Skip to main content
Back to blog
aws

An Alert Should Tell You What Changed, Not Just That It Did

Riya Mittal
Riya Mittal Engineer · Zop.Dev
4 min read
An Alert Should Tell You What Changed, Not Just That It Did

An Alert Should Tell You What Changed, Not Just That It Did

Most cloud alerting fails two ways: silent on the events that mattered, or so noisy you stop reading it.

It stays silent on the events you actually needed to know about, or it fires a stream of context-free notifications you quickly learn to ignore. Either way, when your cloud changes state, the alert does not tell you what moved, why it matters, or where to go next.

The answer is not more alerts. It is alerts that cover the right events and carry the facts of each one.

ZopNight now widens what raises an alert and, in Microsoft Teams, delivers each one as a card you can read and act on without leaving the channel.

The events that were happening without a signal

A cloud environment changes state constantly, and most of those changes used to pass without a signal. A schedule that started or stopped a resource. A whole resource group acted on at once. An override that expired. An automation rule that changed. A budget crossed, a bill moved, a cost anomaly surfaced, a remediation completed or failed, a report export finished. Each is a moment something in your account became different from how you left it.

Alert coverage now spans a subscribable catalog across five categories: Scheduling, Automation, Budgets and Billing, Cost Anomaly, and Remediation. These are the points where state changes, and where finding out after the fact means reconstructing the sequence from logs. Getting told at the moment turns that reconstruction into a card in a channel.

Architecture diagram

In Teams, a card instead of a line

Coverage is only half of it. A notification that says something happened, without saying what, sends you off to go find out. In Microsoft Teams, ZopNight now delivers each alert as a color-coded Adaptive Card built for the event it describes.

The card carries the facts that matter for that event type, a severity band so urgency reads at a glance, and cloud-account and resource-group names resolved to what you call them rather than raw identifiers. Provider labels are clean, so a Lambda event reads as AWS, not an internal string. And a one-click link takes you straight to the exact resource in ZopNight when the card is not enough. You triage in the channel and open the console only when you decide to act.

Raw notificationAdaptive Card in Teams
What happenedYou go find outOn the card
Which account and groupRaw identifiersResolved names
How urgentUndifferentiatedSeverity band, color-coded
Next stepSearch the consoleOne-click deep link

Subscribable, so coverage does not become noise

Wider coverage is a liability if every event reaches everyone. This catalog is subscribable, so each team receives the categories it owns and nothing else. You pick exactly which alerts you want from Alerts settings, and routing is per organization.

CategoryExample events
SchedulingManual and scheduled start and stop, resource-group actions, override expired
AutomationAutomation rule changes, autoscaler and event-readiness lifecycle
Budgets and BillingBudget crossed, billing alerts
Cost AnomalyAnomalous spend surfaced
RemediationApproval, completion, failure, ticket opened

When broad coverage helps, and when to keep it narrow

If one person watches one account, a narrow alert set is fine, and turning everything on would only add noise. Coverage earns its place the moment more than one team acts on shared infrastructure, where schedules, automation, and remediation all change state and no single person is watching all of it.

Subscriptions are what keep that from becoming the wall of notifications people mute. The goal was never to send more. It was to make sure the events that change your cloud reach the people who own them, in a form they can act on. Broad where it needs to be, quiet everywhere else.

Tagged
aws
Riya Mittal

Riya Mittal

Engineer · Zop.Dev

Riya works on the autonomous remediation engine at Zop.Dev. Before that she was a security engineer at a SaaS company that learned the hard way what 14 days of exposure looks like. She writes about cloud security, automation, and the trade-off between speed and safety.

Stop watching the waste.
Start cutting it.

See. Find. Fix. Automatic.

Connect your first cloud account in under 5 minutes. See your first remediation in under 7. No credit card required.

CDCR connect detect classify remediate
full audit every action traceable
read-only default access
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001 · zero-trust· 30% average cloud cost cut· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001 · zero-trust· 30% average cloud cost cut· 4 platforms · 1 console·