Skip to main content
An alert destination is a place CostGraph sends alerts as they happen: a Slack channel, a Microsoft Teams channel, your own webhook, a PagerDuty service, or an email list. Each destination has routes that decide which alerts it receives. Organization owners and admins manage destinations under Settings > Alert destinations.

Add a destination

1

Open alert destinations

Go to Settings > Alert destinations and click Add destination.
2

Pick a type

Select Slack, Microsoft Teams, Webhook, PagerDuty, or Email list, and give the destination a name, such as FinOps on-call.
3

Fill in the connection

Enter the details for the type you picked. The following table lists what each type needs.
4

Add routes

Click Add route and choose the alerts this destination receives. A destination with no routes receives nothing.
5

Send a test

Save the destination, then click Send test on its tile to check that alerts arrive.
Each type needs its own connection details: When you edit a destination, leave a URL or key blank to keep the current value. CostGraph never shows a saved URL or key again. A webhook destination shows its signing secret once, when you create it. Copy it then. See Webhooks for the payload and how to verify the signature.

Routes

A destination receives an alert when any of its routes matches. Each route filters on:
  • Notification type: one alert type, or All notifications.
  • Minimum severity: any severity, info and above, warning and above, or critical only.
  • Minimum cost impact: a monthly amount. Alerts without a cost impact always pass this filter.
  • Tenant: one tenant, or All tenants.
  • Virtual tag and Tag value: only alerts for spend with that tag value. Pick a tenant first.
Alerts that go out immediately can be routed: critical anomalies, budget thresholds, forecast breaches, sync and data problems, and billing notices. The weekly digest is email only. See Anomaly alerts. CostGraph doesn’t send the same alert about the same resource to a destination twice within a cooldown. The cooldown is a week for cost alerts, one to three days for operational alerts, and a day for billing alerts.

Email lists

An email list sends each alert to a set of people:
  • Members: specific people in your organization.
  • Roles: everyone who holds the role when the alert is sent, so the list follows your team as it changes.
  • Group addresses: shared inboxes outside CostGraph, such as finops@example.com.
Members who can’t access an alert’s tenant don’t receive it. A group address must confirm before it receives alerts. After you create the list, enter the address and click Send confirmation. CostGraph emails a Confirm this address link that expires in three days. The address shows as Pending until someone opens the link and confirms, then Confirmed. You can resend a confirmation after an hour. If mail to a confirmed address bounces or is marked as spam, the address goes back to pending on every list.

Delivery health

Each destination tile shows its state: Delivering, Failing, Paused, or No deliveries yet, with the time of the last delivery and the last failure. Click Deliveries for the last 100 attempts and why any failed. CostGraph retries a failed delivery for up to 24 hours, waiting longer between attempts, and honors a destination that asks it to slow down. It doesn’t retry when the destination rejects the alert or isn’t set up correctly. After five such failures in a row, CostGraph pauses the destination and tells your organization owners and admins. Fix the destination, then click Resume. Use Pause to stop a destination without deleting it.

Self-hosted

On a self-hosted deployment, alerts leave from your own cluster, so the destination must be reachable from it. Email lists are available only when your deployment can send email.