Skip to main content

Email Alerts

Compliance Engine findings can trigger email notifications so that owners and responders are alerted to new or updated violations.

When to Use Email Alerts

Email is useful when:

  • You want to notify a distribution list (for example, a security mailbox) about new high‑severity violations.
  • You need simple notifications without full ITSM integration.
  • You want to send summary emails or specific alerts to application owners.

For large environments, email alerts are usually combined with ticketing and dashboards rather than used as the only signal.

Configuring Alerts

Because Compliance Engine stores policy violations and benchmark checks as Salesforce‑backed objects, you can use:

  • Email templates to define the subject and body, including merge fields for policy name, asset identifiers, severity, and links.
  • Workflow rules or automation to decide when an email is sent (for example, when a new violation is created, when severity changes, or when a violation has been open for too long).

Typical merge fields include:

  • Policy name and description.
  • Violation number or identifier.
  • Asset details (for example, account, region, resource ID).
  • Current status and severity.
  • A direct link to the violation in Cloudaware.

Cloudaware documentation and support can provide concrete examples of templates and rules.

Routing Patterns

Common routing approaches include:

  • Sending alerts to a central security or compliance team for triage.
  • Notifying application or service owners based on tags or ownership fields.
  • Using different templates and recipients for high‑severity vs. low‑severity controls.

For complex environments and high volumes of findings, consider combining email with ITSM and collaboration integrations; see ITSM & Ticketing and Collaboration.