For Admins and Supervisors.
Overview
The Inbox filter panel is organized into six filter groups: Basic information, Advanced Options, Participants, Supervision, Policies, and Source. Filters apply the same way across all four workflow tabs (Pending, In Review, Escalations, Closed); the Closed tab adds a seventh group, Closed Information. See Search and filter alerts in the Inbox for the step-by-step procedure.
Filters
Filter | Group | Values | Behavior |
Keyword or Alert ID | Basic information | Free text | Matches an exact phrase and ignores surrounding symbols. Supports a comma-separated list of terms — matches alerts containing any of the listed terms. No wildcard support today. |
Date Range | Basic information | Two dates, plus a preset dropdown (for example, Custom Date) | Limits results to alerts within the selected date range. |
Risk Level | Advanced Options | Low / Medium / High | Multi-select. Leaving all unselected returns the same results as selecting all three. |
Assignee | Advanced Options | Dropdown of Admin and Supervisor users, defaults to Any | Lists the compliance users who can be assigned alerts — that is, users with the Admin or Supervisor role. Limits results to alerts assigned to the selected user. The same filtered list of users powers the Closed by filter on the Closed tab. |
Attachments on Messages | Advanced Options | Attachment / No Attachment | Multi-select. Leaving both unselected returns the same results as selecting both. |
Noise on Messages | Advanced Options | Noise / Not Noise | Multi-select. Leaving both unselected returns the same results as selecting both. See Archive search filters reference for what "Noise" means. |
Participant Search | Participants | Type-ahead search, zero or more entries | Search for and add participants to filter by. Each match can be a specific identity (for example, one email address or Bloomberg chat ID) or a person's (All) entry, which matches every identity that person uses across all their communication channels. Each added participant gets its own direction control — limit that participant to alerts where they sent, received, or either — and a delete icon to remove them from the list. |
Matching condition | Participants | Match Any / Match All / Match Only | Controls how multiple selected participants combine. Match Any — the alert involves at least one listed participant. Match All — the alert involves every listed participant, and may also involve others not listed. Match Only — the alert involves exclusively the listed participants, with no other people included. Only relevant when two or more participants are selected. |
Supervision Group | Supervision | A single User Group, or No Specific Group | You can select one User Group at a time. Each alert carries exactly one User Group tag — or none, for account-level alerts — based on the detection policy that generated it. See How alert visibility and assignment work in the Inbox. |
Policy Module | Policies | Search/dropdown (for example, "Any Policy Module (156 Policy modules)") | Limits results to alerts generated under the selected policy module. Narrows the Lexicon list to lexicons belonging to that module. Shows only active modules unless Include Archived Entities is selected. |
Lexicon | Policies | Search/dropdown, dependent on Policy Module | Limits results to alerts matching the selected lexicon. Narrows the Term list to terms belonging to that lexicon. Shows only active lexicons unless Include Archived Entities is selected. |
Term | Policies | Search/dropdown, dependent on Lexicon | Limits results to alerts matching the selected term. Shows only active terms unless Include Archived Entities is selected. |
Include Archived Entities | Policies | Checkbox | Policies, Lexicons, and Terms form a hierarchy, and each level can be individually archived. An archived entity is no longer used to detect new compliance violations, so by default the Policy Module, Lexicon, and Term dropdowns show only active entities. Selecting this checkbox expands all three dropdowns to also include archived entities — shown greyed out and labeled (Archived) — for finding alerts that were triggered before an entity was archived. |
Source | Source | Checkbox list of configured communication sources | Limits results to alerts from the selected source(s). |
Closed Date Range | Closed Information (Closed tab only) | Two dates, defaults to the last 30 days | Filters by the date the alert was closed. |
Closed Status | Closed Information (Closed tab only) | Resolved / Resolved Escalation | Multi-select. |
Closed by | Closed Information (Closed tab only) | Matches against the same list of Admin and Supervisor users as Assignee | Filters by who closed the alert. |
NOTE: The Closed tab table also adds Closed Date and Closed By columns.
