> For the complete documentation index, see [llms.txt](https://docs.expel.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.expel.io/workbench-setup/notifications/about-notifications.md).

# About Notifications

Expel security monitoring tracks many moving parts at the same time. Many events, like a security device going offline or an Investigation being opened, trigger a notification from Workbench. You may also receive a notification if there is a manual action of some kind that you need to take in support of an Investigative Action.

## Notification Types

Your organization can use more than one type of notification to receive messages about your environment, if you choose. You can also leverage email, or integrations with Slack​​® or Microsoft Teams™, to communicate directly with us.

There are two types of notifications that can be set up in Workbench.

<table><thead><tr><th width="214.328125">Type</th><th>Usage</th></tr></thead><tbody><tr><td>Email notification</td><td><ul><li>Configured at the user level and sent to an individual email address.</li><li>Includes a link to take action in Workbench.</li><li>All users in an organization will receive the <a href="#default-email-notifications">default email notifications</a>, but each user can edit them as they wish.</li><li><a href="/pages/1GrElz7tlmYjXItEMkem">Organization Admin</a> users can also edit email notifications for other users.</li></ul></td></tr><tr><td>Organization notification</td><td><ul><li>Configured at the organization level.</li><li>Only <a href="/pages/1GrElz7tlmYjXItEMkem">Organization Admin</a> users can add, edit, or delete organization notifications.</li><li>Sent to a platform like Slack​​ or Microsoft Teams, or to other integrations like a ticketing system or webhook destination.</li><li>Requires someone in the organization to first set up an integration with a <a href="#supported-platforms">supported platform</a> before receiving any organization notifications, including the <a href="#default-organization-notifications">default organization notifications</a>.</li></ul></td></tr></tbody></table>

## Default Notifications

Certain notifications are enabled by default for organizations and users. You may set up additional notifications for your organization or for your email, and you may also [edit the default notifications](#how-to-set-up-notifications) at any time.

### Default Email Notifications

{% hint style="info" %}
Default email notifications are activated for a user as soon as they are set up in Workbench.
{% endhint %}

An email notification is always generated when the following events occur in Workbench, unless changed by a user or an admin at your organization:

* [Incident is created](#user-content-fn-1)[^1]
* [Incident is closed](#user-content-fn-2)[^2] (Wiz users only)
* [Investigation is created](#user-content-fn-3)[^3]
* [Investigation is assigned to my org](#user-content-fn-4)[^4]
* [Investigation is closed](#user-content-fn-5)[^5]
* [Investigative Action is assigned to me](#user-content-fn-6)[^6]
* [Investigative Action is assigned to my org](#user-content-fn-7)[^7]
* [Notify Action is assigned to my org](#user-content-fn-8)[^8]
* [Verify Action is assigned to me](#user-content-fn-9)[^9]
* [Verify Action is assigned to my org](#user-content-fn-10)[^10]
* [Remediation Action is assigned to me](#user-content-fn-11)[^11]
* [Remediation Action is assigned to my org](#user-content-fn-12)[^12]
* [Remediation Action is automated](#user-content-fn-13)[^13]
* [An assembler has a health status change](#user-content-fn-14)[^14]

### Default Organization Notifications

{% hint style="info" %}
Someone at your organization must first set up an integration with one of the [supported platforms](#supported-platforms) in order to begin receiving the default organization notifications.
{% endhint %}

An organization notification is always generated when the following events occur in Workbench, unless changed by an admin at your organization:

* [Incident is created](#user-content-fn-1)[^1]
* [Incident is assigned to an organization](#user-content-fn-4)[^4]
* [Incident is reopened](#user-content-fn-15)[^15]
* [Investigation is assigned to an organization](#user-content-fn-7)[^7]
* [Remediation Action is assigned to an organization](#user-content-fn-12)[^12]\*
* [Verify Action is assigned to an organization](#user-content-fn-10)[^10]
* [Investigative Action is assigned to an organization](#user-content-fn-7)[^7]
* [Notify Action is assigned to an organization](#user-content-fn-8)[^8]
* [Assembler has a health status change](#user-content-fn-14)[^14]
* [Security device has a health status change](#user-content-fn-16)[^16]
* [Announcement is created](#user-content-fn-17)[^17]
* [Emerging threat is created](#user-content-fn-18)[^18]
* Support ticket is created
* Support ticket is re-opened
* Support ticket is closed
* Support ticket comment created

*\* Exception: For ticketing systems only, when an Investigation occurs due to a Phishing alert, organization notifications for Remediation Actions are not sent to those systems by default. You can* [*contact Support*](/support/how-to-reach-us.md) *to turn this notification on if you wish.*

### Supported Platforms

All of the following integrations are configured at the organization level and support your organization notifications.

{% hint style="info" %}
You can also use Teams or Slack to communicate with us directly.
{% endhint %}

* Microsoft Teams\*
* [OpsGenie](/workbench-setup/notifications/platform-setup/opsgenie-setup-for-organization-notifications.md)
* [PagerDuty](/workbench-setup/notifications/platform-setup/pagerduty-setup-for-organization-notifications.md)
* [ServiceNow](/workbench-setup/notifications/platform-setup/servicenow-setup-for-organization-notifications.md)
* Slack\*
* [Ticketing Systems](/workbench-setup/notifications/platform-setup/ticketing-system-setup-for-organization-notifications.md)
* [Webhooks](/connect-your-technology/about-integrations/webhooks-setup-for-workbench.md)

*\*Our* [*Support team*](/support/how-to-reach-us.md) *can help you set up Teams and Slack.*

## How to Set Up Notifications

All notifications are set up in Workbench in [Settings > Organization Settings](https://workbench.expel.io/settings).&#x20;

{% hint style="info" %}
Email notifications are set up in a user's **Profile** page, and organization notifications are set up in the **My Organizations** section.

An [Organization Admin](/workbench-setup/get-started/add-and-manage-users/user-role-rights.md) user is required to set up organization notifications.
{% endhint %}

* To set up email notifications:
  * Simply select a notification event that will be sent to the user email.
* To set up organization notifications:
  * First use the Integrations tab to set up an integration with a [supported platform](#supported-platforms).
  * Then use the Notifications tab to create the individual notifications that are routed to that platform.

For detailed setup instructions, including how to change your notifications, see:

* [Manage Email Notifications for Workbench](/workbench-setup/notifications/manage-email-notifications.md)
* [Manage Organization Notifications for Workbench](/workbench-setup/notifications/manage-organization-notifications.md)

[^1]: Malicious activity was identified and we are looking into it. Stay tuned for remediation actions.

[^2]: The malicious activity we found is resolved.

[^3]: Additional information is needed and we are looking into it.

[^4]: We need your team to investigate this activity.

[^5]: Additional information was gathered and a conclusion was made.

[^6]: You are assigned an investigative action to help provide additional information related to this activity.

[^7]: We need a representative from your organization to provide more information to help draw a conclusion about the activity.

[^8]: We are sharing an update with your team of lower severity, but can include some actions you can take.

[^9]: We need you to let us know if an action that triggered suspicion is authorized or not.

[^10]: We need someone from your team to let us know if an action that triggered suspicion is authorized or not.

[^11]: You need to take an action to address the unwanted activity. This is typically assigned to you by someone from your team.

[^12]: We identified an action your team can take to address unwanted activity.

[^13]: Expel bots are doing this remediation for you, so your team does not need to do anything.

[^14]: The condition of the [Assembler](/connect-your-technology/expel-assembler/about-the-expel-assembler.md) has become either connected or disconnected.

[^15]: We reopened a previously closed Incident.

[^16]: Your security device has become either connected or disconnected.

[^17]: A global event was created by Expel.

[^18]: Expel Threat Intelligence has identified a new threat that needs your attention.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.expel.io/workbench-setup/notifications/about-notifications.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
