The Alert That Trained You to Ignore It
The Alert That Trained You to Ignore It
Alert fatigue is usually described as a volume problem. Too many notifications, not enough attention, so tune the thresholds and the noise goes down. That framing is comfortable and it is wrong, because it treats ignoring as a failure of discipline rather than what it actually is: a correct conclusion, learned quickly, from consistent evidence.
If a signal fires a hundred times and a hundred times there was nothing to do, the reader has not become lazy. The reader has learned the true base rate. Any system that keeps paging after that has stopped transmitting information and started transmitting habit.
The learning is faster than the alerting
This is the part that makes alert fatigue hard to reverse. Trust degrades much faster than it rebuilds. A handful of empty pages is enough to install the reflex of dismissing without reading, and once that reflex exists it applies to the whole channel, not just the noisy signal that caused it.
So the expensive failure is not the noisy alert. It is the real alert that arrives afterward, into a channel the reader has already been taught to skim. The noisy signal spent credibility that a different signal needed later.
That cost never appears in the alert's own metrics. The chatty check looks fine. It fires, it resolves, nobody complains. The damage shows up somewhere else entirely, in the response time to the incident that mattered, and nothing connects the two.
The test: name the decision
Before a signal earns the right to interrupt anyone, it should answer one question. What decision does the recipient make when this arrives?
A real answer is specific. Fail over. Roll back. Stop the batch. Call the vendor. If the honest answer is "look at it and probably close it," the signal is not an alert. It is a log entry that acquired notification privileges it never justified.
This test is unkind to a large fraction of alerts that exist, which is the point. Most were added at a moment of anxiety, right after something broke, as insurance against being surprised the same way twice. That is a real motive but it produces a signal calibrated to a past fear rather than to a present decision.
Three tiers, and be honest about which one you need
Most signals belong in one of three places, and the mistake is sending everything to the first.
A page means a human changes what they are doing right now. It is reserved for conditions where delay makes the outcome materially worse, and where there is an action available. If nobody can act at 3am, it is not a page, no matter how serious it sounds.
A digest line means somebody should know within the day. Aggregated, batched, read once, and read properly because the volume is survivable. Most of what currently pages belongs here and loses nothing by the move.
A log entry means the information should exist if anyone goes looking. This is where the majority of "just in case" signals actually belong. Writing it down is not the same as telling somebody, and conflating the two is how channels die.
Deleting an alert is doing work
There is an asymmetry that keeps bad alerts alive. Adding one feels like diligence. Removing one feels like accepting risk, because if the removed condition ever occurs, the removal was visibly a mistake and the person who removed it owns that.
Nobody gets credited for the alert they deleted that would have masked a real incident, because that outcome is invisible. So alerts accumulate, monotonically, and the channel degrades on a schedule nobody planned.
The correction is to treat the alert set as something with a budget rather than something that grows. Every signal that has fired repeatedly without producing an action is a candidate for demotion, and demotion is the normal case, not an admission of anything. An alert set that has never shrunk is not thorough. It is unreviewed.
For agents, the same rule with sharper teeth
An agent can generate signals faster than a human can develop a filter, which makes an unreviewed alert set actively dangerous rather than just annoying. And an agent reading its own alerts has no social pressure to keep pretending a useless page matters. It will either act on everything, which is worse than acting on nothing, or it will need the same tiering a human does, made explicit.
So the rule holds in both directions. Each signal an agent emits names the decision it wants and who makes it. Each signal it consumes gets a tier. Anything that cannot name a decision is written down, not announced.
The measure of an alerting setup is not coverage. It is whether the last page anyone received got read carefully, and whether the next one will.
Alert tiering is one of the pieces that took us longest to get right, mostly by getting it wrong loudly first. If you are pruning your own alert set, One Agent, One Company ($9.97) has the tier tests and the failures behind them.