---
title: focusAlert
canonical: https://www.secnostic.com/en/products/alert
language: en
dateModified: 2026-08-12
alternate-de: https://www.secnostic.com/de/products/alert
---

# focusAlert

- URL: https://www.secnostic.com/en/products/alert
- Positioning: Event management and alerting

focusAlert collects events from machines, monitoring, SCADA, or email and brings the right alarm to the right person, not to everyone.

An incident is not only reported but made actionable: who owns it, how urgent it is, who picked it up, and what happens if no one responds.

**From alarm to a clear response**

An alarm sent to everyone quickly becomes one nobody takes seriously. focusAlert ingests events from WinCC, webhooks, SMTP, and other systems and routes them by your rules to the right group or person. What matters is what happens next: who picks it up, what gets escalated, and all of it stays traceable.

**Capabilities**

- Ingest events from heterogeneous sources and evaluate them with rules
- Hand alarms to groups, shifts, on-call rotations, or named owners
- Make acknowledgments, escalations, and responses traceable
- Bridge operations and incident workflows across IT, OT, and production

**Outcomes**

- Respond faster when something goes wrong in operations
- No alarm fades out without a clear owner anymore
- A clear trail of who did what and when, across shifts and on-call

**Supported protocols and channels**

focusAlert reads events from plant, monitoring, and mail systems and delivers them over the right channels. Inbound sources and outbound channels can be extended modularly.

- Event sources: WinCC, Webhook, SMTP, SNMP trap
- Notify targets: Email, SMS, Voice call, Browser push, Microsoft Teams, Slack, Telegram, Webhook

_Rule engine._ Rules decide who is reached, when, and over which channel. Configured in a few clicks, with no programming required.

- **Event**: From WinCC, webhook or mail
- **Evaluate**: Priority, group, shift, time
- **Escalate**: Parallel or one after another, with delay
- **Deliver**: Email, phone or push
- **Acknowledge**: Acceptance and feedback

For edge cases, every stage is fully scriptable. That is rarely necessary.

In practice:

- **Water utilities**: A pumping station reports a pressure drop. The control room has to react at once. (WinCC -> prio 1 -> Phone -> until acknowledged)
- **Industry & production**: A line fault during the night shift. Only the group on duty is woken. (SMTP -> shift group -> one after another -> escalate to lead)
- **IT support**: Monitoring reports an unstable service. focusAlert waits out a grace period in case it recovers on its own. (Webhook -> wait 1 min -> Email + Push -> on-call)

**From source to acknowledgment**

Agents on the source systems capture every event. focusAlert evaluates it with rules, groups and escalation to decide who is reached and how. Delivery then runs over the right channel.

**Multi-tenant and cleanly separated**

focusAlert isolates everything through Teams. A Team bundles groups, recipients, rules, clients, and tokens, fully separated from every other Team.

- **Teams as tenants**: Each Team encapsulates groups, users, recipients, rules, and integrations. Data access is filtered per Team on the server side.
- **Separate environments**: Development, staging, and production run as their own Teams with their own tokens and rules, so configurations never mix.
- **Dedicated access per system**: Every client and integration gets its own token, bound to a single Team.
- **Groups, order, and escalation**: Within a Team, groups, notification order, and escalations decide who is reached and when.

**A look inside focusAlert**

Groups, rules, and receivers stay separate by task and share one event trail.

- Configurator: routing groups, each with its team, rule, and receivers.
- Rules: pre-actions, filters, actions, and conditions decide what happens to an event.
- Receivers: configure retries and manage each person's registered push devices.

**FAQ**

- Q: Does focusAlert replace existing SCADA alarms?
  A: No. focusAlert takes relevant events from existing systems and governs notification, escalation, acceptance, and traceability.
- Q: Which channels does focusAlert support?
  A: Typical channels are email, phone, and browser push. The selection depends on urgency, role, group, and operating mode.
- Q: How are alerts acknowledged?
  A: Recipients can accept alerts or provide feedback. These states feed escalation, history, and analysis.
- Q: Is focusAlert multi-tenant?
  A: Yes. Organizations, groups, rules, recipients, and integrations can be operated separately and administered cleanly.

**Getting started.** We review your sources, groups, on-call models, and escalation paths, then shape a first alerting scope that relieves operations quickly.
