Skip to main content

Personal settings: Notifications (New Experience)

⚠️ Select your experience

The steps depend on your interface version. Select a link to skip to the instructions for your version.

Customers who joined Drata on or after Feb 24, 2026 are automatically on the New Experience.

Instructions for the New Experience ⬇️

Drata notifications keep you informed about work that needs your attention, such as task deadlines, policy updates, monitoring failures, and security issues. You control which notifications you receive and how often, and these settings apply only to you.

To manage notification flows for Slack or Microsoft Teams, please navigate to the Notification Rules page.

Before you begin

Keep these points in mind before you review the notification list:

  • Some notifications are sent immediately, while others are sent as weekly summaries or on a fixed reminder cadence.

  • If you do not receive expected emails, check your spam or junk folder, allowlist Drata’s sender address, and confirm your email gateway is not blocking Drata emails.

Access notification settings

  1. Select Settings.

  2. Open Personal → Notifications.

Personal notification reference

This guide covers all personal email notifications. To manage notification flows for Slack or Microsoft Teams, please navigate to the Notification Rules page. Please note that access to the Notification Rules page is restricted to Administrators.

Area

Notification

What triggers it

Who receives the notification

Audits

New messages

Sent when there are new messages from auditors or Drata admin.

All Drata Admins assigned auditors receive an email notification when there is a new message.

Audits

Status updates for requests

Sent when there are status updates on audit requests.

All Drata Admins assigned auditors receive an email notification when the status of an audit request changes.

Controls

Evidence updates on controls

Sent to control owners when there are changes to control evidence.

Notification Triggers:

  • Mapping or un-mapping evidence to a control

  • Deleting evidence from a control

  • Updating evidence from a control

The control owner receive an email notification.

Controls

Approval updates on controls

Sent to control owners and approvers when the control approval status changes.

Notification Triggers include:

  • control needing approval,

  • an approver requesting changes,

  • another approver is added or changed, or

  • control being approved.

The control owners and approvers receive an email notification.

Controls

Internal notes added to controls

Sent when a new note is added to a control.

The control owners receive an email notification.

Controls

Status changes for controls assigned to you

Sent as summaries of assigned controls and their status changes.

The control owners receive an email notification.

Can be configured as a daily or weekly summary.

Monitoring

Evidence collection errors

Sent when Drata records an evidence collection error.

Any user with this notification toggled on.

Monitoring

Automated test error

Sent when there are automated test failures.

Any user with this notification toggled on.

Can be configured as a daily or weekly summary.

Evidence

Evidence assigned to me

Sent when evidence is assigned to you.

Newly assigned evidence owner.

Policies

Policy comment replies

Sent when someone replies to one of your policy comments.

Any user with this notification toggled on.

Policies

Updates for policies assigned to me

Sent to policy owners when a policy is assigned to them, removed from them, or updated by someone else. If a policy owner loses access to Drata, Drata reassigns the policy to the first available Admin and notifies that Admin.

The policy owner receives the notification.

Risk

Risk owner notifications

Sent when somebody new is assigned as the owner of a risk.

Newly assigned risk owner.

Tasks

Upcoming task reminder

Sent to task owners when they have tasks due in the next seven days.

The user who is assigned the task.

Tasks

Annual compliance task reminder

Once a month, task assignees receive an email reminder about any upcoming annual compliance tasks.

Sent on the 15th of each month to the user who is assigned the task.

Tasks

Past due tasks

Sent to task owners who have overdue tasks.

Sent twice a week to the user who is assigned the overdue task,

Vulnerabilities

Reminders for vulnerabilities with missed or upcoming SLAs

Sent for critical and high-severity vulnerabilities with upcoming or missed SLA deadlines.

Receive email reminders when vulnerabilities are overdue or nearing their due date.

  • On the Vulnerabilities Settings page, set the warning period. This period indicates how many days in advance you would like to receive updates regarding upcoming vulnerabilities.

  • This setting configure lets you choose the frequency which is daily or weekly.

Workflows

Workflow creator notifications

A workflow you created is published (goes live) or deactivated.

User who created the workflow

Notification frequency

Some notifications are sent immediately, while others are delivered as weekly summaries. Frequency options appear only where applicable.


Common issues and troubleshooting

If you’re not receiving notifications:

  • Check your spam or junk folder

  • Confirm your organization’s email gateway isn’t blocking Drata emails

  • Allow time for weekly summaries to be delivered


Important notes

  • ℹ️ Notification availability depends on your role and ownership

  • ℹ️ Some roles may not see certain notification types


Instructions for the Classic Experience ⬇️

My Settings: Notifications

Drata sends various email notifications to alert you to updates within the application, for things such as control status changes and responses to your policy comments.

Drata notifications include alerts for monitoring tests, responses to policy comments, control status updates, and errors in automated tests, ensuring that you are promptly informed about critical system events.

From the 'My Settings' page, you're able to set your notification preferences and opt out if you so desire.

BEFORE DIVING IN

All roles, except for Risk Managers, can access Notifications page under My Settings in the Settings page. For more information on Drata roles, go to Role Administration & RBAC.

Enable your notifications

Under My Settings, you can enable notifications and select the different types of notifications you would like to receive.

You can also define specific preferences for notifications related to control owners and automated test errors, ensuring they are tailored to your role in the system.

  1. Select your name near the bottom left corner. From there, select Settings.

  2. Under My Settings, select Notifications.

  3. Toggle the notifications you would like to receive.

    • Use the 'Allow Notifications' to toggle all notifications ON or OFF.

    • You can also set individual email notifications and delivery frequency (where applicable).

Manage errors in automated tests specifically by navigating to the 'Errors for automated tests' section in the Notifications page and adjusting preferences accordingly.

If you do not receive the notifications you enabled, try one of these tips:

  1. Check your spam or junk folder: Sometimes, notification emails might accidentally get filtered into your spam. Ensure you review these folders for missing emails.

  2. Whitelist Drata email addresses: Add [email protected] to your email whitelist. This will help ensure that emails from Drata are not blocked by your email provider.

  3. Review spam filters or email gateway settings: Confirm with your IT administrator or through your email client settings that no Drata email is being intercepted.

  4. Account for delays: Occasionally, emails may be delayed. If you’ve checked all other steps and still don’t see the notifications, monitor your inbox or contact support for further investigation.

Did this answer your question?