Learn which email notifications Cobalt sends and how to control them.
Cobalt sends email notifications to keep you informed about activity in your organization, your pentests and your findings. The notifications you receive depend on your role, whether you collaborate on a pentest, and your notification preferences.
Your default preference applies to every pentest you are added to. To change it:
Changing your default does not change preferences you have already set on individual pentests.
You can override your default preference for any pentest you collaborate on.
To stop all email for a pentest, set the pentest to Muted and unfollow any findings you are following.
You automatically follow findings you comment on or are assigned to. To follow or unfollow any finding, open the finding and select the bell icon. Users who follow a finding receive notifications about it even when the pentest is muted.
The tables below list the email notifications Cobalt sends to customer users and who receives them. Pentest and finding notifications are also subject to your notification preferences.
| Notification | When it is sent | Who receives it |
|---|---|---|
| Pentest created | A new pentest is created (saved as a draft) in your organization. | All organization users except the person who created it |
| Pentest submitted for review | A pentest is submitted to Cobalt and moves to In Review. | All organization users except the person who submitted it |
| Pentest deleted | A pentest is deleted. | Pentest collaborators |
| Pentester update posted | A pentester posts a team update on the Pentester Updates tab. | Pentest collaborators (customer side) |
| Report is ready | The pentest report moves to Final and is available to download. | Pentest collaborators |
| Retest period ending | The retest window for a pentest is approaching its end date. The email includes the number of findings still pending a fix. | Pentest team members |
| Mentioned in pentest chat | Someone @mentions you in the pentest Chat tab. | The mentioned user |
| Attachment removed | An attachment you uploaded to a pentest, engagement or finding is removed. | The user who uploaded the file |
| Notification | When it is sent | Who receives it |
|---|---|---|
| New finding reported | A pentester publishes a finding on your pentest. | Pentest collaborators, depending on notification preferences |
| Finding state changed | A finding moves to a new state, for example Pending Fix, Ready for Retest or Fixed. | Users following or participating in the finding, plus anyone mentioned |
| Finding assigned | A finding is assigned to someone, or an assignee is removed. | The new assignee and pentest collaborators |
| New comment on a finding | Someone comments on a finding, in the platform or through a connected ticketing tool. | Users following or participating in the finding, plus anyone mentioned |
| Mentioned in a finding comment | Someone @mentions you in a comment on a finding. | The mentioned user |
| Jira sync failed | Automatic push of a finding to your connected Jira project fails. | All organization users |
| Notification | When it is sent | Who receives it |
|---|---|---|
| Engagement created | A new engagement is created in your organization. | Organization Owners, collaborators and group members |
| Engagement deleted | An engagement is deleted. | Engagement collaborators |
| Engagement report is ready | An engagement report moves to Final. | Organization Owners and engagement collaborators |
| Mentioned in an engagement finding | Someone @mentions you in a comment on an engagement finding. | The mentioned user |
| Invited to collaborate on an engagement | You are invited to collaborate on an engagement. | The invited user |
| Added as a collaborator | You are added as a collaborator on a pentest or engagement. | The added user |
| Credential deletion reminder | Credentials shared for a pentest or engagement are pending deletion and still need your confirmation. | Organization Owners and users who provided credentials |
| Service request confirmation | You submit a service request from the Catalog. The email confirms the services requested and links to the scoping forms. | The user who submitted the request |
| Notification | When it is sent | Who receives it |
|---|---|---|
| Invited to an organization | You are invited to join an organization, as a new or existing Cobalt user. | The invited user |
| Added to an organization | You are added to an organization. The email includes your role. | The added user |
| Invited with a role | You are invited to an organization with a specific role, or your role is changed. | The invited user |
| Invited to collaborate on a pentest | You are invited to collaborate on a pentest as a user outside the organization. | The invited user |
| Added to a group | An Organization Owner adds you to a group. | The added user |
| Removed from a group | An Organization Owner removes you from a group. | The removed user |
| Notification | When it is sent | Who receives it |
|---|---|---|
| Unused credits reminder | Your organization has unused credits as the contract end date approaches. Reminders are sent at roughly 180, 90 and 60 days before the contract ends, with different messaging depending on how many credits remain. | Organization Owners and Members |
| Credits deducted | Credits are deducted from your organization balance. The email shows the previous and new balance and the reason. | Organization Owners and Members |
| Notification | When it is sent | Who receives it |
|---|---|---|
| Data removal scheduled | Your organization data is scheduled for removal on an upcoming date. A final reminder is sent closer to the date. | Organization Owners |
| Data retention extended | Your organization data retention period is extended. The email confirms the new removal date. | Organization Owners |
| Data removal complete | Your organization data has been removed from the platform. | Organization Owners |
| Notification | When it is sent | Who receives it |
|---|---|---|
| DAST scan complete | A DAST scan finishes. The email summarizes high, medium and low findings. | Organization Owners |
| DAST scan failed | A DAST scan fails. The email includes the failure reason. | Organization Owners |
| DAST target created | A new DAST target is created. | Organization Owners |
| DAST target deleted | A DAST target is deleted. | Organization Owners |
| Notification | When it is sent | Who receives it |
|---|---|---|
| Two-factor authentication enabled | You enable two-factor authentication on your account. | You |
| Two-factor authentication disabled | You disable two-factor authentication on your account. | You |
| Two-factor authentication required | Your organization turns on two-factor authentication enforcement and you have not set it up yet. | All organization users |
| Two-factor enforcement turned off | Your organization turns off two-factor authentication enforcement. | Affected organization users |
| Verify your identity | You start the account recovery flow and need to confirm your identity with a verification code. | You |
| Account recovery requested | A user in your organization confirms their identity and needs two-factor authentication turned off to regain access. | Organization Owners |
| Security settings updated | A security-sensitive setting on your account is changed. | You |
Account and security notifications are always sent and are not affected by notification preferences.
If you are not receiving emails from Cobalt: