# Audit the alert rules you inherited

Scores every alert in Datadog, Sentry, Cloudflare and Better Stack by how often it fires against how often it mattered.

## The prompt

```
I want to do this: Go through our alert rules: which ones fire the most, and which were ever real?

## Setup (skip if Polylane is already set up)

Read and follow https://polylane.com/auth.md for non-interactive signup and setup. Start by checking whether I am already signed in; reuse my account and workspace.

If the CLI is missing, bootstrap it without starting the interactive wizard:

curl -fsSL 'https://polylane.com/setup?ref=prompts' | bash -s -- --install-only

Then follow the guide through email verification, workspace selection, source connections, and MCP authentication. Ask me for an email code or OAuth consent only when needed. Verify each step; report pending setup instead of claiming success from installation alone.

## How to work

Over MCP: searchTools lists what this workspace exposes, with each tool's schema; call it first. runTool runs one tool, runCode chains several in one call and returns just the answer. search and execute cover the full Polylane REST API: threads, issues, investigations, autofixes, memories.
From the terminal: the polylane CLI wraps the same API, with structured output and non-interactive flags everywhere.
Reads always work. Write tools appear only if I have opted in, and every write is screened.

## Task: Audit the alert rules you inherited

Steps:
1. List the alert rules and monitors across connected providers
2. Pull each one's firing history for the window
3. Cross-reference firings against the issues that turned out real
4. Score each rule: signal rate, duplicate rate, last true positive
5. Deliver the audit with delete, tune, and keep recommendations

Ground every claim in data you actually pulled: the query, the log line, the change record. If the data is inconclusive, say so. Ask me before anything that writes.
```

## What it replaces

**Every alert was somebody's good idea.** Rules accumulate: the 2023 migration, the incident that never recurred, the threshold set in a panic. Deleting one feels dangerous, so the noise compounds instead.

- Rules nobody remembers writing, firing weekly
- Real alerts buried under ceremonial ones
- "Just mute it" as alert management

## What the agent does

1. List the alert rules and monitors across connected providers
2. Pull each one's firing history for the window
3. Cross-reference firings against the issues that turned out real
4. Score each rule: signal rate, duplicate rate, last true positive
5. Deliver the audit with delete, tune, and keep recommendations

## What you get

**Delete with confidence** Every rule scored against what actually happened, so pruning stops being guesswork. The pager gets quieter without getting blinder.

Every prompt: https://polylane.com/prompts/

Get started with one command: `curl -fsSL https://polylane.com/setup | bash` installs the CLI, connects your coding agents, and creates the account.
