Alerting
TrustVendor + Microsoft Teams
For organizations in the Microsoft ecosystem, TrustVendor delivers vendor risk alerts to Teams channels using Adaptive Cards for a structured, actionable presentation.
How data flows
TrustVendor posts Adaptive Card messages to a Teams channel via webhook. Each card contains the signal summary, severity, and an action button linking to the evidence drawer.
How to set up
- 1 Create an incoming webhook in your Teams channel.
- 2 Paste the webhook URL into TrustVendor under Settings > Alerting > Teams.
- 3 Configure severity thresholds and vendor group routing.
Common questions
Do TrustVendor alerts work in Teams channels and chats?
Alerts are delivered to channels via webhook. Direct message delivery is not currently supported.
What information does a TrustVendor Adaptive Card in Teams contain?
Each Adaptive Card shows the vendor name and primary domain, signal type and severity badge, a one-sentence summary of the claim, the date and time the signal was first detected, and an action button that deep-links to the evidence drawer in TrustVendor. Cards are formatted to be readable in both the Teams desktop client and the mobile app without horizontal scrolling.
Can I configure different Teams channels for different signal severities?
Yes. TrustVendor supports multiple Teams webhook endpoints per workspace. You can configure critical and high signals to post to a security-incidents channel, medium signals to a vendor-risk-monitoring channel, and omit low and informational signals from Teams entirely. Each webhook endpoint is configured independently under Settings > Alerting > Teams.
Does TrustVendor support suppressing Teams alerts during vendor maintenance windows?
Yes. You can create a snooze window for a specific vendor in TrustVendor, which pauses alert delivery to all configured channels including Teams for the duration. Service_outage signals for vendors with an active snooze are still recorded in TrustVendor but are not posted to Teams, reducing noise when you already know a vendor is in a planned maintenance window.
How is the Teams webhook secured?
The webhook URL contains a Teams-generated secret token and should be treated as a credential. TrustVendor stores it encrypted at rest and never exposes it in logs or API responses. If you suspect the URL has been leaked, generate a new incoming webhook in Teams and update it in TrustVendor — the old URL can be deleted in Teams immediately.