Help / Alerts & goals / Alerts

Alerts

For everyone who reads the numbers · ~7 min read · Last reviewed 22 July 2026

Every morning at 06:00 UTC, after the nightly data refresh has landed, six detectors sweep every client and write down what changed for the worse. You do not configure them, schedule them, or feed them — they are the smoke detectors of the building: silent until something is actually burning. This page lists what each one watches and where the findings go.

Where alerts surface

  • The client’s Alerts tab — the full feed for one client, newest first, filterable by severity (All / Critical / Warning / Info), with pagination for the long haul.
  • The Alerts item in the sidebar and the header bell — both open the alerts view for your current client.
  • A grouped email digest — when a morning run finds anything new, one email summarising the findings by severity goes to the alert recipients configured by whoever operates your SeoKestrel instance (an operator setting, not a per-user one). A Slack channel can be configured the same way.

The six detectors

DetectorWhat it watchesWhen it fires
Traffic dropOrganic clicks, week over week, on settled Search Console windowsDrop > 20 % (info), > 30 % (warning), > 50 % (critical). Skipped when the baseline week had under 50 clicks.
Rank dropDesktop positions day over day, for keywords that were in the top 30Drop > 5 positions (info), > 10 (warning), > 20 (critical) — up to the 20 worst per client per day.
CWV regressionLCP, FCP, CLS, INP, and TBT per monitored URL and device, against Google’s official thresholdsA metric crossing into a worse category. Good straight to poor is critical; any other worsening crossing is a warning.
Lost backlinkBacklinks from high-authority domains (domain rank 50+)A qualifying link marked inactive in the last day. DR 50+ is info, 65+ warning, 80+ critical.
Featured snippet lostKeywords that held the top of the results page yesterdayThe keyword now ranks below position 3. Landing at 4–10 is a warning; below 10 is critical.
Index exclusionPages excluded from indexability between the two most recent SeoSwift crawl censuses3+ newly excluded pages that are also ≥ 1 % of the site (warning); 10+ and ≥ 5 % (critical).

The index-exclusion detector inherits the Site Health honesty rules: it compares two censuses only when they are at most a week apart, the site has at least 20 pages, and the crawl total moved no more than 20 % between them — a crawl-scope shift is never reported as an indexation event. Its alert also says what it means: crawl-detected states, not Google’s index verdict. See Site health.

How often, and how loudly

  • One run per day, at 06:00 UTC — after the night’s Search Console, analytics, rankings, and Core Web Vitals ingestion, so detectors judge tonight’s numbers, not yesterday’s.
  • Deduplication — the same client + detector + resource combination fires at most once per 23 hours. A keyword still down tomorrow produces tomorrow’s alert, not a rerun of today’s.
  • Three severities — info, warning, critical. The digest email groups findings by severity; the operator can raise the minimum severity that gets emailed at all.

Good to know

  • Detectors never block anything and never guess: a detector that hits missing data or an error for a client simply reports nothing for that client that day.
  • Alerts are the gauges-side of the OKRs & KPIs story: they tell you the moment a gauge moved, so the quarterly goals conversation is never the first place a problem surfaces.

FAQ

Something dropped — why did I get exactly one alert about it?
By design. Once an alert has fired for a given client, detector, and resource, the same combination will not fire again within 23 hours. A problem that persists produces one alert per day, not one per glance.
Can I change the thresholds?
No. The thresholds are fixed in each detector. What can be tuned — by whoever operates your SeoKestrel instance — is the minimum severity that goes out in the notification digest.
How do I mark an alert as handled?
You currently can’t — the alerts feed is a read-only history with severity filters, not a task list. If an alert needs work tracked against it, create the task where you track tasks; the alert stays as the record of when the problem was detected.
Traffic clearly dipped yesterday — why no traffic alert?
Two usual reasons. The traffic detector compares fully settled 7-day windows ending three days back, because Search Console finalises its numbers late — a dip from yesterday is not settled data yet. And clients with fewer than 50 clicks in the baseline week are skipped, since percentage swings on tiny numbers are noise. See Search insights for the same three-day lag elsewhere.