Configuring TSFA Settings

Configuring TSFA Settings

Managing Incident Severity and Notifications

The TSFA Settings page allows administrators to configure incident notifications and manage prevalence thresholds used by ThinkShield Firmware Assurance (TSFA) to identify widespread issues.

This feature is available for Org Admins and IT Admins under Configurations & Settings > Organization Settings > TSFA Settings
Notes
  1. Any TSFA user can add or delete other users from the Settings table.
  2. By default, no users receive notifications or emails until configured.

Setting Up Incident Notifications

  1. Sign in to an Organization as an Org Admin or IT Admin. 
  2. From the top drop-down menu select Configuration & Settings.
  3. In the left panel, go to Organization Settings > TSFA Settings.
  4. Open the Incident Notifications tab.
  5. Select Add Users
  6. Select the checkboxes next to the users you want to configure alerts for.
  7. Click Save.
  8. Optional: To send email notifications when an incident occurs, turn on the Email Notifications toggle button to On and click Save.

Removing Users

  1. Select the checkbox next to the organization user(s) to exclude from notifications.
  2. Click Remove Users.
  3. Click Proceed. User(s) will stop receiving the notifications.

Setting Up Prevalence Event Thresholds

Org Admins can configure Prevalence Event Thresholds to control how prevalent issues are identified. Values must be between 0.01% and 99.99%, with up to two decimal places. If no decimal is provided, the value is treated as a whole number. Trailing zeros (e.g., 4.00) are ignored, and values with more than two decimal places are not accepted.

To Update Thresholds
  1. Open the Prevalence Model tab.
  2. Click Edit.
  3. Enter the desired threshold values.
  4. Click Save.
Default threshold values:
  1. 24 hours: 10%
  2. 7 days: 5%
  3. 30 days: 2% 
Notes
Updates do not affect issues previously identified as prevalent.
New threshold values take effect the following day at approximately 1:00 AM, when the Prevalence Model runs again.
For more information, read Incident Overview.