Alert rules
A rule says what to watch, how far ahead of expiry to act, which clients it covers and how you are told.
Before you start
Section titled “Before you start”- You need the owner or admin role. Other roles can read the Alerts page but the editing controls are hidden. See Roles and permissions.
- To use the PSA ticket channel, connect a PSA first. See PSA integrations.
Create a rule
Section titled “Create a rule”- Open Alerts and select Add rule.
- Under Applies to, choose Certificates or Domains. This cannot be changed after the rule is saved.
- Under Trigger, pick a preset of 90, 60, 30, 14, 7 or 1 day, or type any number of days from 1 to 365.
- Under Covers, leave All clients in this workspace or pick a single client.
- Turn Email on or off. Leave the address list empty to use your owners and admins, or type specific addresses and press Enter after each one. A rule holds up to 20 addresses.
- Turn PSA ticket on if you want a ticket. Choose the Provider if more than one PSA is connected.
- Leave Rule is active on, and select Create rule.
A plain-English summary of the rule appears above the buttons as you edit, for example “Certificates for all clients expiring within 30 days: email 2 owners and admins and raise a HaloPSA ticket.”
Edit, pause or delete
Section titled “Edit, pause or delete”- Select a rule in the list to open it, change what you need, and select Save changes. The scope is fixed, everything else can be changed.
- Use the switch on the rule row to pause it. Paused rules never fire, and existing alerts are unaffected.
- To remove a rule, open it and select Delete rule. Alerts that have already fired stay in the history.
- Reset replaces every rule, including client-specific ones, with the recommended ladder: certificates at 60, 30, 7 and 1 days, and domains at 60, 30 and 7 days.
Duplicate rules are refused
Section titled “Duplicate rules are refused”Two rules with the same scope, the same threshold and the same client would raise and send the same alert twice, so Tidehawk refuses to create the second one. The drawer disables Create rule and explains which rule already covers it. Change the threshold, the scope or the client to save.
Editing is treated differently. If a workspace already holds a duplicate pair, the drawer warns you but still lets you save, so you can fix the recipients or channels on either rule before deleting one.
What happens next
Section titled “What happens next”The next evaluation run picks the rule up within 15 minutes. It applies to everything already in your inventory, not only to items discovered after the rule was created, so a new rule can produce alerts immediately for certificates that are already close to expiry.
Limits and edge cases
Section titled “Limits and edge cases”- The threshold must be between 1 and 365 days.
- A rule must keep at least one channel. Turning both off blocks Save.
- Turning the PSA channel off clears the provider stored on the rule.
- With no PSA connected, the PSA switch is disabled and the Alerts page links you to Integrations.
- A rule with the PSA channel on but no provider chosen raises no ticket. The rule summary says so.
- Certificates on the auto renewal track ignore the rule’s threshold and use a shorter, validity-scaled window instead. See How alerts work.