Skip to content
C50 Clause50EU AI Act transparency — made auditable.EU AI Act evidence, made auditable
All documentation

Alerts

The four kinds of alert in plain words, what the hourly pass actually does, and why an alert is a notification rather than a task.

Alerts tell you when something about your compliance position has changed. There are four: a coverage gap (a duty with no proof behind it), evidence out of date (proof you had, which has expired), a rule pack update (the rules moved on since your last calculation), and a system change (your record was updated after your last calculation). They appear in an inbox in the app, and anything new is sent to your organisation as a single digest email — never one email per alert.

An alert is a notification, not a task. There is no button to resolve or close one. Fix the underlying condition and no further alert is raised for it; the original stays as a dated record of what you were told and when. To see what is still outstanding, look at your coverage page, which shows current state.


More detail

The four kinds, in plain words

A system whose coverage has never been calculated produces no alerts at all — not even gap alerts. Every one of the four kinds is a comparison against a previous calculation, and there is no honest baseline to compare against. The dashboard already tells you the system has not been checked yet; piling alerts derived from nothing on top would imply a baseline that does not exist. In practice this state lasts less than an hour: the same pass that evaluates alerts calculates coverage first, so a system with no baseline gets one and starts producing alerts on the following pass.

Why an alert is a notification, not a task

Each alert is a dated statement: at this time, this system was in this condition. It is a record of what you were told and when. Once written it is not edited — the only thing that ever changes on it is whether the email went out.

A condition that clears simply stops producing new alerts. Record the missing evidence and no further gap alert is raised for that requirement. The old one stays in the inbox as history, which is the useful behaviour: the question an auditor asks is not “is this ticket closed” but “when did you know, and what did you do about it”.

So the inbox is a timeline, and the coverage page is the current picture. Use each for what it is good at.

When the digest email goes out

Clause50 runs a scheduled pass every hour. Each pass does three things in order: recalculates the coverage of any system whose score has fallen behind, re-examines alerts for every system against that fresh result, then sends each organisation with anything new one digest email listing everything not yet notified. Never one email per alert.

Hourly is the cadence of the check, not of your inbox. What stops you being emailed every hour is the suppression rule below, not the schedule — a condition you have not dealt with is raised once and then left alone for a week.

You do not have to wait for the next pass. There is an evaluate now action per system that updates the inbox immediately; it does not send email, which follows on the next scheduled pass.

Nothing is marked sent unless it was sent — see below — so an alert raised while email delivery is unavailable is not lost. It waits in the inbox and goes out on a later pass.

What alerts never contain

Alert records and digest emails carry identifiers, names, statuses, and rule references. They never carry the contents of your evidence, your uploaded files, or any connector credential. That restriction is enforced where the email is assembled, not merely intended where the alert is written.

Plan

Automatic alerts are listed as a paid-plan feature in the plan comparison on the Artifacts page.