Alerts
Pro can tell you when an agent behaves unusually, so you don’t have to watch the audit log. There are two alerts, both per agent:
| Alert | Fires when | Default |
|---|---|---|
| Repeated denials | One agent is denied this many times within the period | 10 denials in 10 minutes |
| Unusual activity | One agent makes this many calls within the period | Off |
Set them in Settings → Alerts. Enter 0 to turn an alert off. The period (1–1440 minutes) applies to both. See Settings.
Where alerts go
Section titled “Where alerts go”Alerts go to the same places as approval notifications: the email addresses in Settings → Notify these emails about new approvals (or the site admin email), and the Slack incoming webhook if you set one.
An alert names the agent, says how many denials or calls it counted and over how many minutes, suggests what to check, and links to the audit log. For example: “Claude Desktop was denied 10 times in the last 10 minutes.” It contains no input and no secrets.
How often
Section titled “How often”- Each alert is sent at most once per agent and alert type in each period, however many more calls follow.
- Alerts are sent in the background, so they never slow down the agent’s call.
- All unknown agents are counted together, as “Unknown agents”.
- Denials caused by the kill switch are not counted, because they are expected while it is on.
- For the unusual-activity alert, Raqvio Agent Guardrails checks the count at most once a minute per agent.
What to do when you get one
Section titled “What to do when you get one”Open the audit log and look at the agent’s recent calls.
- Repeated denials usually mean the agent is misconfigured, or is trying something you haven’t allowed. Allow the ability if the agent needs it, or pause the agent.
- Unusual activity can mean a runaway loop in the agent. Pause the agent, or turn on the kill switch to stop every agent at once. A rate-limit rule can cap calls automatically.