> ## Documentation Index
> Fetch the complete documentation index at: https://docs.corbado.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Monitor Authentication Health

> How Corbado Observe alerts on broken logins within minutes and detects partial defects in segments, funnels and environments.

Corbado Observe tells you within minutes when login, signup or a single method breaks, and it finds partial defects in one browser, OS version or market before they reach your support team. Each alert names the affected segment and links to the evidence, which shortens the time to resolution.

Monitoring works on the journeys Observe already records. It needs no additional events in your integration.

## 1. Two layers

| | Alert rules | Anomaly analysis |
| - | - | - |
| **Question** | Is something broken right now? | Did a journey change over time in one segment? |
| **Signal** | Flow and subflow volume, login success rate and funnel changes in configured groups | Every dimension you send: browser, OS, app version, custom tags, funnel nodes |
| **Speed** | Volume rules every minute, the other rules on complete hours | Daily, faster for clear incidents |
| **Output** | Alert to email, webhook, PagerDuty or your own service | Finding with segment, impact and evidence, optionally an alert |
| **Typical cause** | Release, outage, broken IdP or third-party dependency | New browser or OS release, partial defect in one segment, gradual friction |

Alert rules watch the groups you configure. They catch a total outage and a failing method in a known segment. Anomaly analysis scans all dimensions and finds the defect in a segment nobody configured, for example passkey login breaking on one Android version while the overall login volume looks normal.

## 2. Alert rules

An alert rule computes one number per group over a time window and compares it with severity bands. The rule type decides what it measures:

* **Flow volume:** the flow level. Completed logins, signups, recoveries or enrollments in the window, compared with the time right before.
* **Subflow volume:** a single method or step, such as passkey login, password login, social login, SSO or email OTP.
* **Login success rate:** the share of engaged logins that completed, over whole hours.
* **Funnel conversion change:** the conversion between two funnel nodes, compared with the same weekday of earlier weeks.
* **Anomaly detection:** changes of one funnel node across browsers, OS versions and your custom tags.
* **Finding incident:** a critical finding whose affected users per day, or estimated per week, reach the agreed severity levels, activated by the Corbado team or automatically.

Which rule fits depends on how severe and how fast the problem is:

| Severity | Example | Rule type |
| - | - | - |
| **Critical** | Completed logins drop below 25% of the expected volume within 10 minutes | Flow volume |
| **Critical** | Social login fails for one application while the total looks normal | Subflow volume |
| **Warning** | A critical finding affects more users per day than agreed, for example an error returning on one browser | Finding incident |
| **Warning** | Login success on one browser stays below its normal rate for an hour | Login success rate |
| **Warning** | Passkey login completion drops on a new browser release, or password fallback rises on one OS version | Anomaly detection |
| **Info** | Conversion from identifier to completed login falls after a release | Funnel conversion change |

Route critical alerts to on-call and warnings and info to the team's email. Business hours follow each market's local timezone.

## 3. Anomaly analysis and findings

Anomaly analysis finds the defects that hide in the overall numbers. It scans every funnel node, every environment and every dimension you send, not only the groups a rule watches: a passkey login breaking on one new browser version, a funnel step losing conversion after a release or one market falling behind. Its funnel history compares weekday-aligned periods, so normal weekly patterns stay flat. [Analytics & findings](/corbado-observe/overview/analytics) explains the views in the console.

As part of the managed enterprise service, Corbado turns the relevant results into findings: classified errors, affected segment and impact, verified with manual or automated tests and checked against your source code. [Finding incident](/corbado-observe/alerting/alert-rules#7-finding-incident) describes what a finding contains and how critical findings alert.

By default, anomalies and findings reach you in [Findings](https://app.corbado.com/observe/analytics/findings). Two rule types connect them with alerting: [anomaly detection](/corbado-observe/alerting/alert-rules#6-anomaly-detection) alerts per cohort on the same changes, and a [finding incident](/corbado-observe/alerting/alert-rules#7-finding-incident) rule alerts when a critical finding reaches the agreed number of affected users.

Both directions of the handover are covered:

* **Alert first:** a volume rule fires on a broad drop. The funnel history and environment breakdowns for the alert's window show the segment and step that caused it.
* **Finding first:** a finding points to a segment nobody watched. Add a rule grouped by that dimension or an override with a stricter threshold.

## 4. Getting started

<Steps>
  <Step title="Send production traffic">
    One to two weeks of traffic show the daily and weekly patterns of your login.
  </Step>

  <Step title="Agree on the critical journeys">
    Decide which flows, methods and segments need an alert. Corbado proposes rules, windows and thresholds based on your traffic.
  </Step>

  <Step title="Create contact points and rules">
    Add email, webhook or PagerDuty destinations in [**Observe → Alerting → Contact points**](https://app.corbado.com/observe/alerting/contact-points) and create the rules.
  </Step>

  <Step title="Tune per segment">
    Adjust thresholds with the rule's history and statistics, add overrides for segments such as small markets and set business hours per market timezone.
  </Step>
</Steps>

Continue with [alert rules](/corbado-observe/alerting/alert-rules) for the configuration and [notifications](/corbado-observe/alerting/notifications) for delivery. Rules and alert history are also available through the [Observe API](/api-reference/observe/overview).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.