Email alerts
Who gets emailed about an incident, which incidents qualify, and why you might not have been told.
Email is the only notification channel today. There is no Slack integration, no webhook, no SMS.
What triggers an email
An incident has to be critical:
- A sales drop of 70% or more
- Your site is down (outages are always critical)
A warning incident — a 40–69% drop — opens on your dashboard and emails nobody.
The single most common surprise
A 55% revenue drop creates an incident and sends no email. If you are relying on email alone to know something is wrong, you will miss everything between 40% and 70%.
Check the Incidents list periodically, or ask through Need help? to have your threshold lowered to warning.
Who receives it
Organization owners only. Not every member, not the person who added the site.
If the owner's inbox is the wrong destination, the current workarounds are a forwarding rule, or a shared address as the owner account.
What the email contains
- Subject:
[ChangeTrace] Critical incident: Revenue dropped 74% vs 7-day average - The severity, the site domain and the incident title
- A View incident button linking straight to the page
It does not contain ranked causes. The email is sent the moment the incident is created, and correlation runs up to 30 minutes later — so by the time you click through, the causes are usually there. Incident lifecycle →
Turning them off
Settings → Notifications → Incident email alerts.
The switch covers the whole organization. Off means nobody gets incident email — incidents still open and appear in the dashboard as normal.
Why you did not get an email
Working through it in order:
Was the incident critical?
Warning-severity incidents do not email. Check the severity chip on the incident.
Are alerts switched on?
Settings → Notifications.
Are you an owner?
Only owners are emailed. Members are not.
Check spam
Alerts come from a ChangeTrace address. Allow-list it.
Was there an incident at all?
Sales-drop detection covers the four cases where ChangeTrace deliberately stays quiet — not enough history being the usual one on a new site.
No duplicates
Each incident emails at most once. A re-run of the detector cannot produce a second incident for the same site, metric and day, so it cannot produce a second email either.
A multi-day slump does email you each day, because each day is genuinely a new incident.
{ }For developers
Threshold is ALERT_SEVERITY_THRESHOLD (default critical) on the ladder info < warning <
critical. Recipients come from memberships with role owner. Delivery is via Resend and never
throws — a send failure is logged and the detector run continues. With no API key configured the
service logs the message instead of sending, so a self-hosted deployment needs no mail provider.

