Owners and administrators configure workspace security email under
Settings → Notifications. Notifications report activity; they do not allow
or block a tool call.
Recipients
Workspace owners and administrators are always included. You can also record a
shared mailbox or PSA intake address.
Adding an address sends a confirmation email. The address receives no alerts
and cannot receive a test until the recipient confirms it. Do not rely on an
unconfirmed recipient.
Event delivery
Events are grouped by access changes, tool activity, sign-in and location, and
the weekly summary. Available delivery modes are:
Immediate: send shortly after the event.
Daily: group matching events into the daily email.
Weekly: used by the Monday security digest.
Off: do not send that event by email.
The portal marks event types that are not yet available. Leave those off; their
presence in Settings is not evidence that Stackyapper is sending them.
Expected locations
Add the two-letter country codes where workspace members and AI clients are
expected to connect. A connection from another country contributes to
location-event classification.
Expected locations affect notification context only. They are not an access
allowlist and do not replace identity, workspace, or tool policy.
Client-address retention
Choose how much client-address detail is stored with audited calls:
Full: whole address, with the greatest forensic detail.
Truncated: IPv4 /24 or IPv6 /48.
Off: no client address.
Location alerts use network and country context rather than the complete
address, so reducing address retention primarily reduces later forensic detail.
Choose a setting consistent with your organization's privacy and investigation
requirements.
Verify a change
After changing notification settings:
Confirm the selected workspace.
Reopen the section and verify the saved delivery modes.
Send a test only to a verified recipient.
Review expected countries and retention separately; neither is an event
delivery mode.