1. Two layers
Alert rules watch the groups you configure. They catch a total outage and a failing method in a known segment. Anomaly analysis scans all dimensions and finds the defect in a segment nobody configured, for example passkey login breaking on one Android version while the overall login volume looks normal.
2. Alert rules
An alert rule computes one number per group over a time window and compares it with severity bands. The rule type decides what it measures:- Flow volume: the flow level. Completed logins, signups, recoveries or enrollments in the window, compared with the time right before.
- Subflow volume: a single method or step, such as passkey login, password login, social login, SSO or email OTP.
- Login success rate: the share of engaged logins that completed, over whole hours.
- Funnel conversion change: the conversion between two funnel nodes, compared with the same weekday of earlier weeks.
- Anomaly detection: changes of one funnel node across browsers, OS versions and your custom tags.
- Finding incident: a critical finding whose affected users per day, or estimated per week, reach the agreed severity levels, activated by the Corbado team or automatically.
Route critical alerts to on-call and warnings and info to the team’s email. Business hours follow each market’s local timezone.
3. Anomaly analysis and findings
Anomaly analysis finds the defects that hide in the overall numbers. It scans every funnel node, every environment and every dimension you send, not only the groups a rule watches: a passkey login breaking on one new browser version, a funnel step losing conversion after a release or one market falling behind. Its funnel history compares weekday-aligned periods, so normal weekly patterns stay flat. Analytics & findings explains the views in the console. As part of the managed enterprise service, Corbado turns the relevant results into findings: classified errors, affected segment and impact, verified with manual or automated tests and checked against your source code. Finding incident describes what a finding contains and how critical findings alert. By default, anomalies and findings reach you in Findings. Two rule types connect them with alerting: anomaly detection alerts per cohort on the same changes, and a finding incident rule alerts when a critical finding reaches the agreed number of affected users. Both directions of the handover are covered:- Alert first: a volume rule fires on a broad drop. The funnel history and environment breakdowns for the alert’s window show the segment and step that caused it.
- Finding first: a finding points to a segment nobody watched. Add a rule grouped by that dimension or an override with a stricter threshold.
4. Getting started
1
Send production traffic
One to two weeks of traffic show the daily and weekly patterns of your login.
2
Agree on the critical journeys
Decide which flows, methods and segments need an alert. Corbado proposes rules, windows and thresholds based on your traffic.
3
Create contact points and rules
Add email, webhook or PagerDuty destinations in Observe → Alerting → Contact points and create the rules.
4
Tune per segment
Adjust thresholds with the rule’s history and statistics, add overrides for segments such as small markets and set business hours per market timezone.