Back to blog
Risk ModelMethodologyTravel RiskOperations

Who Gets Told, and How Fast

Part 7 of Inside the Risk Model: ShadowIQ's notification strategy — immediate only for credible, itinerary-intersecting alerts; a human check before rumours interrupt anyone; digests for the rest.

July 20, 2026ShadowIQ Risk Intelligence Team

Every notification you send is a small withdrawal from your team's attention. Send too many and the account empties — people mute the channel, and the one that mattered goes unread. So the hardest question in alerting isn't "what did we detect," it's "who deserves to be interrupted, and how urgently."

This is Part 7 of Inside the Risk Model: how ShadowIQ decides who gets told, and how fast.

Detection is not notification

A foundational idea: every alert lands on the dashboard, but only some earn an interruption. Detecting something and paging a human about it are different decisions. Getting that split right is what separates a tool people trust from one they mute.

ShadowIQ sorts each alert into a notification tier:

  • Immediate — a credible alert that directly intersects someone's itinerary in place and time. The closer and more serious, the wider the escalation (from a heads-up to an urgent email/SMS notification).
  • Held for a human first — a serious-looking alert that hasn't cleared the credibility bar (single shaky source, uncorroborated, poorly located) goes to an analyst to verify before it interrupts anyone. As we said in Part 4: we don't wake people up for rumours.
  • Daily digest — relevant-but-not-urgent activity is batched into a once-a-day summary for coordinators and admins, so it's captured without constant pinging.
  • Dashboard only — past events, low-relevance signals, and anything already handled stay visible for the record and notify no one.

The bar for an immediate alert is high on purpose

An immediate notification requires an alert to clear several of the earlier axes at once: it has to be credible (Part 4), it has to genuinely intersect the itinerary in place and time (Part 3), and the more it also scores on consequence and live likelihood, the more urgently and widely it escalates. An alert that's serious but distant, or nearby but unverified, or live but trivial, does not trigger a 2am notification. That restraint is a feature — it's what keeps the immediate channel meaningful.

Tuned to the trip and the organisation

Notification isn't one-size-fits-all:

  • Organisations set their own thresholds — a program can require a higher severity or confidence floor before anything reaches its people, routing the rest to the dashboard.
  • Each trip has a Live Pulse setting for how closely social signals are watched — off by default, with hourly or rapid modes for the trips that warrant closer attention (a higher-profile leg, a volatile window). It's scoped tightly around where the group actually is in the schedule, so you're not paying attention-cost for a quiet part of the trip.

The right person, not everyone

Tiers also decide who, not just how fast. An urgent, itinerary-intersecting alert can reach a traveller or on-call manager; a trip's risk-level change reaches the accountable admin; routine relevant activity reaches coordinators via digest. Internal analyst-verification routes are kept separate from customer-facing notifications entirely — so a "please verify this" to an analyst never masquerades as an alarm to your travellers.

Why it matters to you

ShadowIQ's notification strategy is built around one belief: an interruption should be rare, and therefore trusted. When your phone buzzes with a ShadowIQ alert, it's because a credible threat genuinely intersects a trip — not because something happened somewhere in a country you operate in. That's the difference between a channel people watch and one they mute.

Final in the series: How AI and humans keep the whole thing honest.