Alerts

Alerts

WAI Docs Wed Aug 19 13:22:37 EDT 2026
List
Quick Start
Welcome
Supported Applications & LLMs
Release Notes
August 18, 2026 WitnessAI Release
August 4, 2026 WitnessAI Release
July 21, 2026 WitnessAI Release
July 14, 2026 WitnessAI Release
July 9, 2026 WitnessAI Release
June 30, 2026 WitnessAI Hotfix
June 23, 2026 WitnessAI Release
June 16, 2026 WitnessAI Release
June 11, 2026 WitnessAI Release
June 4, 2026 WitnessAI Hotfix
June 2, 2026 WitnessAI Update
May 19, 2026 WitnessAI Update
April 30, 2026 WitnessAI Update
April 28, 2026 WitnessAI Update
April 23, 2026 WitnessAI Update
April 16, 2026 WitnessAI Update
April 14, 2026 WitnessAI Update
April 9, 2026 WitnessAI Update
April 9, 2026 WitnessAI Update
April 7, 2026 WitnessAI Update
April 2, 2026 WitnessAI Update
March 31, 2026 WitnessAI Update
March 24, 2026 WitnessAI Update
March 19, 2026 WitnessAI Update
March 17, 2026 WitnessAI Update
March 12, 2026 WitnessAI Update
March 5, 2026 WitnessAI Update
February 26, 2026 WitnessAI Update
February 24, 2026 WitnessAI Update
February 10, 2026 WitnessAI Update
January 27, 2026 WitnessAI Update
January 20, 2026 WitnessAI Update
January 13, 2026 WitnessAI Update
December 18, 2025 WitnessAI Update
December 9, 2025 WitnessAI Update
November 25, 2025 WitnessAI Update
November 18, 2025 WitnessAI Update
November 11, 2025 WitnessAI Update
October 28, 2025 WitnessAI Update
October 23, 2025 WitnessAI Update
October 9, 2025 WitnessAI Update
October 2, 2025 WitnessAI Update
September 30, 2025: WitnessAI Update
September 23, 2025: WitnessAI Update
August 12, 2025: WitnessAI Update
July 31, 2025: WitnessAI Update
July 18, 2025: WitnessAI Update
April 11, 2025: WitnessAI Release v2.0
June 9, 2025: WitnessAI Update
June 23, 2025: WitnessAI Update
TOC Left Sidebar: not active
TOC Left Sidebar: ORIGINAL
User Guide
Policies - GuardRails
Witness Anywhere: Remote Device Security
Witness Attack
Administrator Guide
404
 

Alerts

💡
Note the Alerts Console Redesign was released October 2, 2025
See the Release Notes here.
The Alerts section displays real-time alerts triggered by WitnessAI Policies and Guardrails. These notifications can be used to inform security teams, managers, or individual users about high-risk events, policy violations, or other significant activities.
Alerts can be forwarded to a number of popular SIEM platforms, as documented in the User Guide → Settings → Configuration → SIEM Integrations section.
The Alerts feature is vital for ensuring rapid response to potential issues and maintaining control over AI interactions within the organization.
WitnessAI navigation and top-level filters are described and shown in detail on the https://docs.witness.ai/v2-0/console/ documentation page. Please refer to that resource if the instructions below are not sufficient.
WitnessAI Alerts console showing a full list of alerts with columns including Risk Type, Date, Event Start, Alert type, Applications, Username, User Group, Policies. Multiple alert rows are visible with various risk types highlighted in different colors (red for high risk). The left sidebar shows navigation options.
Navigate to the Alerts console by clicking “Alerts” in the left-side navigation menu. To collapse the left-side menu and have more room to view extra columns in the page, just click the left-pointing arrow button shown in mid-page of the left side menu, close to the right side of the “Policies” menu item.

Time Range and Filters

The console includes the standard time range selector. Top-level filters for groups, users, and applications are on the second header line. Once any filters are set, a “Clear” button appears to the right of the top-level filters, as shown in the image below. When the Clear button is clicked, it resets all filters to their default, except the date field.
Note that switching between console views resets the date to “Last 7 days".
Additional top-level filters include “Group”, “User”, and “Application”.
WitnessAI Alerts console showing Time Range and Filters. The page header shows date/time filters, Group, User, Application, and Action filters. A ‘Clear’ button is visible on the right side to reset filters. The alerts list shows various alert types with risk indicators.

Alert Count, Exporting Data and Choosing Columns

The third line of the page header displays “nnnn Total Alerts in last n days” for the chosen time range. On the right side of the screen, an “Export” widget and a “Column Chooser” icon are displayed.

WitnessAI Alerts console header showing ‘113 Alerts in last 7 days’ alert count, with an Export button (with dropdown arrow) for downloading alerts as CSV or JSON, and a Column Chooser icon on the right side for customizing which columns to display.

 
Export enables an export of the current page of filtered Alerts showing on the console, in CSV or JSON format. By default this is set to 250 Alerts.
💡
Note that only the default count of items displayed on the page are exported, not the full set that match the filter.
 

WitnessAI Alerts Column Chooser panel showing available columns with checkboxes: Risk, Risk Type, Date, Intent, User, Username, Email, Application, Policy (all checked). An Export button and Column Icon are visible at the top. Columns have drag handles (6-dot handle) to reorder them.

 
Column Chooser lets you pick the columns you want to view and export. Click the Column Icon (looks like an open book), then click to ‘check’ the columns you want to display on the console.
Click and drag the 6 dot handle to change the order of columns to your preference.
 

WitnessAI Alerts Column Chooser panel showing a reordered list of columns after dragging: Risk, Risk Type, Intent, Date, User, Username (partially visible). Demonstrates how to reorder columns using the 6-dot drag handles. An Export button and Column Icon are at the top.


Column Changes

Additional Columns: UserName, Email, Policy, Action, and Subtopic.
The “Prompt” column has been removed. Prompts are viewable in the right-side “Alert Details” slide-out sidebar by clicking any individual Alert row.
Provider Logos in the Application column and Action badges in the Action column provide instant “at-a-glance” understanding of your Alerts.
The Alerts console provides filtering, searching, customization options, and an improved “Alerts Page” to help you locate and review specific alerts.
WitnessAI Alerts console showing Column Changes with new columns including UserName, Email, Policy, Action, and Subtopic. The alerts list shows multiple entries with application provider logos in the Application column and action badges. An Alert Details sidebar is visible on the right showing alert details with Conversation section.

Column Filters

Column filter and sort are only available for the ”Date” column in the current release. Hovering over the text of the Date column header changes your mouse cursor from an arrow into a link pointer. Clicking one time displays an upward-facing arrow next to the Date label, and sorts the table in ascending chronological order (newest alerts at the top).
Clicking a second time displays a downward-facing arrow, and sorts the table in descending chronological order (oldest alerts at the top).
A third click makes the arrow disappear, and returns the table to the original sort. Generally this is ascending chronological order.

Alert Details Sidebar

Clicking any Alert row displays the slide-out “Alert Details” sidebar. The first view is the “Overview” tab as shown below, underlined in orange.
Clicking on the “Matches” tab (see below) shows additional information about the Alert.
 

WitnessAI Alert Details Sidebar showing the Overview tab for an ‘Illegal Activities’ category alert: ‘None’ prompt blocked by Model Protection guardrail (High Risk, Blocked). Shows Policy (North Central Legal Department v56, Jims Policy), Guardrails (Model Protection - prompt injection detected), Conversation preview, Prompt text (a jailbreak attempt using ‘LiveGPT’ persona), and Classification section.

 

WitnessAI Alert Details Sidebar showing the Matches tab for a ‘Data Leakage’ alert: ‘Draft contract agreement’ prompt redacted by Data Protection guardrail (High Risk, Redacted/Warning/Allowed). The Matches tab shows ‘Data Protection 2’ matches with a prompt containing redacted personal information (names and financial transaction details).

File Attachments In Alerts

Blocked attachments will generate alerts in the Alerts console. Alerts with blocked file attachments will display the text “Confirm File Upload” in the Intent column.
The sidebar displays the details of the alert.
WitnessAI Alerts console showing File Attachments in Alerts. The alerts list shows entries with ‘Confirm File Upload’ in the Intent column. The Alert Details sidebar on the right shows details of a file attachment alert with ‘Document content scanned’ information, a blocked file attachment, and conversation details.