{"templateId":"markdown","sharedDataIds":{"sidebar":"sidebar-sidebars.yaml"},"props":{"metadata":{"markdoc":{"tagList":[]},"type":"markdown"},"seo":{"title":"Email Notifications","description":"Control the power of AI Agents in runtime.","llmstxt":{"hide":false,"sections":[{"title":"Table of contents","includeFiles":["**/*"],"excludeFiles":[]}],"excludeFiles":[]}},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"email-notifications","__idx":0},"children":["Email Notifications"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Deliver Capsule policy-violation notifications as email, so your team sees AI agent and shadow-AI signals in the inbox they already watch."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"overview","__idx":1},"children":["Overview"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["When a policy you've linked is violated, Capsule sends an email to an address of your choice. The email summarizes the violation - severity, policy, affected entity, and time - with a ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["View in Capsule"]}," link back into the portal."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The address can be a personal inbox or a distribution / security-group address. Capsule sends one message to the address you configure; it doesn't distinguish between the two, so fanning a group address out to its members is your mail platform's job."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["You can add more than one email channel and link each to different policies, so (for example) high-severity violations go to your on-call distribution list while everything else goes to a shared triage inbox."]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"header":{"controls":{"copy":{}}},"source":"Capsule policy violation\n  → Capsule sends an email via Capsule's email provider\n  → email arrives at the address you configured\n"},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"sender-identity","__idx":2},"children":["Sender identity"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Capsule notification emails come from:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"header":{"controls":{"copy":{}}},"source":"Capsule Security <sender@mail.capsulesecurity.io>\n"},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["To keep delivery reliable, ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["allow-list this sender"]}," (add it to your safe-senders list, or ask your mail administrator to allow-list it at the gateway). Allow-listing the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["mail.capsulesecurity.io"]}," sending domain covers it. Security-alert email that lands in spam is email your team won't act on."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"prerequisites","__idx":3},"children":["Prerequisites"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Before you begin, ensure you have:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["An ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["email address"]}," where you want Capsule notifications to arrive (a personal inbox, or a distribution / security-group address)"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["A ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Capsule Security"]}," account with admin access"]}]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"1-configure-the-channel-in-capsule","__idx":4},"children":["1. Configure the channel in Capsule"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Log in to the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Capsule Security"]}," portal."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Go to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Settings → Notifications"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Add channel"]}," and choose ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Email"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Enter a ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["display name"]}," (how this channel appears in Capsule) and the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["email address"]}," to notify."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Save & Test"]},"."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"what-the-test-actually-proves","__idx":5},"children":["What the test actually proves"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Save & Test"]}," sends a real test email to the address you entered. The test email is clearly labeled as a test - its subject is ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["[Capsule] Test notification"]}," and its body confirms the channel is configured correctly."]},{"$$mdtype":"Tag","name":"blockquote","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["A passing test means Capsule's email provider ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["accepted"]}," the message for delivery - not that it reached the inbox. After the test succeeds, confirm the email actually arrived. If nothing shows up within a minute, check the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["spam / junk"]}," folder, then double-check the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["spelling of the address"]},", then confirm the sender is ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["allow-listed"]}," (see ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"#sender-identity"},"children":["Sender identity"]},")."]}]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"2-what-the-emails-contain","__idx":6},"children":["2. What the emails contain"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["A notification email includes:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Severity"]}," - Critical, High, Medium, or Low, shown prominently as a colored banner"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Policy"]}," - the policy that was violated"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Entity"]}," - the affected agent or entity"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Category"]}," - the kind of signal that triggered the notification"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Time"]}," - when the violation occurred (in UTC)"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["A ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["View in Capsule"]}," button that deep-links to the violation in the portal"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["A test email is clearly marked as a test and omits the severity banner and the View in Capsule button, so it's never mistaken for a real alert."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"footer-manage-in-capsule-not-unsubscribe","__idx":7},"children":["Footer: Manage in Capsule, not unsubscribe"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Notification emails carry a ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Manage in Capsule"]}," link to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Settings → Notifications"]}," - there is deliberately ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["no unsubscribe link"]},". These are team destinations, often shared inboxes, so turning a channel off is an admin action in Capsule, not a one-click link that any single recipient could use to silence the whole team's security alerts."]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"3-link-the-channel-to-policies","__idx":8},"children":["3. Link the channel to policies"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["An email channel only receives notifications for the policies you link to it. On the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["policy edit"]}," screen, add the email channel to the policy's notification channels - the same way you link any other notification destination. Link as many policies as you want; a channel with no linked policies stays idle."]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"rate-limits","__idx":9},"children":["Rate limits"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["To protect deliverability, Capsule caps how many emails it sends - ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["per destination each hour"]}," and ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["per tenant each month"]},". When a cap is reached, further emails to that destination (or across the tenant) are ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["suppressed"]}," until the window resets, at which point sending resumes automatically. Suppressed sends are recorded in Capsule's delivery log, so nothing is lost silently."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The defaults are ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["20 emails per hour per destination"]}," and ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["1,000 emails per month per tenant"]},". These are defaults, not fixed limits - they're configurable for your deployment."]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"troubleshooting","__idx":10},"children":["Troubleshooting"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Test passes, but no email arrives."]}," A passing test means Capsule's email provider accepted the message, not that it was delivered. Check the recipient's ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["spam / junk"]}," folder, confirm there's ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["no typo"]}," in the address, and make sure ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["sender@mail.capsulesecurity.io"]}," is ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["allow-listed"]}," so your mail gateway doesn't quarantine it (see ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"#sender-identity"},"children":["Sender identity"]},")."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["The channel row shows an Error state."]}," Capsule flips a channel to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Error"]}," when delivery to that address is failing - typically because the mailbox has been removed or the receiving server is rejecting the mail. ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Edit"]}," the channel and fix the address (or point it at a working mailbox). A successful delivery clears the error and returns the channel to Active."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Emails stopped, and the delivery log shows \"Sending paused\" / suppressed sends."]}," This is rate limiting - a per-destination hourly or per-tenant monthly cap was reached (see ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"#rate-limits"},"children":["Rate limits"]},"). No action is needed; sending resumes automatically when the window resets."]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"support","__idx":11},"children":["Support"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For help with this integration:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Email"]},": support@capsule.security"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Include"]},": Your organization ID, the affected channel's display name, and any error shown on the channel row"]}]}]},"headings":[{"value":"Email Notifications","id":"email-notifications","depth":1},{"value":"Overview","id":"overview","depth":2},{"value":"Sender identity","id":"sender-identity","depth":2},{"value":"Prerequisites","id":"prerequisites","depth":2},{"value":"1. Configure the channel in Capsule","id":"1-configure-the-channel-in-capsule","depth":2},{"value":"What the test actually proves","id":"what-the-test-actually-proves","depth":3},{"value":"2. What the emails contain","id":"2-what-the-emails-contain","depth":2},{"value":"Footer: Manage in Capsule, not unsubscribe","id":"footer-manage-in-capsule-not-unsubscribe","depth":3},{"value":"3. Link the channel to policies","id":"3-link-the-channel-to-policies","depth":2},{"value":"Rate limits","id":"rate-limits","depth":2},{"value":"Troubleshooting","id":"troubleshooting","depth":2},{"value":"Support","id":"support","depth":2}],"frontmatter":{"seo":{"title":"Email Notifications"}},"lastModified":"2026-07-22T15:37:08.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/guides/email-notifications","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}