Agent-readable docs index: /llms.txt. Full docs in one file: /llms-full.txt. Download /docs.zip to grep all markdown files locally.

Notifications

Owners and admins configure workspace security email under Settings → Notifications. Notifications report activity; they do not allow or block a tool call. Every event, its default delivery mode, and the modes it accepts are listed below.

Recipients

Workspace owners and admins are always included. You can also add other email addresses that should receive security alerts.
Adding an address sends a confirmation email. The address receives no alerts and cannot receive a test until the recipient confirms it. Do not rely on an unconfirmed recipient.

Delivery modes

  • Immediate: send shortly after the event.
  • Daily: group matching events into the daily roll-up email.
  • Weekly: used only by the Monday security digest and its sections.
  • Off: do not send that event by email.
Not every mode applies to every event. Immediate and Daily apply to individual security events; Weekly applies only to the digest and its sections.

Security events

EventDefault modeAllowed modes
Managed identity access changedImmediateImmediate, Daily, Off
Administrative role grantedImmediateImmediate, Daily, Off
Destructive tool executedDailyImmediate, Daily, Off
Repeated denied callsImmediateImmediate, Daily, Off
App credential failureOff (not yet wired)Immediate, Daily, Off
New countryImmediateImmediate, Daily, Off
Destructive call from a new networkImmediateImmediate, Daily, Off
New network in a known countryDailyImmediate, Daily, Off
Failed sign-in burstOff (not yet wired)Immediate, Daily, Off
New AI client observedDailyImmediate, Daily, Off
Daily roll-up emailDailyDaily, Off
Weekly security digestWeeklyWeekly, Off
Destructive tool activity defaults to Daily to avoid alert fatigue in a busy write-enabled workspace; raise it to Immediate if your workspace runs few write operations.
Two event types remain off because they are not yet wired:
  • App credential failure: customer credential-health changes are not yet connected to the notification dispatcher.
  • Failed sign-in burst: a rejected sign-in does not always identify a workspace safely, so Stackyapper does not guess which company to notify.
New-country and new-network alerts begin only after a member has used at least one recorded network on ten separate days. This avoids treating a new workspace as an incident.

Weekly digest sections

The Monday security digest is the master switch; when it is off, no section is sent. Each section is either included (Weekly) or Off:
SectionDefault
Needs youOn
IdentityOn
AlertsOn
Access surfaceOn
Higher-risk activityOn
Denied callsOn
Dormant accessOff
Available evidenceOn
The dormant-access section is off by default because in a workspace's first weeks everything looks dormant.

Expected locations

Add the two-letter country codes where workspace members and AI clients are expected to connect. This records the workspace's expected operating locations for summary and investigation context.
Expected locations affect notification context only. They are not an access allowlist and do not replace identity, workspace, or tool policy.

Client-address retention

Choose how much client-address detail is stored with audited calls:
  • Full: whole address, with the greatest forensic detail.
  • Truncated: IPv4 /24 or IPv6 /48.
  • Off: no client address.
Country alerts do not require a stored complete address. New-network alerts use the retained IPv4 /24 or IPv6 /48 prefix, so choosing Off also disables prefix-based detection. Choose a setting consistent with your organization's privacy and investigation requirements.

What an email contains

No Stackyapper email contains tool arguments, data returned by a connected app, provider credentials, API keys, or session tokens. Security email reports identifiers and counts, not the contents of a call.
An immediate alert contains the event title and its fixed summary line, the actor's name and email address, the UTC timestamp, the country, the client address at your chosen retention level, the network operator, and a short set of event-specific facts — the audit action and the host or provider it targeted, a member's previous and new role, or the tool name, risk class, and self-reported AI client name. It closes with links to Audit and to notification settings, both of which require sign-in.
The daily roll-up lists event names and counts. The weekly digest adds tool names with call, denial, and prior-period counts, alongside active-user and retention figures. Both stay at the level of names and numbers.

Other Stackyapper email

EmailSent when
Workspace invitationAn owner or admin invites someone
Recipient confirmationAn address is added as a notification recipient
Test notificationAn admin sends a test
Access request receivedSomeone requests an approval-gated app
Access approvedA reviewer approves that request
Issue resolvedA problem you reported through stackyapper_report_problem is fixed
Only the recipient-confirmation email carries a link that grants anything: a single-use link, valid for seven days, that confirms one address for one workspace. An invitation carries no token at all — the recipient signs in with their own Microsoft 365 or Google account, and their verified address must match the invited address and the workspace domain, so a forwarded invitation grants nothing.
Mail arrives from noreply@stackyapper.dev or support@stackyapper.dev. Allow both if your filtering quarantines unfamiliar senders. Invoices and receipts come from Stripe under your billing contact, not from Stackyapper.

Verify a change

After changing notification settings:
  1. Confirm the selected workspace.
  2. Reopen the section and verify the saved delivery modes.
  3. Send a test only to a confirmed recipient.
  4. Review expected countries and retention separately; neither is an event delivery mode.