Alerts & Observability
The Arcform Control Plane includes a real-time Slack alert layer that surfaces governance events, ledger status changes, audit warnings, and attribute lifecycle events into dedicated workspace channels. No polling. No dashboards. Events arrive where your team already works.
Architecture
Entity automations → slackEntityAlert → slackAlert → Slack channels
The alert layer operates as a two-function pipeline. Entity automations fire on database record changes and invoke slackEntityAlert, which extracts the relevant context (category, severity, title, details) and forwards it to slackAlert, which formats and delivers the message to the correct Slack channel.
// Alert pipeline
Entity change event
→ Entity automation (trigger filter)
→ slackEntityAlert (context extraction + routing)
→ slackAlert (formatting + Slack API delivery)
→ #arcform-* channel (structured message)
The bot identity is Arcform Control Plane with a 🛡️ icon. Messages use Slack Block Kit for structured formatting with severity-coded indicators.
Channel Boundaries
Alerts are routed to four dedicated channels by governance domain. Each channel maps to a specific category of entity changes, ensuring clean separation and easy filtering.
#arcform-governancecategory: governanceEntities: SignerSet, KeyLineage
Events: Signer set rotations, threshold changes, key compromise, manual revocation
Severity range: warning / critical
#arcform-ledgercategory: ledgerEntities: EnvelopeLog
Events: XRPL anchor status transitions (pending → signed → anchored / failed / skipped)
Severity range: info / critical
#arcform-auditcategory: auditEntities: AuditLog
Events: Warning and critical-severity audit entries only (info filtered out)
Severity range: warning / critical
#arcform-attributescategory: attributesEntities: Attribute, Delegation
Events: Attribute issuance, revocation, expiry; delegation creation, scope changes, revocation
Severity range: info / warning / critical
Severity Levels
infoRoutine operations — identity activations, attribute issuance, successful anchoring.
warningAttention required — signer set updates, threshold changes, status transitions.
criticalImmediate action — key compromise, attribute revocation, anchor failures, signer set revocation.
Entity Automations
Six entity automations watch for changes across the governance data model. Some include trigger conditions to filter noise — for example, AuditLog alerts only fire on warning or critical severity, and EnvelopeLog alerts only fire when anchor_status changes.
| Automation | Entity | Events | Channel |
|---|---|---|---|
| Signer Set Changes | SignerSet | create, update, delete | #arcform-governance |
| Key Lineage Events | KeyLineage | create, update | #arcform-governance |
| Critical Audit Alerts | AuditLog | create (warning/critical) | #arcform-audit |
| Attribute Lifecycle | Attribute | create, update, delete | #arcform-attributes |
| XRPL Anchor Status | EnvelopeLog | update (anchor_status) | #arcform-ledger |
| Delegation Changes | Delegation | create, update | #arcform-attributes |
Message Format
Slack Block Kit structured messages
Each alert is delivered as a Block Kit message with a consistent structure:
// Message structure
🟡 Signer Set Updated — Treasury Signers
*DID:* `did:comms:ff7e...`
*Status:* `active` → `superseded`
*Threshold:* 2 → 3
Type: signer_set_updated • Severity: warning • Time: 2026-07-01T19:45:08.900Z
Design Principles
Channel isolationEach governance domain has its own channel. No mixing. Easy to mute low-priority domains without losing critical signals.
Noise filteringTrigger conditions pre-filter events before they reach the function. Only warning/critical audit entries and anchor_status changes trigger alerts.
Two-function pipelineslackEntityAlert handles context extraction and routing logic. slackAlert handles formatting and API delivery. Clean separation of concerns.
Severity-coded indicatorsEvery message carries a visual severity marker (🟢 🟡 🔴) and structured metadata footer for quick triage.
No pollingEntity automations fire on database writes. Alerts arrive in Slack within seconds of the triggering change.