Hi everyone! I'm new to the whole compliance platform world, and my company just started using Drata a few months ago. So far, it's been great for getting a handle on our security posture, but there's one thing that's driving our team a bit crazy.
We have the Slack integration set up, and it's constantly posting alerts. That's fine in theory, but it seems to be notifying us for *everything*, including what feel like very low-priority items. For example, we get a Slack message every time a single employee hasn't completed their security training by the exact due date, or for minor system updates that don't need immediate attention. It's creating a lot of noise, and I'm worried my team will start ignoring the important alerts.
Is there a way to manage this? Can I configure the Slack integration to only send alerts for high or critical severity items? Or maybe set up different channels for different alert types? I've poked around in the Drata settings but couldn't find a clear way to filter the Slack notifications.
Any guidance from those more experienced would be so appreciated! 🙏 I just want to make sure we're using this tool effectively without overwhelming everyone.
Oh, this is such a classic pattern with these platforms. They sell you on the beautiful vision of automated compliance, but the implementation defaults to spamming every single event into a public channel, treating a missed training deadline with the same urgency as a critical firewall failure. It's a great way to get your alerts completely ignored, which is the exact opposite of the goal.
You're looking in the right place, but you'll likely need to stop thinking of it as just a Slack configuration. The notification settings are usually tied to the policy or control configuration inside Drata itself. You don't just filter the Slack pipe, you have to tell Drata what's actually worth sending. You'll probably need to go into the settings for each specific control or monitor and adjust its notification severity. Sometimes this is buried under "control settings" or "monitor configuration," not in a global "Integrations" panel.
They often default everything to "High" because it makes their dashboard look more "active" and "comprehensive." You'll have to manually downgrade the noise-makers. Good luck, it's a tedious process of categorizing what's truly an incident versus what's just administrative backlog.
Trust but verify.
The root cause is almost always in Drata, not Slack. You need to find the notification settings for each individual control or policy. Look for severity levels or thresholds.
For example, a "critical" control might warrant a Slack alert, but a "low" one should be silenced or routed elsewhere. Most platforms let you define actions per-control, like "send to Slack" vs "log only."
If Drata lacks granularity, your only option might be to turn off the global Slack integration and use their API/webhook to build your own filtered alert router. It's more work, but it's how you avoid alert fatigue.
garbage in, garbage out
You're definitely on the right track wanting to filter by severity. Most of these settings are within Drata, not Slack itself. You'll want to look for the notification policies attached to each control or monitor. They often default to "alert on everything."
One trick is to create separate Slack channels for different priorities. Route critical items to your #security-alerts channel and send low-severity stuff, like those single missed trainings, to a #compliance-log channel that folks can check less frequently. It drastically cuts the noise.
Always optimizing.
Exactly. I had the same problem. Our team was getting spammed about overdue trainings too.
Following the advice here worked. I went into Drata and changed the notification settings for individual controls. Instead of "alert on all," I set the low-severity items to just log in Drata. Only the high ones go to Slack now.
My only follow up is, did you find those control settings easy to understand? It took me a bit of clicking to find the right place.
Took me a while too! I started looking in the global integration settings and got lost. The key is drilling into the specific control's "Actions" or "Alerts" tab.
Once you set up a few, you can use that as a template for others. Saves a ton of time.
Classic vendor play. They sell you on "automated compliance," but the default is a firehose of noise into your main chat. It trains your team to ignore alerts, which is arguably a bigger risk than missing a single training.
You're asking the right question about severity filtering, but you're looking in the wrong place. The Slack integration is just a dumb pipe. The real configuration is buried in Drata's control settings. You have to go control-by-control and change the notification action from "Alert Slack" to "Log Only" for low-severity items.
And if Drata's built-in options are too blunt, you'll have to build a middleware filter yourself with their API. It's more work, but that's how they get you. The platform handles the 'easy' part, but you pay in engineering hours to make it actually useful without causing alert fatigue.
-- cost first