Skip to main content
This runbook explains day-to-day operations for monitors, alerts, and channel delivery.
Monitoring is available on Pro and Advanced plans. See osint.ly/pricing for current limits.

Daily operations

1

Review monitor health

Open Monitoring and scan active monitors, last run timestamps, and recent alert volume.
2

Triage new alerts

Prioritize alerts by severity and target criticality before updating workflow status.
3

Validate channel delivery

Confirm email and Discord webhook delivery for alerts generated in the last period.
4

Clean obsolete monitors

Pause or delete monitors that are no longer part of active investigations.

Monitor configuration standards

FieldStandard
Monitor nameInclude case or client identifier + target
FrequencyStart daily, then increase only if investigation needs it
TypeMatch target shape (Email Registration, Global Search, Module Query)
OwnershipKeep monitors inside the correct solo or team workspace

Alert workflow

Initial state after alert creation. Requires triage.
Analyst is validating signal quality and impact.
Investigation action completed and no pending follow-up.

Failure patterns and actions

  • Confirm monitor is active
  • Confirm target and type are valid
  • Verify schedule frequency
  • Check whether the underlying data source has new events

Capacity and cost hygiene

  • Keep high-frequency monitors only for high-priority targets
  • Review monitor count weekly against plan limits
  • Use history and project context to avoid duplicate monitors
  • Archive resolved investigations to keep alert queues actionable
If monitor creation is blocked, the workspace has reached plan monitor limits. Remove obsolete monitors or upgrade plan.