See all monitors →
Docs

Alert severity levels: how Relvato decides what's critical

A site with a few dozen monitors can produce a lot of results, and not all of them deserve to wake you up. Relvato gives every alert one of five levels, from Critical to Warning, decided by what stopped working — a checkout that can't take payment, a login that won't let people in, a page that got slower — never by how alarming the error message sounds. The rules are fixed, written in Relvato's code and the same for every account, so the same failure always gets the same level. This page lists them, and shows how to choose which levels reach you.

The five levels

Critical means money or the site itself is at stake right now. High means people can't get in or reach the site, or the site may be compromised. Medium means something real broke while sales and sign-ins still work. Low is housekeeping. Warning is a caveat on a run that passed, or a heads-up about your setup.

The table below lists what lands at each level. The rest of this page explains the rules behind it.

How a failed monitor gets its level

When a monitor fails, its level comes from what that monitor watches. Monitors on the buying path — checkout, payment, cart and orders — are Critical: a failure there loses sales every minute it lasts. Security monitors are High: the vulnerability scan, file and theme integrity, the admin roster, third-party scripts, the exposure scan and signs of a hack. They're listed by name, not guessed from their wording, so none of them can slip to a lower level and get silenced by a High threshold.

The domain itself — its registration, its DNS and its certificates — is High, because a lapsed domain or a hijacked record takes the whole site down. Sign-in and availability are High too: login, sign-up and account monitors, uptime and SSL. Email authentication (SPF, DKIM and DMARC) is Medium: it's about whether your mail is delivered, not about logging in.

Everything else that fails is Medium: the storefront, visual regression, structure drift, Core Web Vitals, contact forms, custom monitors and the rest. They're real failures worth knowing about, but customers can still buy and sign in. A run that passed but carries a soft finding is a Warning.

Alerts that aren't about one run

Some alerts come from what Relvato did rather than from one monitor's run, and they have fixed levels too. If a plugin update broke a monitor and Relvato couldn't roll it back, that's Critical: the site is broken and nothing undid it. If Relvato did roll it back, that's High: the site works again, but the fixed version you wanted is held back and a known vulnerability may be open again.

In Quarantine mode, after a clean-up, an unexpected high-risk change is Critical and any other unexpected change is High. If the Relvato plugin stops answering, that's Critical, because the monitors that depend on it go blind. Account-level alerts follow the same thinking: a failed payment for your Relvato plan is Critical; reaching the monthly run limit or Slack or webhook alerts stopping are High; a Relvato plugin update being available is Low; a setup heads-up, such as the Web Vitals beacon not being active, is a Warning.

What never counts as a failure

A run that couldn't happen isn't a failure, and it doesn't alert as one: the firewall blocked Relvato, the site didn't answer, the plugin didn't reply, or the monitor still needs setup. The run shows Couldn't run with the reason, so you can fix the cause, but it isn't treated as the site breaking.

Monitors that drive a real browser get up to three attempts before a failure counts, because a page can time out once for no lasting reason. Monitors that read data — a vulnerability lookup, a checksum comparison — run once, because a retry can't change the answer.

A monitor that keeps flipping between passing and failing — three passes that needed a retry, or four status flips, in its last ten runs — is marked Flaky — alerts paused while it settles, and its alerts pause until it passes cleanly five times in a row. Security monitors are never paused this way: when one flips, the site really changed, and every change is a finding.

When an alert is sent

A monitor alerts when it goes from passing to failing. If it keeps failing on the next runs, you aren't told again — the failure stays at the top of your dashboard and the bell until it's fixed. A failure you dealt with in Relvato, by accepting a new baseline or ignoring the findings, counts as passing again, so the next real failure alerts. A monitor you run by hand alerts every time it fails, because you're waiting for the answer.

Quarantine mode is the one exception to your settings: you put a just-cleaned site there to be interrupted, so its alerts go out at once, whatever your threshold and digest choices, on the channels your plan includes.

Choose which levels reach you

In Relvato, open Alert settings and pick a level under Alert me on: Warnings and up — everything, Low and up, Medium and up, High and up, or Critical only. The default is Medium and up. The choice applies to email, Slack and webhook alerts and to the daily or weekly digest. Anything below it is still recorded on the run and shown in the bell; it just doesn't interrupt you.

The same page mutes whole sites and routes monitor types to particular channels — checkout failures to Slack, everything else to email, for example. Each alert shows its level: a coloured badge in emails and digests, a Severity line in Slack, and a severity field in the webhook payload, so your own tools can route on it too.

What lands at each level

LevelWhat it meansExamples
CriticalSales or the whole site are at stake nowCheckout, payment, cart or order monitor fails · a plugin update broke a monitor and couldn't be rolled back · an unexpected high-risk change in Quarantine mode · the Relvato plugin is offline · your Relvato payment failed
HighPeople can't get in or reach the site, or it may be compromisedLogin, sign-up, account, uptime or SSL monitor fails · a security monitor finds something · domain registration, DNS or a certificate is at risk · a plugin update broke a monitor and was rolled back · monthly run limit reached · Slack or webhook alerts stopped
MediumSomething real broke, but sales and sign-ins still workStorefront, visual regression, structure drift, Core Web Vitals, contact form or custom monitor fails · email authentication (SPF, DKIM, DMARC) fails
LowHousekeepingA Relvato plugin update is available
WarningA caveat on a passing run, or a setup heads-upA passing run with a soft finding · the Web Vitals beacon isn't active · monitors pause soon because the plugin hasn't been seen

FAQ

Can I change the level of one monitor?

No. A monitor's level comes from what it watches, the same for every account, so a Critical alert always means the same thing. You control what reaches you instead: the threshold, muted sites and which monitor types go to which channel, all in Alert settings.

Why is a Core Web Vitals regression only Medium?

A slower page costs conversions, but customers can still buy; a broken checkout stops every sale. With the default threshold, Medium and up, you're still told about it.

Why didn't I get an alert for a failing monitor?

Usually one of these: it's below your threshold; it was already failing, so there's no repeat alert; it's paused as flaky; it couldn't run, for example because a firewall blocked Relvato; the site is muted; or the channel isn't on your plan. The run itself always shows what happened.

Does AI decide how severe an alert is?

No. The level comes from fixed rules in Relvato's code. Relvato AI can explain a failure and suggest a fix, but it never changes a level or decides whether you're alerted.

What's the difference between Low and Warning?

Low is something to act on when convenient, such as updating the Relvato plugin. Warning is a heads-up that didn't stop anything: a caveat on a run that passed, or a setup detail worth a look.

Related reading
Docs

Get the alerts that matter, where you'll see them

Pick your threshold once, route the urgent ones to Slack, and let the rest wait for the digest.