
Anatomy of an alert
A rule has five parts:- A measure and an aggregation: what to compute, such as
p95of latency,sumof cost, or acountof spans. - Filters: which spans are counted, such as only LLM spans, one model, or one environment.
- A window: how far back each evaluation looks, from 1 minute to 2 hours.
- A trigger: an operator and a threshold the result is compared against.
- Notification settings: what an empty window means, and whether a standing breach repeats.
How evaluation works
TraceRoot checks active rules once a minute. Each rule is measured again once it can hold new data: a rule with a window of 5 minutes or less is measured at its own window’s pace, and wider windows are measured every 5 minutes. Each window ends 30 seconds behind the clock so spans that are still arriving are counted. Every evaluation gives the rule a severity:- OK: the value is within the threshold.
- Alert: the value breaches the threshold.
- No Data: the window had nothing to measure.
Beyond the UI
Alerts can also be managed outside the Alerts page:- Public API: six routes under
/api/v1/public/alertslist, create, read, update, pause or resume, and delete rules. - CLI: the
traceroot alertscommands (list,get,create,update,status,delete). See the CLI guide for installing and signing in. - AI agent: the in-app agent can read rules (
list_alerts,get_alert) and, with your approval, change them (create_alert,update_alert,set_alert_status,delete_alert).
Where to start
Get Started
Create your first alert and check it against the live preview.
Rule Reference
Measures, units, aggregations, windows, filters and states.
Slack Delivery
Connect Slack and read the messages an alert sends.
Detector Notifications
Email and Slack digests for new and reopened detector signals.

