-
Type:
Bug
-
Resolution: Unresolved
-
Priority:
Medium
-
Component/s: Alerts - Query / Results / Filters, Alerts - Status / Details
-
None
-
Severity 3 - Minor
Issue Summary
Users have visibility to see alerts in their Alerts tab when they are not a responder on the alert.
This occurs when they are added as a responder at alert creation. Following - an alert policy applies to the alert and removes/replaces the responder. Users who were a responder at creation, and no longer after the policy is applied, can still view the alert.
Steps to Reproduce
- Create a Global Alert policy that removes or replaces the responder(s).
- Create an alert. Responder added at creation can be a user. If the responder is a team, then there needs to be members of the team to demonstrate they can view that team's alerts.
Expected Results
Users / responders should no longer have visibility into the alert since they are no longer a responder.
Actual Results
Users / responders have visibility into the alert even though they are no longer a responder.
Workaround
NA
Findings
Here is a test to confirm this behavior:
Other
This can also be reproduced through an integration. For example; create a test alert like the one above via API, and add a responder to the body.
Then - have the integration remove any responders at creation. Responders added at creation / removed by integration still would have visibility into seeing this alert even though they are no longer a responder on it:
- mentioned in
-
Page Loading...