Understanding alerts
What each of the eight rules looks at, what 'Activity risk' means, why an alert did or did not fire, and how to dismiss one.
What are the eight rules?
| Rule | What it looks at | Default |
|---|---|---|
| R1 Large refund | Any single refund at or above your threshold | $100 |
| R3 Large discount | Any discount at or above your threshold | 30% |
| R6 Open check left outstanding | An order still open with no payment after a number of hours | 6 hours |
| R7 Refund shortly after sale | A refund within a number of minutes of the sale it reverses | 15 minutes |
| R9 Drawer opened with no sale | No-sale drawer opens, counted per employee per day | on |
| R12 Refund rate above store average | An employee's refund rate at 3× the average of other non-manager staff | after 50 transactions |
| R14 Discount rate above store average | Same comparison for discounts | after 50 transactions |
| R15 Void rate above store average | Same comparison for voids | after 50 transactions |
R12, R14 and R15 are included in the Pro and Complete tiers.
What does 'Activity risk: high' mean?
It is a priority label for your review queue, based only on how far outside your threshold the transaction is and on the amount involved. It is not a percentage and not a statement about the employee. High alerts are emailed as they happen; medium and low stay in the dashboard and appear in the weekly summary.
Why did an alert fire on something that was fine?
Because the transaction was outside a range you set, and the rules cannot know the context. That is by design: a $120 refund for a genuine return still meets a $100 threshold. Dismiss it with a short reason (for example, "return with receipt, approved by Sam") so the log shows it was reviewed. If a rule keeps flagging ordinary activity, raise its threshold in Settings.
Why did nothing fire on a transaction I expected to see?
The most common reasons: the amount was under your threshold; the refund was issued more minutes after the sale than your window; the employee is marked as a manager (excluded from rate comparisons); or the employee has fewer than 50 transactions in the last 30 days, so the comparison rules have not switched on. Voids made through Clover's Virtual Terminal are removed from Clover's records entirely and cannot be seen by any app; voids made on a device are visible.
What is in 'Transaction records used'?
The exact Clover records the alert was computed from: order and payment IDs, amounts, times and the employee login. They are stored with the alert and cannot be changed afterwards, by you or by us. Use them to find the transaction in Clover's own Transactions page.
How do I dismiss an alert?
On the alert, type an optional reason and select Dismiss alert. It moves to the Dismissed list with your reason and the time. Dismissing never deletes the alert or its records.
Can an alert be edited or deleted?
No. Alerts and their records are append-only. You can dismiss an alert; nobody can alter one. This is deliberate, so the log is a reliable account of what was flagged and what was reviewed.