← Back to blog

Revenue Alerts That Reach Your Team

A finding on a dashboard helps no one if the right person never sees it. Finno notification channels send revenue anomaly and abuse alerts to Slack, email, Telegram, WhatsApp, or your own webhook — in the language you choose.

Finno notification channels — outbound alerts when revenue anomalies need attention.

Picture this: Friday evening, low traffic, finance has gone home.

At 19:03 Finno’s revenue anomaly detection loop detects a settlement failure on a gateway node — requests were served, money moved in the ledger, but settlement to a provider did not complete. Money at risk: $18,000. Severity: critical.

The finding sits on the Anomalies page. Perfectly visible — if someone is looking.

Nobody is.

Monday morning finance reconciles the week and discovers a gap that could have been a two-line fix on Friday night if anyone had been paged.

Dashboards do not wake people up. Channels do.

What notification channels are (and are not)

Finno notification channels are outbound integrations configured in the admin dashboard. When a qualifying event happens — usually an anomaly or abuse investigation case opening or escalating — the dashboard dispatcher formats a message and delivers it to the channel you chose.

This runs on the cold path. It does not sit in Reserve or Finalize. Your API latency stays what it was.

Channels are not a replacement for Prometheus or Grafana. They are not generic log streaming. They are opinionated messages about revenue and integrity events Finno already understands, with severity, money at risk, and links back to the finding or case.

If you already live in Slack for incidents, you can meet Finno there instead of building a custom poll of our REST API.

Where you can send alerts

Today you can configure:

  • Webhook — POST a signed JSON payload to your incident system, internal automation, or a bridge you maintain.
  • Slack — via an incoming webhook URL on your workspace.
  • Email — SMTP, with optional authentication, suitable for finance distribution lists.
  • Telegram and WhatsApp — for teams that operate there (common in some regions and on-call rotations).
  • SMS — for a small set of ops mobiles, via a webhook channel named sms and an admin phone number in configuration.

Each channel has its own minimum severity, event types, cooldown, and message language (English or Persian templates are built in). You might send critical anomalies to SMS and high investigation cases to Slack #billing-ops, while email carries a daily-friendly summary list.

Which events actually fire

Typical event types include:

  • anomaly.opened — the first time a non-shadow finding matches this channel’s filters.
  • anomaly.escalated — severity increased on an existing finding (for example, from high to critical as exposure grew).
  • fraud.opened — a new investigation case crossed your configured threshold.
  • fraud.escalated — case severity went up after additional signals arrived.

Shadow-mode statistical anomalies — the ones Finno calculates quietly while you calibrate baselines — never notify. That prevents experimental detectors from paging you before you trust them.

Cooldowns prevent the same incident from generating twenty messages in an hour when the detector refreshes the same episode.

What the message contains

Messages are meant to be actionable, not dumps.

You should expect:

  • A short title (“Settlement failure on gw-prod-2”).
  • Severity and money at risk when the detector computed it.
  • Subject hints (service, consumer, node — depending on detector).
  • A path back to the admin UI to acknowledge or resolve.

For email, Telegram, and WhatsApp, Finno uses the language you set on the channel so Persian-speaking ops teams are not stuck reading English boilerplate.

Delivery log and test button

Every attempt is recorded in notification_deliveries: success or failure, error text from SMTP or the webhook, timestamp, channel id, linked finding or case.

Before go-live, use the test action on a channel to send a synthetic message. Verify Slack permissions, SMTP TLS, and Telegram bot tokens before the first real settlement failure — not during it.

If a delivery fails, the log tells you whether to fix credentials, DNS, or a firewall rule — without guessing.

Operator alerts vs consumer alerts

Do not confuse notification channels (ops-facing) with proactive consumer alerts (customer-facing).

When a end-user’s wallet balance drops below a threshold or postpaid credit consumption crosses a warning band, Finno can email or SMS that consumer through a separate business-events loop — “your balance is low,” “you are at 90% of credit limit.”

That is customer success and churn prevention.

Notification channels are for your team when your books or pipeline need attention.

Both can coexist; they solve different problems.

Setting up without alert fatigue

A common mistake is pointing every anomaly at Slack with severity “low.” You will mute the channel within a week.

A saner starting point:

  1. Send critical ledger and settlement findings to an immediate channel (Slack + SMS for someone on call).
  2. Send fraud.opened at high and above to a billing ops room.
  3. Leave statistical shadow detectors alone until you promote them on the board.
  4. Use cooldowns of at least a few minutes per channel.

Finno ranks revenue anomaly findings by money at risk precisely so the first message in a real incident is usually worth opening — not another generic CPU graph.

Getting started

Configure channels under Notifications in the admin dashboard. If SMTP or Telegram must route through internal relays, contact us — deployment patterns for restricted networks are a common question.

For how anomalies, abuse investigation, and channels fit together, see Revenue assurance.