Configure alerts & email digests
Get notified when cost behaviour changes: either as real-time webhooks to a chat channel, or as a periodic email summary.
Both live on the Alerts hub (it’s the single Notifications home; Email Digests is a tab there). Alerts is an explicit sidebar entry under Govern.
Webhook alerts (Teams / Slack / generic JSON)
Section titled “Webhook alerts (Teams / Slack / generic JSON)”Alerts work out of the box. When your first cloud connects, leancosts sets up an e-mail channel addressed to the workspace owner plus three rules, so you are notified without configuring anything:
| Default rule | Fires when… |
|---|---|
| Forecast increase | Projected month-end creeps ≥ 3% week-over-week and ≥ $500, or the burn jumps ≥ 8% vs the same week last month |
| Daily spend drift | The last 7 days’ mean daily spend is ≥ 25% above the prior baseline and the implied weekly excess is ≥ $200 |
| Monthly budget breach | The projected month-end exceeds the monthly budget you set on the Costs page (inert until you set one) |
These carry a default badge on the Alerts page. Edit or delete them like any other. Deleting them is permanent; they are never re-created. They do not count against your plan’s alert limits.
To send alerts somewhere else instead, add a webhook channel below. A rule that binds no specific channels delivers to all active channels, so a webhook you add later also receives the default rules.
At most 3 cost-alert e-mails per channel per day go out; anything beyond that is shown on Recent events as suppressed, never silently dropped.
Newly detected cost anomalies (spikes and drops) are also delivered to your channels automatically: one notification per anomaly, carrying the scope, direction, severity, and the actual/expected/delta amounts. Every notification includes an Open in leancosts link back to the relevant page (Costs for spend alerts, the Savings Register for anomalies).
1. Add a channel
Section titled “1. Add a channel”Alerts → Channels → New channel. First pick Deliver to:
E-mail: just a name and an address. Nothing else to configure.
Webhook: provide:
- a name and the destination URL (any HTTPS webhook works),
- a template:
teams_adaptive_card,slack_block_kit, orgeneric_json, - an optional HMAC secret: when set, deliveries are signed with
x-finops-signature: sha256=<hex>so the receiver can verify authenticity.
The form shows inline setup steps for the selected template: exactly how to obtain the webhook URL in the destination app:
- Microsoft Teams (
teams_adaptive_card): in Teams open the channel → ⋯ → Workflows → template “Post to a channel when a webhook request is received” → Add workflow → copy the generated POST URL. (The classic Office 365 “Incoming Webhook” connector has been retired; Workflows replaces it.) - Slack (
slack_block_kit): at api.slack.com/apps create/open an app → Incoming Webhooks → on → Add New Webhook to Workspace → copy thehooks.slack.com/services/…URL. - Generic JSON (
generic_json): any HTTPS endpoint. For Discord, use a channel webhook (Channel → Edit → Integrations → Webhooks → New Webhook → Copy URL).
Hit Test to fire a synthetic event and confirm the endpoint returns 2xx.
2. Add a rule
Section titled “2. Add a rule”Alerts → Rules → + Rule. Pick a metric and bind one or more channels:
| Metric | Fires when… |
|---|---|
Cost drift (daily_cost_drift) | the mean daily spend of the last 7 complete days rises ≥ driftPct% vs the prior 21-day baseline and the implied weekly excess spend is ≥ minDelta (needs at least 14 days of data) |
Forecast increase (forecast_increase) | the projected month-end creeps ≥ creepPct% week-over-week (+ ≥ creepMinUsd) or the current-week burn jumps ≥ burnPct% vs the same week last month: defaults 3% / $500 / 8% |
Volatile spend (volatile_spend) | the day-to-day variability (stddev ÷ mean) of the last 14 daily totals crosses the threshold % (needs at least 14 days of data) |
Budget forecast breach (budget_forecast_breach) | the projected month-end exceeds the monthly budget set on the Costs page. No threshold to configure on the rule; just enable it and pick channels. Never fires while no budget is set |
Defaults for drift/volatility are 25% / 200; for forecast increase, 3% creep / $500 / 8% burn. Rules apply at the account/organization scope. All metrics are evaluated weekly; a known one-time spike (an open spike anomaly) suppresses drift and forecast alerts so you are not paged twice for the same event.
Setting the monthly budget: on Costs → Monthly trend, use Set monthly budget (admins only). The trend then shows a dashed budget line and a “projected $X of $Y budget” stat, the same number the Budget forecast breach rule fires against. The budget covers every cloud, so when the page is narrowed to one cloud, a region or a cohort, the trend shows the budget alone (“for the whole org”) and no line.
Edit a rule
Section titled “Edit a rule”Alerts → Rules → Edit on a rule opens the same form under the row. You can
change the thresholds and the channels it delivers to (and switch it
Disable / Enable from the row). The name and the metric stay fixed: to
watch something else, create a new rule. With no channel selected, every
active channel receives the rule. An agent can do the same with the
update_alert_rule tool; see Use with an agent.
3. Confirm delivery
Section titled “3. Confirm delivery”Alerts → Recent events lists fired events. Each entry shows the rule name (or
“Test event”), a plain-language summary of what fired, and a delivery-status badge
(delivered / failed / pending); the raw JSON payload is one click away behind a
View payload toggle. Failed deliveries retry up to 3 times with linear backoff.
Email digests
Section titled “Email digests”A unified savings digest delivers a weekly (or daily) summary with two sections: What you saved (realized measured savings + ROI) and New waste found (the top open findings from Opportunities).
If you can manage connections, it carries a third block, Connections needing attention: the connectors whose credential is expiring or already expired (Azure client secrets, GitHub fine-grained tokens and Azure DevOps tokens). Each line says where the date came from, so a date you typed is never presented as one we verified. AWS access keys and the OpenAI / Anthropic admin keys do not expire and never appear.
There is also a Savings report digest (register_report): the Savings
Register report emailed with the board PDF and full CSV attached. Recipients
are admin-managed org members. Trigger it on-demand from Opportunities
(Email report) or set a recurring cadence (Schedule…). Alongside realized
impact, open claim, and closure rate, the summary (and the PDF) reports the money
left on the table (the open savings claim not yet saved, counted day by day
since the first daily reading) so leadership sees the cost of delay, not just
the backlog. The attachments show money in each recipient’s
display currency, the same as the email body. For a workspace billed in reais
the PDF is written in Portuguese.
- Go to Alerts → Email Digests (or Settings → Email).
- Subscribe and choose your cadence. Subscriptions are user-owned.
- Preview renders the email against your data before you commit.
Unsubscribe is one click and works without an active session: the emails carry
standard List-Unsubscribe headers, so Gmail/Outlook show their native
unsubscribe button. Admins can force-send a digest for incident response.