> For the complete documentation index, see [llms.txt](https://docs.compliance.phalcon.blocksec.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.compliance.phalcon.blocksec.com/manual/monitor.md).

# Monitor

Monitor continuously tracks risk changes for addresses you care about and sends you notifications when updates are detected — no need to manually re-screen.

## What Is Monitor

Enable Monitor on any screened address, and Phalcon Compliance will automatically re-analyze it on a dynamic schedule. When a risk change is detected — such as a new alert triggered, an alert expired, or the overall risk level changed — you'll be notified through your configured channels.

## Availability

* **Essential and Scale**: 1 monitored address included. Add more via the Monitor Add-on. See [Plans, Billing, and Payment](/manual/plans-billing-and-payment.md#monitor-add-on) for details.
* **Free and Credits**: 7-day free trial (one-time per account). Upgrade to continue.
* **Enterprise**: Custom capacity per contract.

## Enabling and Stopping Monitor

You can enable Monitor from:

* **Address Details Page** — Click the **Monitor** button in the top action area.
* **Address List** — Use the action menu on the right side of any row.

To stop, click **Stop Monitor** from any of the above locations or from the Monitor management page.

## Setting Up Notifications

Monitor events are delivered separately from Risk Engine alerts. To receive them:

1. Go to **Notification Channels**, open a channel, and enable **Monitor Events**.
2. On the **Monitor** page, click **Edit** to choose which events trigger notifications:

<figure><img src="/files/eOsf2mrj6ym4WPbJ8hJn" alt="Monitor notification settings panel"><figcaption></figcaption></figure>

| Event Type           | Severity Filter                       |
| -------------------- | ------------------------------------- |
| Risk Level Increased | —                                     |
| Risk Level Decreased | —                                     |
| Alert Triggered      | All / High & Critical / Critical only |
| Alert Expired        | All / High & Critical / Critical only |

All four event types are enabled by default.

## Monitor List

Monitor is a top-level item in the sidebar. The page has two tabs:

<figure><img src="/files/NpXSBvpYIgCwVsnZBt1b" alt="Monitor list page"><figcaption></figcaption></figure>

**Active** — addresses currently being monitored, showing chain, risk level, monitoring start time, and latest event.

**Stopped** — addresses no longer monitored, showing when and why monitoring stopped. You can **Resume** a stopped monitor if you have available quota.

Your current quota usage is displayed in the toolbar.

## Monitor Detail Page

Click any address in the Monitor list to view its detail page, which includes:

<figure><img src="/files/pa3ETtIZgtgQJUnWKJ3B" alt="Monitor detail page with risk timeline"><figcaption></figcaption></figure>

* Current status, chain, risk level, and when monitoring started
* Actions to stop or resume monitoring

### Risk Timeline

A chronological history of everything that happened while the address was monitored:

* **Monitoring started / stopped** — When monitoring began or ended.
* **Risk level changed** — Shows the previous and new level, with the alerts that caused the change.
* **Alert triggered / expired** — Individual alert events that did not cause a level change.

The timeline is complete and unfiltered — it records all events regardless of your notification trigger settings.

## Notification Message Types

Monitor sends four types of notifications:

* **Risk Level Increased** — The address's risk level has escalated, with the related alerts listed.
* **Risk Level Decreased** — The address's risk level has de-escalated, with the expired alerts listed.
* **Alert Triggered** — New alerts detected that did not change the risk level.
* **Alert Expired** — Alerts expired that did not change the risk level.

Each message includes the address, chain, current risk level, and a link to the Monitor detail page.
