
How alerts are generated
Alert states
Suppressed is not a state. An alert inside a suppression window remains Active — only notifications are paused. See Alert Management.
Threshold types
Alert clusters
When multiple alerts fire in a correlated pattern — across related assets, at the same time, or from the same upstream source — Prizm groups them into an Alert Cluster. A cluster captures the shared context: name, description, assets impacted, total alerts, and creation timeline. Investigating the oldest member alert in a cluster typically leads to the root cause fastest.Alert suppression
Suppression pauses notifications for a defined window or scope. Metric checks still run and breaches are still recorded in the audit log — only notifications are paused.Alert Detail
AI-generated triage context, impact analysis, root cause steps, timeline, and alert clusters.
Alert Management
Alert states, issue linkage, and suppression configuration.
Thresholds
Auto, Limit, and Custom threshold types — including multi-criteria rules and per-condition actions.