Create a subscription
You can create a subscription from the activity experience:- From scratch with natural-language, full-text, or standard-filter matching.
- From a saved search, preserving its query and scope for future activity.
- With optional scope filters for one or more integrations, directory users, or devices.
- With saved-search history when earlier matches should be included in the initial review queue.
How matching works
Subscriptions evaluate incoming activity and record each event at most once per subscription. The selected mode determines how the query is applied:
Natural-language matching is semantic, so review the first results and narrow
the scope or rewrite the query if it is too broad. Full-text matching is
literal; it does not expand synonyms or interpret a natural-language question.
For a subscription created from a saved search, Forge keeps the saved search’s
query and filters. You can choose whether to seed the subscription with the
saved search’s existing results or start with new matching activity only.
What it shows
- Query mode and source (scratch or saved search).
- Scope chips for selected integrations, directory users, and devices.
- The number of matched sessions and matching events.
- The matching method for each event, including semantic, full-text, or standard-filter matches.
- Links back to the matching session or event in Live activity.
Good uses
- Watch for unapproved AI products or known risky phrases.
- Monitor activity from a selected integration, directory user, or device.
- Follow a sensitive cohort while validating a new source or rollout.
- Keep a recurring policy-review pattern visible until ownership or scope is settled.
- Track an investigation theme across new sessions without rebuilding the search each time.
Workflow
1
Start from a question
Example: “Which finance devices are using unapproved AI products?”
2
Build or reuse a search
Choose a matching mode and narrow it with integration, directory-user, or
device scope. Use a saved search when you already have the right query.
3
Check sample matches
Open a few sessions in Live activity to confirm that the results represent
actionable evidence.
4
Save the subscription
For a saved search, include history only when earlier matches belong in the
initial queue.
5
Tune it
Narrow noisy subscriptions, or broaden the query and scope when expected
matches are missing.