Reports and notifications
Run history, branded PDF and client reports, custom report domains, and email and Slack alerts.
Run history
Every run is recorded under its project. Projects → history shows the run ledger and a score trend per bundle, with scheduled scans labelled Scheduled scan and manual cloud runs labelled Cloud scan. Cloud runs show progress automatically on their detail page; see Cloud scans. Opening a run shows the decision, the findings grouped by check with selectors and fix guidance, and the commit, branch, and pull request it came from.
Projects → overview puts every project’s latest result and trend on one screen, which is where agencies with many client sites usually start their day.
PDF reports
Any run can be downloaded as a PDF from its page. The report carries your organization’s name, logo, and accent color, and lists up to 20 findings in priority order.
Sending a report to a client
On any paid plan, a run’s page has Send this report to a client. It creates a private link that opens the branded report, with a PDF download, without an account.
This is included in Developer, Team and Agency. A custom report domain is a separate Agency capability, not a requirement for private client links.
- Links expire after 7, 30, or 90 days, or never.
- The link is shown once, when you create it.
- You can revoke your own links at any time; owners and admins can revoke any link in the organization.
- Report pages are marked
noindexand are never cached by browsers or proxies.
Branding
Owners and admins set the report identity under Organizations:
- Logo URL: a public HTTPS address of a PNG, JPEG, or WebP image, at most 1 MiB.
- Accent color: used for headings and highlights in HTML and PDF reports.
Your own report domain (Agency plan)
Agencies can serve client links from their own host, for example
reports.youragency.com, so clients never see QualityGate:
- Under Organizations → Report domain, enter the hostname.
- Add the two DNS records shown there at your DNS provider: a
CNAMEthat points the hostname at QualityGate (set it to DNS only if your provider offers proxying), and aTXTrecord that proves you own it. - Choose Check DNS. The domain becomes active once the records resolve and the certificate is issued.
From then on, new client links open on your domain and the report shows only your organization’s name, logo, and accent. The domain serves report links and nothing else. A hostname that is not verified within seven days is released.
Notifications
QualityGate can email and post to Slack when something needs attention.
Organization settings (under Organizations, owners and admins):
- an email recipient, for example a team list;
- a Slack incoming webhook URL (
https://hooks.slack.com/services/...), stored encrypted and never shown again; - Quota alerts by email and Slack, sent when monthly usage reaches 80% and 100%;
- Weekly digest by email and Slack, summarizing every project, including the latest scheduled scan per project and bundle.
Project settings (on each project’s card): whether a failed gate notifies by email, Slack, or both. This covers pull request, branch, and scheduled runs.
To create a Slack webhook, add the Incoming Webhooks app to your Slack workspace, choose a channel, and copy the webhook URL it gives you.