Signals and namespaces
A signal is a field that a query can inspect. Its namespace identifies the source of that field. Start with the source, then narrow the reference by signal group or field name.
Choose a namespace
Section titled “Choose a namespace”Read a field name
Section titled “Read a field name”domain.classification.phishing has two parts. domain selects the namespace; classification.phishing selects the field within that source.
domain.classification.phishing:>0.8Existing Domain rules can keep unqualified names such as classification.phishing. In alert rules, an unqualified field resolves to Domain. Use explicit prefixes when writing rules that include Email or Canary. The compatibility-only created_on field is the exception: it must remain unqualified and records when the lookup result was created.
Query support and rule support
Section titled “Query support and rule support”| Namespace | Data source | Alert rules |
|---|---|---|
domain |
Results from the current domain analysis | Supported |
email |
Email Intelligence events linked to the monitored domain | Supported with Email Intelligence access |
canary |
Site Canary events for the monitored domain | Supported with Site Canaries access |
In the visual builder, choose a namespace for each condition group. The field picker then shows that source’s fields. Email and Canary availability follows the organization’s feature access.
Matched results has separate Domain, Email, and Canary tabs. These previews search each source independently across organization data within the selected window. They do not simulate a complete rule run scoped to one monitored domain.
Combine sources deliberately
Section titled “Combine sources deliberately”Conditions within one namespace apply to one record. Conditions across namespaces check for matching records independently within the monitored domain’s scope. They do not join an email, a Canary event, and a domain result into one correlated event.
See rules across namespaces for examples, time windows, and supported Boolean shapes.
Field availability
Section titled “Field availability”A registered field may have no value on a particular record. Enrichment coverage, provider event type, scan results, and subscription access determine what data is present. Use _exists_: when presence itself matters.
Each namespace reference includes the public catalog’s exact field names, types, and descriptions. Search within a namespace or open one signal group at a time. See Upsilon query syntax for operators and type-specific behavior.