Help

Website Watch Help

Troubleshoot Watch billing, missing alerts, mutes, quiet hours, pause versus cancel, and how Watch differs from Scheduled Scans.

Who This Topic Is For

Users who already added or tried to add a watched site and need the next operational step or a fix for missing alerts.

Prerequisites

Before You Start

Use this checklist to make sure the workflow guidance applies cleanly to your current task.

  • You can sign in and open /watch.
  • You know the HTTPS URL you intended to monitor.
  • You can see the watch status pill or the error shown when Watch website failed.
Expectations

What To Expect

Use this section to set the right outcome before you start the workflow.

No mail on the first clean baseline

If the first runs only record what was already there, Watch stays quiet. Alerts start when something new appears, the score drops, or a cert window is hit.

Pulse is lighter than the weekly scan

Daily pulse covers headers, certificate days, mixed content, HTTP to HTTPS, and common exposed paths. Weekly Standard or Deep is the matching dashboard pack, locked for that seat. Pulse will not look like a ZAP-backed full scan.

Manual runs are rate-limited

Run pulse now at most once per 15 minutes. Run weekly Standard now or Run weekly Deep now at most once per 6 hours. Scheduled included runs still follow the daily and weekly cadence.

Playbook

Step-By-Step Guidance

Follow these steps in order for a reliable and repeatable outcome.

  1. Confirm the watch exists and is active.

    Open /watch and click the site.

    Status should be active. pending_payment means checkout is not finished.

    paused means you stopped runs on purpose. past_due means billing needs the Manage billing portal.

  2. Read last pulse, last full, and certificate days.

    If last pulse is empty, the runner has not completed a pulse yet. If last weekly scan is empty, the weekly Standard or Deep scan has not landed.

    Certificate days and last window explain whether a cert alert should already have been sent.

  3. Check alert settings before assuming mail failed.

    Confirm New findings, Score drop, minimum severity, quiet hours, timezone, extra recipients, and Weekly digest. A High minimum severity will skip a Low header finding.

    Quiet hours delay rather than drop the event.

  4. Inspect Open issues and mutes.

    If the finding is listed and you previously clicked Mute, alerts for that fingerprint will not repeat. Click Unmute on the open-issue row or in Muted issues to restore alerts for that fingerprint only.

  5. Do not confuse Watch with Scheduled Scans or credits.

    Custom cadence and Comprehensive still live under Scheduled Scans and the dashboard.

    Watch included runs do not deduct credits. If a credit Comprehensive did not run, that is not a Watch defect.

    If weekly Deep did not run, confirm the seat is Deep, not Standard.

Examples

Worked Examples

These scenarios show how the workflow looks in practice, including the result you should see.

Alert missing during quiet hours

Quiet hours are 22:00 to 07:00 America/New_York. A pulse at 01:10 finds a new exposed path. Mail does not arrive at 01:10. It arrives after 07:00.

This is expected delay, not a failed runner. Disable quiet hours if overnight mail is required.

Checkout blocked because billing is not configured

Watch website returns Watch billing is not configured instead of a Stripe URL. Price IDs are not live for this environment. The site is not watching yet and no seat was added.

Contact support. Do not retry until prices exist. There is no fake success path.

Zero credits, Watch still green

The account credit balance is 0. The watch stays active. Next pulse and weekly Standard or Deep still run. A teammate then starts Comprehensive from the dashboard and is blocked until they buy credits.

Watch included cadence is independent of credits. Comprehensive is not.
Operations

Operational Playbook

Use this long-form guidance to execute the workflow consistently across planning, implementation, and validation.

Treat Watch As Change Detection, Not A Replacement Scan Menu

Website Watch is a per-site subscription that answers a narrow question: did this HTTPS origin change in a way you asked to hear about. It is not a pentest. Daily pulse is the same on every seat. Pick Standard or Deep for the weekly scan when you add the site; that depth is locked for the seat. Quick and Comprehensive are not Watch tiers. If a teammate expected Comprehensive, add-ons, or a custom weekday, they are describing Scheduled Scans or a dashboard credit scan. Keep those products in the same account if you need them. Watch still earns its seat when credits are at zero, which is intentional so monitoring does not silently stop during a credit dip. When a ticket says Watch did not scan Comprehensive, the correct reply is to run Comprehensive from the dashboard. When it says Watch did not scan Deep, check whether the seat is Standard or Deep before sending them to a credit scan.

Expect A Quiet Baseline, Then Alerts On Delta

The first successful pulse and weekly Standard or Deep scan establish what already existed. Vulnify does not email every historical finding on day one. After that baseline, alerts fire for new or worsened findings, resolved findings if that setting is on, score drop beyond the threshold, and certificate windows at 30, 14, 7, and expired. The cert window uses the tightest match, so 12 days remaining is a 14-day window rather than 30. If nothing new appeared, no mail is the correct outcome. Before escalating missing email, confirm the watch is active, quiet hours are not covering now, the finding is not muted, and minimum severity is not set above the issue you expected.

Separate Occupied Seats From Running Checks

Occupied seats include pending_payment, active, paused, and past_due. Pause is a freeze: pulses stop, the site still counts against quantity, and Resume continues from the last baseline. Cancel is an end-of-term drop: the watch stops and quantity decreases at period end without a mid-cycle credit. Agencies should pause during a client freeze and cancel only when the site should leave billing. Adding a sixth client when five seats of that depth are occupied opens Stripe Checkout. Unused paid seats attach without a new checkout only when the new origin uses the same depth. A Standard spare will not cover a Deep origin. If checkout says Watch billing is not configured, payment prices are not live yet and the add cannot succeed until support or an admin finishes Stripe Price setup.

Use Mutes And Quiet Hours As Policy, Not As A Bug Switch

Mute is for accepted risk, staging exceptions, and findings you already track elsewhere. A muted fingerprint remains visible as an open issue with a Muted pill, and it also appears under Muted issues. It drops out of new-finding mail until you click Unmute. Quiet hours delay alerts until the window ends in the watch timezone, which is why a 02:00 pulse may arrive at 07:00. Weekly digest, when enabled, sends Monday at 09:00 in that timezone so operators can review even if they muted noisy items. Extra recipients are capped at five. If Slack or Jira is connected, Watch can also emit a watch.alert event for the same change. Do not disable New findings globally to silence one issue; mute that fingerprint instead.

Escalate With The Watch URL, Status, And Last Run Times

A useful Watch support request includes the watch name, HTTPS URL, status pill, last pulse time, last weekly scan time, locked depth (Standard or Deep), certificate days, whether quiet hours are set, and whether the missing item is already listed under Open issues as muted. Include whether the user expected a pulse, a weekly Standard, a weekly Deep, or a credit Comprehensive scan. That split prevents a long investigation into the wrong product. Manual Run pulse now is limited to once per 15 minutes and Run weekly Standard now or Run weekly Deep now once per 6 hours, so a second click in the same window is not a failure of the runner.

Validation

Validation Checklist

Use this checklist to confirm the workflow was completed correctly.

  • Watch status is active or the billing state is understood.
  • Last pulse or last full time is present after a reasonable wait.
  • Alert checkboxes and quiet hours match the missing-mail theory.
  • The missing finding is not muted and meets minimum severity. If it is muted, Unmute it from Open issues or Muted issues.
  • The requested depth matches the locked Watch seat (Standard or Deep). Comprehensive is a credit scan.
Troubleshooting

Common Problems And Fixes

If something does not match expectation, check these common failure modes first.

No email after adding the site

The baseline is quiet on purpose. Wait for a later pulse or weekly Standard or Deep scan, or click Run pulse now after the 15-minute limit. Confirm the watch is active and not paused.

Common failure mode

HTTP URL rejected

Use an HTTPS origin. Watch is not a scanner for plain HTTP sites.

Common failure mode

Pause dropped monitoring but billing stayed

That is correct. Pause occupies the seat. Cancel if the site should leave quantity at period end.

Common failure mode

Weekly Standard or Deep looks different from a pulse

Expected. Pulse is a lightweight daily check. Weekly Standard or Deep is the matching dashboard pack and appears in scan history when a scan_id is present.

Common failure mode

Manual run says action failed immediately after the last click

Honor the 15-minute pulse and 6-hour full limits. The included daily and weekly schedule is separate from those manual buttons.

Common failure mode

Muted a finding by mistake

Open the watch and click Unmute on that open-issue row, or under Muted issues. You do not need support to clear a mute.

Common failure mode
FAQ

Website Watch Help FAQs

Common questions for this topic.

The first successful runs set a baseline so Watch does not spam existing findings. Alerts start when something new appears, the score drops, or a certificate window is reached.

Next Recommended Action

Continue to the best next page based on where you are in your workflow.