Set up alerts
You need an admin role in the Kontext workspace.- Open Settings → Notifications.
- Under Slack risk alerts, select Connect Slack and approve the connection in Slack.
- Choose an Alert channel.
- Turn on Send confirmed risk findings.
What gets sent
Kontext sends an alert when both of these are true:- Kestrel, Merlin, or the additional shell check flagged the call. See detection.
- The AI assessment rated the call risky.
What the message contains
The alert heading names the severity and primary category, for example “High risk finding · External service or resource change”. Kontext includes these fields below the heading:
The Open Risk in Kontext link opens the Risk page. Find the call in Flagged tool calls and follow the steps in investigate a finding.
When alerts pause
Kontext pauses AI assessments and Slack alerts for the rest of the billing cycle when a Free workspace reaches its monthly transaction limit. The channel receives one “Kontext risk alerts paused” message with the date alerts resume. You can also resume alerts by upgrading. Policies keep running on your endpoints during the pause.If no alert arrives
- Check that the call appears in Flagged tool calls on the Risk page.
- Check its Severity column. Pending means the assessment has not finished. No risk means Kontext sends no alert for the call.
- Check that Send confirmed risk findings is on and an Alert channel is set.
- Check that the Kontext Slack app can post to that channel.