Topic
This article explains how Visual Command Center (VCC) uses the Always Alert and Auto Incident options on risk event categories to decide when incoming events become alerts, when they become incidents, and how notifications reach contacts.
Description
VCC evaluates each incoming risk event and advisory against the Alert Settings for its category and severity. Those settings determine whether VCC simply records the event, creates an alert, or also launches an incident and notifications automatically. Two options control that behavior: Always Alert creates an alert for every qualifying event even when no assets are nearby, and Auto Incident automatically launches an incident and its notification without manual review.
Always Alert
When Always Alert is selected for a category and severity, VCC creates an alert for events in that category even if there are no nearby assets in the alert radius. This is useful when alerts are wanted for certain critical categories (for example, NC4-sourced events) purely for situational awareness, not just asset impact.
The alert uses the notification template tied to it and notifies the contacts hard-coded into that template — specified groups, roles, or individuals. If the template has no hard-coded contacts, the alert (and any associated incident) is still created, but no notifications are delivered. A template that lacks the required contacts or fields can also prevent the associated incident from launching automatically even though the alert fired. Template recipients are therefore as important as the category setting: an Always Alert category tied to a template with no contacts produces visible alerts in VCC that notify no one.
Auto Incident
When Auto Incident is enabled in the Alert Settings for an incident source and a notification template is selected, qualifying feed items automatically create an incident from that template, send the configured notification, and appear on the VCC Operator Console — without manual review or launch. If Auto Incident is not selected, incoming feed items do not create incidents or send notifications, even when alerts are visible.
As with Always Alert, if the selected template contains no contacts, the incident is created but no one is notified, and a template missing required contacts can block the automatic launch.
When Neither Is Enabled
If a category has neither Always Alert nor Auto Incident enabled, VCC behaves conservatively: qualifying risk events may not automatically create incidents or appear in the Alerts list, and they remain in a non-alert state until an alert is launched manually — for example, through an operator workflow or an orchestration action. The events still exist as data in the VCC feeds; they simply do not produce automated alerts or incidents.
Make Sure the Right Contacts Are Notified
However alerts and incidents are created, VCC notifies only the recipients the configuration specifies. Set recipients in one or more of these ways:
- Hard-code contact groups, roles, or individuals into the notification template.
- Auto-add contacts in the alert area: add the VCC!: Add EB Contacts in Area variable to the template (the sending role needs Edit access to that template), or enable Send to Contacts in Area in the VCC Admin Console Alert Settings to notify all contacts whose saved locations fall within the alert radius.
- Include a multi-selection location variable covering Expected, Last Known, and Static in auto-launch templates, so automated alerts match employees by any of those location types.
When Always Alert or Auto Incident is enabled, verify that the linked templates and alert settings include appropriate recipients and area-based options; otherwise alerts and incidents may be generated with no effective communication.
Orchestration Workflows for Some Feeds
Some feeds create alerts through orchestration workflows rather than through category settings, so both should be considered together:
- For Travel Risk Events, workflows handle both alert creation and notification. If the feed's workflow is turned off, VCC will not create alerts regardless of category settings.
- Operator Entered Risk Events only create an event; they do not select a template or contact list at creation. Automatic communication requires either a workflow in Everbridge Suite triggered by Operator Entered events or a template selected in VCC Admin (Legacy Alerting).
- To convert a Risk Event into a VCC alert, configure an orchestration workflow with a trigger matching the event, condition filters such as severity, the recipients to notify, and a VCC alert or incident action, then test it with a sample event.
Review Settings for High-Volume Feeds (NC4)
High-volume feeds such as NC4 Risk Events and Advisories can generate many alerts or auto-launched incidents if these options are enabled without care. To review the configuration:
- Identify the event category and severity used by the incoming events (for example, specific civil unrest or strike-related categories).
- In the VCC Admin Console (Admin Console > Data > the relevant feed), check whether Always Alert and Auto Incident are enabled for that category.
- Keep Always Alert enabled only where alerts are wanted even with no nearby assets; otherwise disable it or tighten conditions to avoid non-actionable alerts.
- Disable Auto Incident where automatic incident creation and notification are not appropriate for the operational team, and rely on manual launch or targeted workflows instead.
- Confirm the linked notification template includes the correct hard-coded contacts and any area-based variables needed.