Skip to main content

IE notifications upgrade guide

When upgrading from Invicti Enterprise to Invicti Platform, notification rules are converted into Automations - the equivalent feature in Invicti Platform. This document explains how each part of a notification rule maps to an Automation and what isn't transferred.

For a high-level overview of all upgrade areas, refer to the Moving from Invicti Enterprise to Invicti Platform document. For full details on setting up Automations in Invicti Platform, refer to the Automation definition document.

Why this matters​

Notification rules from Invicti Enterprise don't map one-to-one to Automations. Some trigger types split across multiple events, scope settings translate differently, and several notification features have no equivalent in Invicti Platform. Understanding the mapping helps you confirm that your alert coverage works as expected after the upgrade and identify gaps that require manual configuration.

What's carried over​

This section covers which notification rule properties carry over to Invicti Platform Automations during the upgrade.

Rule name and state​

The notification rule name transfers as the Automation name. Enabled and disabled states transfer as-is - a disabled rule becomes a disabled Automation.

Each carried-over Automation receives the description "Imported from legacy system" to indicate its origin.

Scope​

The scope of a notification rule - which websites it applies to - translates as follows:

Invicti Enterprise scopeInvicti Platform scope
Any websiteAll targets
Specific websiteSpecific target (matched by target ID)
Website groupCollection (carried over by group ID)

Trigger events​

Notification rules in Invicti Enterprise fire on scan events. These map to Invicti Platform Automation triggers:

Invicti Enterprise eventInvicti Platform triggerNotes
Scan completedScan doneCreated for all automations with email or messaging actions
Scan completed with issue-tracker integrationVulnerability foundCreated in addition to Scan done when the rule includes a supported issue-tracking integration
Scan faultedScan failedCreated for all automations

Recipients and actions​

The upgrade carries over email notifications as a Send email action, including:

  • User email addresses from the Invicti Enterprise rule recipients list
  • External email addresses defined directly in the rule

If the Invicti Enterprise rule had report attachments configured, the transferred Automation includes a report link in the email.

The upgrade carries over integration notifications as a Create issue action on the Vulnerability found trigger. The following integrations are supported:

  • Jira
  • GitHub
  • GitLab
  • Azure Boards
  • Slack
  • Microsoft Teams
  • Webhook

For details on how each integration carries over, refer to the IE integrations upgrade guide document.

Severity filters​

When a notification rule in Invicti Enterprise filtered by vulnerability severity, those conditions carry over to the Vulnerability found trigger in the carried-over Automation. Supported severity levels: Critical, High, Medium, Low, Information.

Best practice severity

The Best Practice severity level isn't available in Invicti Platform. Notification rules that filtered on best practice severity won't transfer that condition.

Report types​

If a notification rule had email report attachments configured, the report type maps to the closest equivalent in Invicti Platform:

Invicti Enterprise reportInvicti Platform report
Executive SummaryExecutive Summary
OWASP Top Ten 2021OWASP Top Ten 2021
OWASP Top 10 2025OWASP Top 10 2025
OWASP ASVS 5.0OWASP ASVS 5.0
SANS Top 25CWE/SANS Top 25
WASC Threat ClassificationWASC Threat Classification
PCI DSS v3.2 CompliancePCI DSS v3.2 Compliance
PCI DSS 4.0 CompliancePCI DSS 4.0 Compliance
HIPAA ComplianceHIPAA Compliance
ISO 27001 ComplianceISO 27001 Compliance
NIST SP 800-53 ComplianceNIST SP 800-53 Compliance
DISA STIG ComplianceDISA STIG Compliance
Report type fallback

If a notification rule used a report type that isn't available in Invicti Platform, the Comprehensive report template is used instead.

This table covers only the IE report types that map to an equivalent in Invicti Platform. Invicti Platform has additional report types not available in Invicti Enterprise. For the full list, refer to Types of reports.

What isn't carried over​

FeatureReason
SMS notificationsInvicti Platform Automations don't support SMS delivery
Rule priorityInvicti Platform doesn't have a priority ordering concept for Automations
Notification grouping by time windowNo equivalent grouping mechanism in Invicti Platform Automations
Custom email subject and bodyInvicti Platform sends predefined email templates; custom content isn't preserved
Rules with a duplicate nameIf an Automation with the same name already exists, the upgrade skips the rule
Unsupported integration typesOnly issue-tracking and messaging integrations are supported in Automations

Post-upgrade actions​

After the upgrade:

  1. Select Automations from the left-side menu and confirm your notification rules appear.
  2. Check trigger events and confirm they match your intended alert logic.
  3. Verify that email recipients and integration actions are correctly configured.
  4. Recreate any rules that were skipped due to duplicate names or unsupported types.
  5. If you used notification grouping or custom email content in Invicti Enterprise, configure equivalent logic manually in Invicti Platform.

Troubleshooting​

A notification rule isn't showing as an Automation after the upgrade

Several rule types are skipped during the upgrade. Check whether the rule had a duplicate name - if an Automation with the same name already exists, the upgrade skips that rule. Also confirm whether the rule used an unsupported integration type, such as SMS or a secrets management connector. Refer to the What isn't carried over section for the full list of excluded types.

The Automation has Scan done as the trigger but I expected Vulnerability found

The Vulnerability found trigger is only created when the original Invicti Enterprise notification rule was linked to a supported issue-tracking integration (Jira, GitHub, GitLab, or Azure Boards). If the rule only had email or messaging recipients, the upgrade creates a Scan done trigger only. If you need vulnerability-level alerting, add a Vulnerability found trigger to the Automation manually in Invicti Platform.

Email recipients are missing from the carried-over Automation

User email addresses carry over from the IE rule recipients list and any external email addresses defined directly in the rule. If a recipient isn't present, check whether they're an active user in Invicti Platform and whether their email address matches exactly what was configured in Invicti Enterprise. Recreate any missing recipients manually in the Automation's Send email action.

The Create issue action is missing from the carried-over Automation

The Create issue action is only created when the original rule was linked to a supported issue-tracking integration (Jira, GitHub, GitLab, or Azure Boards) and the Scan Completed trigger was configured. Check whether the integration itself was successfully carried over in Invicti Platform. If the integration wasn't carried over, the action can't be created automatically - set it up manually in the Automation after confirming the integration is configured.


Need help?​

Invicti Support team is ready to provide you with technical help. Go to Help Center

Was this page useful?