Skip to main content

Inbox alert filters reference

This article provides a reference for every filter available when reviewing alerts in the Inbox.

For Admins and Supervisors.

Overview

The Inbox filter panel is organized into six filter groups: Basic information, Advanced Options, Participants, Supervision, Policies, and Source. Filters apply the same way across all four workflow tabs (Pending, In Review, Escalations, Closed); the Closed tab adds a seventh group, Closed Information. See Search and filter alerts in the Inbox for the step-by-step procedure.

Filters

Filter

Group

Values

Behavior

Keyword or Alert ID

Basic information

Free text

Matches an exact phrase and ignores surrounding symbols. Supports a comma-separated list of terms — matches alerts containing any of the listed terms. No wildcard support today.

Date Range

Basic information

Two dates, plus a preset dropdown (for example, Custom Date)

Limits results to alerts within the selected date range.

Risk Level

Advanced Options

Low / Medium / High

Multi-select. Leaving all unselected returns the same results as selecting all three.

Assignee

Advanced Options

Dropdown of Admin and Supervisor users, defaults to Any

Lists the compliance users who can be assigned alerts — that is, users with the Admin or Supervisor role. Limits results to alerts assigned to the selected user. The same filtered list of users powers the Closed by filter on the Closed tab.

Attachments on Messages

Advanced Options

Attachment / No Attachment

Multi-select. Leaving both unselected returns the same results as selecting both.

Noise on Messages

Advanced Options

Noise / Not Noise

Multi-select. Leaving both unselected returns the same results as selecting both. See Archive search filters reference for what "Noise" means.

Participant Search

Participants

Type-ahead search, zero or more entries

Search for and add participants to filter by. Each match can be a specific identity (for example, one email address or Bloomberg chat ID) or a person's (All) entry, which matches every identity that person uses across all their communication channels. Each added participant gets its own direction control — limit that participant to alerts where they sent, received, or either — and a delete icon to remove them from the list.

Matching condition

Participants

Match Any / Match All / Match Only

Controls how multiple selected participants combine. Match Any — the alert involves at least one listed participant. Match All — the alert involves every listed participant, and may also involve others not listed. Match Only — the alert involves exclusively the listed participants, with no other people included. Only relevant when two or more participants are selected.

Supervision Group

Supervision

A single User Group, or No Specific Group

You can select one User Group at a time. Each alert carries exactly one User Group tag — or none, for account-level alerts — based on the detection policy that generated it. See How alert visibility and assignment work in the Inbox.

Policy Module

Policies

Search/dropdown (for example, "Any Policy Module (156 Policy modules)")

Limits results to alerts generated under the selected policy module. Narrows the Lexicon list to lexicons belonging to that module. Shows only active modules unless Include Archived Entities is selected.

Lexicon

Policies

Search/dropdown, dependent on Policy Module

Limits results to alerts matching the selected lexicon. Narrows the Term list to terms belonging to that lexicon. Shows only active lexicons unless Include Archived Entities is selected.

Term

Policies

Search/dropdown, dependent on Lexicon

Limits results to alerts matching the selected term. Shows only active terms unless Include Archived Entities is selected.

Include Archived Entities

Policies

Checkbox

Policies, Lexicons, and Terms form a hierarchy, and each level can be individually archived. An archived entity is no longer used to detect new compliance violations, so by default the Policy Module, Lexicon, and Term dropdowns show only active entities. Selecting this checkbox expands all three dropdowns to also include archived entities — shown greyed out and labeled (Archived) — for finding alerts that were triggered before an entity was archived.

Source

Source

Checkbox list of configured communication sources

Limits results to alerts from the selected source(s).

Closed Date Range

Closed Information (Closed tab only)

Two dates, defaults to the last 30 days

Filters by the date the alert was closed.

Closed Status

Closed Information (Closed tab only)

Resolved / Resolved Escalation

Multi-select.

Closed by

Closed Information (Closed tab only)

Matches against the same list of Admin and Supervisor users as Assignee

Filters by who closed the alert.

NOTE: The Closed tab table also adds Closed Date and Closed By columns.

Did this answer your question?