Operations alerts

An alert is evidence to review, not a verdict to broadcast.

Every alert needs an owner, evidence link, acknowledgement and closure receipt. Suppression requires a reason, and no alert may automatically message customers or claim a public incident.

Four severities

Severity describes risk, not blame.

The public site publishes the classification law only. It does not expose internal alert counts, affected accounts, evidence or incident detail.

info

Info

A reviewable operating signal with no immediate public-harm assertion.

warning

Warning

A bounded degradation or expiry risk requiring an owner and evidence review.

critical

Critical

A material public, service, commercial or safety risk requiring prompt accountable action.

emergency

Emergency

A severe safety, security or integrity condition requiring restricted escalation and explicit communication authority.

Lifecycle

Open, acknowledged, resolved or suppressed.

Suppressed is not resolved. A suppression reason and owner remain required, and the condition can be reopened from new evidence.

open

The registry requires an accountable transition receipt for this state.

acknowledged

The registry requires an accountable transition receipt for this state.

resolved

The registry requires an accountable transition receipt for this state.

suppressed

The registry requires an accountable transition receipt for this state.

Required receipt

What closure must prove.

A resolved alert needs evidence of the investigated condition, owner acknowledgement, action or non-action rationale and final state.

Evidence link

Reference a governed proof object, run receipt, source record or restricted incident record.

Owner acknowledgement

Name the accountable decision owner; automation cannot acknowledge itself.

Resolution or suppression reason

State why the condition is closed, deferred or suppressed and how it can be reopened.