Skip to main content
Notifications keep your team informed about what Clarion is doing, and let agents reach you when they need approval or clarification before continuing.

Two kinds of notifications

In-app notifications tell you about things that happened: an issue was assigned to you, a task is overdue, an agent finished a triage. They appear in the notification tray. Human input notifications are active requests from agents that need a response before execution can continue. They’re delivered to a configured destination and resume the agent run when you reply.

What triggers a notification

Only escalation notifies your team. When an issue moves to Escalated, Clarion announces it on the configured channels. Everything else stays quiet:
  • Creating an issue never notifies. Issues arrive continuously, and paging on each one would be noise.
  • Open issues don’t notify. They are confirmed problems below the escalation bar, left on the board for someone to pick up.
  • Grouped issues don’t notify again. An issue folded under an already-escalated parent is covered by the parent’s announcement. See Grouping related issues.
Follow-up messages about an issue, such as an agent’s updates, approvals, and clarifications, stay in that issue’s Slack or Teams thread, so everything about it reads as one conversation.

Channels

Human-input notifications are delivered over:
  • Slack — app messages with interactive buttons for approval and clarification. Threaded under the issue’s escalation announcement, so a run’s approvals, clarifications, and agent posts stay in one place. See the Slack integration guide.
  • Microsoft Teams — the same flow, into a Teams channel or chat. See the Microsoft Teams integration guide.
  • Telegram — bot messages into a chat.
  • SMS — via Twilio, to workspace members with a verified phone number. Notification only; SMS does not carry interactive approval buttons.
Skills can additionally act through general outbound email, a webhook, a phone call, or a PagerDuty page. Those are agent tools rather than workspace human-input destinations: PagerDuty in particular is a way for an agent to page on-call, not a place a human answers an agent from.

Which severities escalate

Settings → Agents → Escalation & notifications also sets the severities that escalate. When an agent escalates an issue at one of those severities, the issue is escalated and announced to your destination. Below the bar, the issue stays open for a human to pick up, and nobody is paged. The bar is also written into the agent’s system prompt, so agents know when to escalate.

Multiple destinations per workspace

A workspace no longer has a single notification target. Configure a set of destinations in Settings → Agents → Escalation & notifications, each with:
  • Channel and target — the Slack channel, Teams channel or chat, Telegram chat, or the members to text.
  • Label — a human-facing name, e.g. #sec-ops, Cloud on-call, Exec bridge.
  • Description — “use this destination when…”. This is shown to admins and read by the agent when it routes the run.
  • Primary — exactly one destination is primary. It is the guaranteed fallback.
Leaving the set empty turns human-input notifications off.

Agents route themselves

Because each destination carries a description, an agent can pick the right one for the run it is on — a DNS change to the infrastructure channel, a suspected identity compromise to the security channel — and pin that choice for the rest of the run. The choice is bounded: an agent may only select from destinations an admin already configured, the id is validated server-side, and any run without a valid choice falls back to the primary destination. An agent cannot invent a destination.
Give every destination a clear description. It is the only thing the agent has to route on.

Posting to any channel

By default, agents can only post to Slack and Teams destinations that are explicitly named: the destinations above, plus channels and chats mentioned in a skill or in agent behavior. That scoping is a deliberate safety boundary, because it means a compromised or misled agent cannot pick its own audience. Workspace admins can lift it with Allow agents to post to any channel, below the destination list. With it on:
  • Slack: agents can post, reply, react and upload files in any public channel, and in private channels the Clarion app has been added to. They still can’t invite people to a channel or change its topic unless it is listed or mentioned.
  • Microsoft Teams: agents can message any chat or channel, look up anyone in your Microsoft directory, and start new group chats. Approval and clarification requests can then be delivered into a group chat the agent created during the run.
  • Slack direct messages stay limited to the people mentioned in skills or on call.
The setting applies to runs that start after you change it. Workspaces that had Unrestricted Microsoft Teams messaging turned on start with this setting on.
Leave this off unless you have a specific need for agents to reach channels you haven’t listed, such as ad-hoc war rooms. It widens where agent-authored content can land.

Human input types

Approval — yes/no on a tool the agent wants to run (“Suspend user account?”). The prompt names the tool, the target, and the agent’s rationale. Clarification — a question, in one of three shapes: Clarifications can be marked skippable, carry a default value, and arrive as a batch — several related questions asked together and shown with their position in the batch, rather than one round trip each. Scheduled runs can ask for clarification too, so an overnight sweep can still put a question in front of a human rather than guessing or aborting.

Who can respond

By default, only Admin and Member roles can answer, and Slack or Teams responders must be linked to a workspace member. Turning on Anyone can respond to human input in Workspace settings opens it to any member — including read-only — and to teammates in the linked channel without a Clarion account. Either way, the audit log records who unblocked the agent.

Timeouts and escalation

Each request carries a timeout. On timeout the agent either auto-aborts the action or escalates to a backup destination, depending on the skill. To deny every unanswered tool approval after 12 hours instead of waiting, turn on Deny unanswered tool approvals in Workspace settings. Which issue severities an agent may escalate on at all is set by Severities that escalate in Settings → Agents → Escalation & notifications.
Approval requests for tool calls are an explicit safety boundary. Agents can never execute a gated tool without a human response. The run pauses until you reply or the timeout fires.

On-call rotation

Settings → Agents → Escalation & notifications also holds the workspace’s on-call rotation: which member is on call for which date. Agents read it when a skill says to page whoever is on call, and it can be mirrored into a Google Calendar through the Google Calendar integration.

Escalation cards

Escalation messages carry the issue reference and link back to the issue in Clarion. In Slack, an escalated issue can be closed directly from its card without opening the app.

Slack

Connect Slack for interactive approvals.

Microsoft Teams

Connect Teams for the same flow.

Telegram

Bot delivery into a Telegram chat.

Twilio

SMS and voice calls for high-urgency events.