Skip to main content
The alert detail page is the primary triage surface. It combines AI-generated context, downstream impact, root cause steps, and cluster information so you can understand why an alert fired and what to do — without navigating away.
Image

Alert header

Key metrics

Three quick stats at the top:

AI Summary

An AI-generated interpretive paragraph — not a restatement of numbers, but an explanation of what they mean. The summary covers four things in order:
  • What — the metric, segment, and the observed vs. expected deviation using directional language (spiked, dropped, drifted, exceeded)
  • Pattern — the anomaly type in plain English: spike (sharp transient rise), drop (sudden decrease), drift (gradual shift), sustained (persistent, not self-correcting), or shift (step-change to a new level)
  • Trend — improving (may be transient), worsening (prioritise immediately), or stable (not self-correcting)
  • Recurrence — only shown if the alert has fired more than once; notes how many times since first seen
Examples of AI-generated titles replacing raw condition strings:

Alert context

The raw evaluation details behind the alert:
Image

Impact Analysis

Shows downstream assets affected (from lineage), plus an AI Insights paragraph that translates the blast radius into business language:
  • Groups downstream assets by business domain (sales reporting, inventory management, brand performance, etc.)
  • Describes which reports, dashboards, or decisions are at risk
  • For Critical and High severity, recommends notifying downstream consumers before they run reports from affected assets

Root Cause Analysis

An AI Insights section with two parts:Context paragraph — what the metric measures, how upstream assets feed it, and why the deviation is meaningful given the baseline model.Three investigation steps — numbered, executable, tied to specific upstream assets or transformation layers:Investigation focus by anomaly type:

Alert Cluster

If this alert belongs to a cluster (a group of related alerts sharing a common root cause or failure pattern), a cluster summary appears on the detail page:
Image
Click the cluster name to open the cluster view, where all member alerts are listed together with shared context. Cluster lifecycle:
Resolving a cluster does not automatically resolve its member alerts. Each alert must still be individually resolved. The cluster closes when all members are resolved.

Triaging an alert

  1. Read the AI-generated title and Summary to understand what happened and how serious it is before looking at raw numbers.
  2. Check the Alert context panel for the exact breach value and threshold.
  3. Review Impact Analysis to understand downstream exposure and whether consumers need to be notified.
  4. Follow the Root Cause Analysis steps starting with Step 1 — each step names a specific asset or layer to inspect.
  5. Check the Timeline tab to determine when the issue started and whether it is recurring.
  6. Update the Status — mark as normal if no action is needed, or link/create an issue to track remediation. See Alert Management for lifecycle details.
AI Insights quality improves as more context (descriptions, domain tags, lineage) is populated on your assets. Use the Refresh button on any AI module to regenerate from the latest alert state.