IE notifications upgrade guide
When upgrading from Invicti Enterprise to Invicti Platform, notification rules are converted into Automations - the equivalent feature in Invicti Platform. This document explains how each part of a notification rule maps to an Automation and what isn't transferred.
For a high-level overview of all upgrade areas, refer to the Moving from Invicti Enterprise to Invicti Platform document. For full details on setting up Automations in Invicti Platform, refer to the Automation definition document.
Why this matters
Notification rules from Invicti Enterprise don't map one-to-one to Automations. Some trigger types split across multiple events, scope settings translate differently, and several notification features have no equivalent in Invicti Platform. Understanding the mapping helps you confirm that your alert coverage works as expected after the upgrade and identify gaps that require manual configuration.
What's carried over
This section covers which notification rule properties carry over to Invicti Platform Automations during the upgrade.
Rule name and state
The notification rule name transfers as the Automation name. Enabled and disabled states transfer as-is - a disabled rule becomes a disabled Automation.
Each carried-over Automation receives the description "Imported from legacy system" to indicate its origin.
Scope
The scope of a notification rule - which websites it applies to - translates as follows:
| Invicti Enterprise scope | Invicti Platform scope |
|---|---|
| Any website | All targets |
| Specific website | Specific target (matched by target ID) |
| Website group | Collection (carried over by group ID) |
Trigger events
Notification rules in Invicti Enterprise fire on scan events. These map to Invicti Platform Automation triggers:
| Invicti Enterprise event | Invicti Platform trigger | Notes |
|---|---|---|
| Scan completed | Scan done | Created for all automations with email or messaging actions |
| Scan completed with issue-tracker integration | Vulnerability found | Created in addition to Scan done when the rule includes a supported issue-tracking integration |
| Scan faulted | Scan failed | Created for all automations |
Recipients and actions
The upgrade carries over email notifications as a Send email action, including:
- User email addresses from the Invicti Enterprise rule recipients list
- External email addresses defined directly in the rule
If the Invicti Enterprise rule had report attachments configured, the transferred Automation includes a report link in the email.
The upgrade carries over integration notifications as a Create issue action on the Vulnerability found trigger. The following integrations are supported:
- Jira
- GitHub
- GitLab
- Azure Boards
- Slack
- Microsoft Teams
- Webhook
For details on how each integration carries over, refer to the IE integrations upgrade guide document.
Severity filters
When a notification rule in Invicti Enterprise filtered by vulnerability severity, those conditions carry over to the Vulnerability found trigger in the carried-over Automation. Supported severity levels: Critical, High, Medium, Low, Information.
The Best Practice severity level isn't available in Invicti Platform. Notification rules that filtered on best practice severity won't transfer that condition.
Report types
If a notification rule had email report attachments configured, the report type maps to the closest equivalent in Invicti Platform:
| Invicti Enterprise report | Invicti Platform report |
|---|---|
| Executive Summary | Executive Summary |
| OWASP Top Ten 2021 | OWASP Top Ten 2021 |
| OWASP Top 10 2025 | OWASP Top 10 2025 |
| OWASP ASVS 5.0 | OWASP ASVS 5.0 |
| SANS Top 25 | CWE/SANS Top 25 |
| WASC Threat Classification | WASC Threat Classification |
| PCI DSS v3.2 Compliance | PCI DSS v3.2 Compliance |
| PCI DSS 4.0 Compliance | PCI DSS 4.0 Compliance |
| HIPAA Compliance | HIPAA Compliance |
| ISO 27001 Compliance | ISO 27001 Compliance |
| NIST SP 800-53 Compliance | NIST SP 800-53 Compliance |
| DISA STIG Compliance | DISA STIG Compliance |
If a notification rule used a report type that isn't available in Invicti Platform, the Comprehensive report template is used instead.
This table covers only the IE report types that map to an equivalent in Invicti Platform. Invicti Platform has additional report types not available in Invicti Enterprise. For the full list, refer to Types of reports.
What isn't carried over
| Feature | Reason |
|---|---|
| SMS notifications | Invicti Platform Automations don't support SMS delivery |
| Rule priority | Invicti Platform doesn't have a priority ordering concept for Automations |
| Notification grouping by time window | No equivalent grouping mechanism in Invicti Platform Automations |
| Custom email subject and body | Invicti Platform sends predefined email templates; custom content isn't preserved |
| Rules with a duplicate name | If an Automation with the same name already exists, the upgrade skips the rule |
| Unsupported integration types | Only issue-tracking and messaging integrations are supported in Automations |
Post-upgrade actions
After the upgrade:
- Select Automations from the left-side menu and confirm your notification rules appear.
- Check trigger events and confirm they match your intended alert logic.
- Verify that email recipients and integration actions are correctly configured.
- Recreate any rules that were skipped due to duplicate names or unsupported types.
- If you used notification grouping or custom email content in Invicti Enterprise, configure equivalent logic manually in Invicti Platform.
Troubleshooting
A notification rule isn't showing as an Automation after the upgrade
Several rule types are skipped during the upgrade. Check whether the rule had a duplicate name - if an Automation with the same name already exists, the upgrade skips that rule. Also confirm whether the rule used an unsupported integration type, such as SMS or a secrets management connector. Refer to the What isn't carried over section for the full list of excluded types.
The Automation has Scan done as the trigger but I expected Vulnerability found
The Vulnerability found trigger is only created when the original Invicti Enterprise notification rule was linked to a supported issue-tracking integration (Jira, GitHub, GitLab, or Azure Boards). If the rule only had email or messaging recipients, the upgrade creates a Scan done trigger only. If you need vulnerability-level alerting, add a Vulnerability found trigger to the Automation manually in Invicti Platform.
Email recipients are missing from the carried-over Automation
User email addresses carry over from the IE rule recipients list and any external email addresses defined directly in the rule. If a recipient isn't present, check whether they're an active user in Invicti Platform and whether their email address matches exactly what was configured in Invicti Enterprise. Recreate any missing recipients manually in the Automation's Send email action.
The Create issue action is missing from the carried-over Automation
The Create issue action is only created when the original rule was linked to a supported issue-tracking integration (Jira, GitHub, GitLab, or Azure Boards) and the Scan Completed trigger was configured. Check whether the integration itself was successfully carried over in Invicti Platform. If the integration wasn't carried over, the action can't be created automatically - set it up manually in the Automation after confirming the integration is configured.
Need help?
Invicti Support team is ready to provide you with technical help. Go to Help Center