Introduction
The Alerts page is where Spikerz tells you what it has detected on your connected social media accounts.
Spikerz monitors your accounts around the clock - credentials and recovery details, admin access and roles, login activity, impersonators, malicious comments and DMs, bots and fake followers, community-guideline risks, and leaked data on the dark web. Whenever something notable is found, it becomes an alert.
Each alert answers four questions: what happened, which asset it affects, when it happened, and what you can do about it. From the alert itself you can jump straight to the settings or permissions page where the issue can be fixed.
This guide explains how to read the alert feed, how to narrow it down with search and filters, what the Security alerts cover, and how to move between the alerts of a single account and the alerts of all your assets at once.
Alerts for One Account vs. All Assets
Spikerz shows alerts at two levels, and both use the same feed, search, and filter controls.
A Single Account
When you select a specific asset - for example your Instagram profile or a Facebook page - the Alerts page shows only the alerts raised for that account.
Use this view when you are investigating one account: everything on screen belongs to it, so the feed reads as a clean timeline of that account's security history.
All Assets (Aggregation Mode)
Switch to aggregation mode to see the alerts of every connected account consolidated into a single feed, regardless of platform or brand.
In this view each alert card carries an asset chip - the platform icon plus the account name - so you can always tell which account an alert came from without leaving the list. Selecting an alert still takes you to the right place on the right asset.
Aggregation mode is the practical starting point for a security team managing several profiles or brands: you triage everything from one screen, then drill into an individual account only when an alert needs deeper investigation. For everything else aggregation mode brings together, see the Spikerz Aggregation Mode Guide.
Reading the Alert Feed
Alerts are listed newest first, so the most recent detection is always at the top. Every alert is presented as a card containing:
Title - what happened, in plain language, such as "Your password was changed" or "Role changed".
Description - the detail behind the title. Names, page names, and roles are highlighted inside the sentence, so you can see exactly who and what was involved - for example which user was granted a role, or which roles they held before and after the change.
Asset - the platform icon and account the alert relates to.
Date and time - when the activity was detected.
Actions - links that take you where you can act on the alert (see Acting on an Alert below).
Resolve control - the circular check icon on the right of the card, used to mark the alert as handled.
Selection checkbox - to the left of the card, for handling several alerts together.
A Select all checkbox above the feed selects every alert currently loaded in the list, and shows the number selected in brackets. Combine it with a filter first when you want to act on one specific group of alerts.
Alert Tabs
Three tabs sit above the feed, each with a counter so you can see the size of your queue before opening it:
All alerts - every alert Spikerz has raised for the current scope, of every type.
Security - only the security alerts: changes to credentials, recovery details, access, and roles. This is the tab to work from when you are reviewing the safety of your accounts rather than their content or audience.
Resolved - alerts you have already marked as handled, kept for reference and audit.
The tabs change what the feed shows, and search and filters apply to whichever tab you are on.
Searching Alerts
Use the Search bar at the top of the page to find alerts with free text. Search is case-insensitive and matches the content of the alert - its title and its description, including the names, page names, and roles highlighted inside it.
A few examples:
Type password to surface every password-related alert.
Type an employee's name to see every alert involving that person - roles granted, roles changed, permissions removed.
Type a page name to see everything raised against that page.
In aggregation mode, type an account name to narrow the combined feed down to a single asset.
Results update as you type, and you can clear the search from the field to return to the full list.
Filtering Alerts
Select the Filter button next to the search bar to narrow the feed. Filters can be combined with each other and with search, which is what makes a long queue manageable - for example, filtering to a single platform and a single week, then searching for a person's name.
Alerts can be filtered by parameters including:
Platform - the social network the alert came from.
Asset or account - a specific connected account. Especially useful in aggregation mode, where the feed spans every asset.
Alert type - the kind of alert, so you can isolate one category of activity.
Date range - the period the alert was detected in.
The Filter button reflects how many filters are currently active, and the filters can be cleared to return to the default view at any time.
Tip: filters and search stack. Opening the Security tab, filtering to one platform, and searching for an employee's name is the fastest way to answer a question like "what access changes has this person been involved in on our Instagram accounts this month?"
Display Options
The Display button at the top right of the page controls how the alert feed itself is presented, letting you adjust the view to suit the way you work - a compact list for fast scanning of a large queue, or a fuller layout when you want more context on each alert without opening it.
Display settings only change your own view of the feed. They never change which alerts exist, their status, or what anyone else sees.
Security Alerts
Security alerts are raised when something happens that could affect who can reach your accounts, or how they can be recovered. These are the alerts that matter most in an incident, because they are the signals that usually precede an account takeover.
They fall into a few recognizable groups.
Credentials and Recovery Details
Changes to the details used to log in to an account, or to recover it:
Your password was changed - the account password has been changed.
Phone Number was changed - the phone number on the account has been changed.
2FA method was added - a new two-factor authentication method was added to the account.
2FA method was removed - a two-factor authentication method was removed from the account.
Recovery details deserve particular attention. An attacker who adds their own phone number or authenticator, or removes yours, can keep access to an account even after the password is reset - so a change you do not recognize here should be treated as urgent.
Access, Users, and Roles
Changes to who can administer your pages and assets, and at what level:
New user was added to your page - a person was granted a role on the page, and the alert names both the person and the role.
Role changed - an existing user's roles were changed, showing the roles they held before and the roles they hold now. This is how privilege escalation becomes visible - for example a user moving from Editor to Admin.
New page permissions detected - new permissions were added to a named page.
Page permissions removed - permissions to a named page were removed.
Together these alerts give you a running record of your admin surface, which is exactly what an access review needs: who was added, who was elevated, and when.
Automated Spikerz Remediation
Some alerts report an action Spikerz has already taken on your behalf, rather than something you need to fix. For example, Permissions for unknown user ... were removed via Spikerz tells you that Spikerz detected an unrecognized user holding permissions on one of your assets and removed that access automatically.
These alerts are still worth reading. They confirm the protection is working, and they tell you that someone unexpected had access in the first place - which is usually worth understanding.
Note: the same activity is also written to the Activity Log, alongside user and system events, when you need the full chronological picture of a workspace rather than the alert queue.
Acting on an Alert
Each alert card offers a direct route from detection to action:
Details - opens the full context of the alert without leaving the feed.
View settings - opens the relevant settings page for alerts about credentials or recovery details, such as a password, phone number, or 2FA change.
View permissions - opens the permissions page for alerts about users, roles, or page access, so you can review who currently has access and correct it.
Resolve - the circular check icon on the right of the card marks the alert as handled and moves it to the Resolved tab.
Resolving an alert is a record that a human reviewed it, so it is worth resolving deliberately: check the alert, confirm the change was expected, and only then mark it as resolved. Anything you cannot account for should stay open until it is investigated.
To clear several alerts at once, select them with the checkboxes - or use Select all after filtering - and resolve them together.
A Recommended Routine
A short, repeatable review keeps the queue under control:
Open Alerts in aggregation mode so nothing on any asset is missed.
Go to the Security tab and work oldest unresolved alert upwards.
For each alert, use Details to confirm what happened, then View settings or View permissions to verify the current state of the account.
Resolve what you can account for; leave anything unexpected open and investigate it.
Use search and filters to group related alerts - by person, page, platform, or date - rather than reading the feed top to bottom.
If an alert points to access or recovery details you do not recognize, treat it as a live incident: remove the unknown access, reset the credentials, and re-check the account's recovery details before resolving the alert.