DID.COMMSDOCS

Alerts & Observability

The Arcform Control Plane includes a real-time Slack alert layer that surfaces governance events, ledger status changes, audit warnings, and attribute lifecycle events into dedicated workspace channels. No polling. No dashboards. Events arrive where your team already works.

Architecture

Entity automations → slackEntityAlert → slackAlert → Slack channels

The alert layer operates as a two-function pipeline. Entity automations fire on database record changes and invoke slackEntityAlert, which extracts the relevant context (category, severity, title, details) and forwards it to slackAlert, which formats and delivers the message to the correct Slack channel.

// Alert pipeline

Entity change event

→ Entity automation (trigger filter)

→ slackEntityAlert (context extraction + routing)

→ slackAlert (formatting + Slack API delivery)

→ #arcform-* channel (structured message)

The bot identity is Arcform Control Plane with a 🛡️ icon. Messages use Slack Block Kit for structured formatting with severity-coded indicators.

Channel Boundaries

Alerts are routed to four dedicated channels by governance domain. Each channel maps to a specific category of entity changes, ensuring clean separation and easy filtering.

#arcform-governancecategory: governance

Entities: SignerSet, KeyLineage

Events: Signer set rotations, threshold changes, key compromise, manual revocation

Severity range: warning / critical

#arcform-ledgercategory: ledger

Entities: EnvelopeLog

Events: XRPL anchor status transitions (pending → signed → anchored / failed / skipped)

Severity range: info / critical

#arcform-auditcategory: audit

Entities: AuditLog

Events: Warning and critical-severity audit entries only (info filtered out)

Severity range: warning / critical

#arcform-attributescategory: attributes

Entities: Attribute, Delegation

Events: Attribute issuance, revocation, expiry; delegation creation, scope changes, revocation

Severity range: info / warning / critical

Severity Levels

🟢
info

Routine operations — identity activations, attribute issuance, successful anchoring.

🟡
warning

Attention required — signer set updates, threshold changes, status transitions.

🔴
critical

Immediate action — key compromise, attribute revocation, anchor failures, signer set revocation.

Entity Automations

Six entity automations watch for changes across the governance data model. Some include trigger conditions to filter noise — for example, AuditLog alerts only fire on warning or critical severity, and EnvelopeLog alerts only fire when anchor_status changes.

AutomationEntityEventsChannel
Signer Set ChangesSignerSetcreate, update, delete#arcform-governance
Key Lineage EventsKeyLineagecreate, update#arcform-governance
Critical Audit AlertsAuditLogcreate (warning/critical)#arcform-audit
Attribute LifecycleAttributecreate, update, delete#arcform-attributes
XRPL Anchor StatusEnvelopeLogupdate (anchor_status)#arcform-ledger
Delegation ChangesDelegationcreate, update#arcform-attributes

Message Format

Slack Block Kit structured messages

Each alert is delivered as a Block Kit message with a consistent structure:

// Message structure

🟡 Signer Set Updated — Treasury Signers

*DID:* `did:comms:ff7e...`

*Status:* `active` → `superseded`

*Threshold:* 2 → 3

Type: signer_set_updated • Severity: warning • Time: 2026-07-01T19:45:08.900Z

Design Principles

Channel isolation

Each governance domain has its own channel. No mixing. Easy to mute low-priority domains without losing critical signals.

Noise filtering

Trigger conditions pre-filter events before they reach the function. Only warning/critical audit entries and anchor_status changes trigger alerts.

Two-function pipeline

slackEntityAlert handles context extraction and routing logic. slackAlert handles formatting and API delivery. Clean separation of concerns.

Severity-coded indicators

Every message carries a visual severity marker (🟢 🟡 🔴) and structured metadata footer for quick triage.

No polling

Entity automations fire on database writes. Alerts arrive in Slack within seconds of the triggering change.