Effective communication is key to managing cybersecurity processes, and CSFaaS keeps stakeholders informed automatically: notifications are generated from workspace activity and routed to the people concerned, without per-event configuration.


1. How Notifications Work Today

Every meaningful action in the workspace is recorded in the activity log, and the relevant events reach members through three channels:

  • The Inbox: the bell in the header opens an inbox panel with your notifications. You can mark items read or unread (individually or in bulk), and every notification deep-links to the exact item it concerns.
  • Followed items: most items carry an activity bell. Follow an item and its events appear in your Inbox under "Items I follow", so you can watch exactly the frameworks, policies, risks or demands you care about.
  • Email: key events that need attention outside the app, such as workspace invitations and demand alerts, are also sent by email.

Routing is based on involvement: item owners, followers, requesters and approvers are notified about the items they are involved in. Billing alerts go to Account Managers.


2. What You Can Configure, and Where

Because routing is automatic, notifications need no dedicated settings tab. The related controls live where they belong:

  • Per user, in the Inbox: each member chooses what to follow through the activity bells; followed items feed their own "Items I follow" view.
  • Demand alerts, in Settings, Risk Demand: the Demand notifications list. Members holding the Analyst role are always alerted when a demand is submitted for review (drafts stay silent until then); you can add extra recipients, who are also notified when a requester updates a demand that was sent back for more information. If no extra recipients are configured, the page warns you that only Analyst-role members will be alerted.
  • Live presence, in Settings, Users: the workspace switches for live cursors and selected-item presence control the real-time awareness layer (who is working where), which complements notifications.
  • Email: transactional emails are automatic; there is nothing to configure.

See the Risk Demands documentation for how demand alerts fit the review workflow.


3. The Legacy Notifications Tab

Earlier versions of CSFaaS had a Notifications tab in Workspace Settings with a per-category matrix of notification rules. That tab has been retired: notification routing is now automatic and consistent across modules, and the only recipient list you still manage by hand is the demand alert list described above.

Tip: if someone is missing an alert, check three things: that they are a member of the workspace, that they hold the relevant role (for demand alerts, the Analyst role), and that they follow the item if it is a per-item event.