alert across every client and every monitored domain, shown on an instance with no open alerts on any domain, any status, or any time frame yet.

  1. Domain tabs

    All, Devices, CyberSentry, and Expirations filter the same list down to one monitored domain. An account only sees the tabs it has access to - a tech without CyberSentry never sees a security row, on any tab.

  2. Client, Status, Severity, Time frame, Search

    All five narrow the same table. Status opens on Open, the working view. Time frame defaults to All time, so an old unresolved alert cannot be filtered out of sight by accident.

  3. Alerts table

    Severity, Domain, Client, Alert, Entity, and Raised columns, with a select-all checkbox in the header for bulk actions. It reads "No alerts match these filters" here because nothing on this instance has tripped a threshold on any domain, not because alerting is off. This trial has no devices, no CyberSentry findings, and nothing near expiration yet - rows appear here the moment a device, CyberSentry, or an expiration raises one.

Why it works this way

Severity uses one vocabulary across every domain: a device alert's own severity maps directly, a CyberSentry high reads as critical while low and informational both read as info, and an expiration's severity comes from how close it is - expired or within 7 days is critical, within 30 days is a warning, further out is info.

The desk is a reading surface, not a second home for the alert. Acknowledging here writes the same record the alert's own page would, but resolving, muting, or snoozing an alert always happens on the page that owns it, never on the desk.

Time frame measures when an alert was raised, not when it was last seen or when it expires, which is why it defaults to All time rather than a rolling window that could hide an old, still-open critical.

Questions this page answers

What is the Alerts Desk?

One place to look at every open alert we raise, across every client and every monitored domain. It does not replace the pages where alerts live: device alerts still belong to the device, CyberSentry alerts to Triage, expirations to the client's documentation. The desk is a reading surface over all of them, so a tech has one list to scan instead of four pages to remember.

How is severity decided?

Each domain keeps its own rules and the desk shows them in one vocabulary. Critical, Warning and Info map from the device alert severity, from the CyberSentry alert severity (high reads as critical, low and informational both read as info), and for an expiration from how close it is: expired or within 7 days is critical, within 30 days is a warning, anything further out is info. Severity is the only colour on the page, so a red row always means the same thing.

What do Open, Acknowledged and Closed mean here?

Open means nobody has picked it up. Acknowledged means somebody has, and it is still live. Closed means it is over, however it ended: a device alert that resolved, a security alert that was resolved or expired, or an expiration that has passed and been acknowledged. The desk opens on Open because that is the work; switch the Status filter to Acknowledged, Closed or All to see the rest.

What does the Time frame filter measure?

When the alert was raised, not when it expires or when it was last seen. It defaults to All time on purpose: a six month old critical that nobody fixed is exactly the row this page exists to surface, and a rolling window would hide it. The presets are the same ones the report builder uses, so "Last 30 days" means the same thing in both places.

What does the RMM Health report show?

One row per client, for the days you pick. It counts their Devices, how many are Offline, their Uptime, their Patch compliance, and their Open alerts. It is a picture of a window of time, not of this minute.

Was this helpful?

Last validated 2026-09-15