Skip to main content
Subscriptions turn a question you want to revisit into a standing watch. Forge evaluates new activity against the subscription, records each matching event, and groups matches by session so you can review the evidence as it arrives. Open any match in Live activity to see the surrounding session and decide what to do next. This is useful when a one-time search is not enough: you are validating a new integration, monitoring a high-risk pattern, waiting for a policy or access change to take effect, or keeping an investigation open until the pattern stops. A subscription is a review workflow, not an enforcement rule or a notification channel.

Create a subscription

You can create a subscription from the activity experience:
  • From scratch with natural-language, full-text, or standard-filter matching.
  • From a saved search, preserving its query and scope for future activity.
  • With optional scope filters for one or more integrations, directory users, or devices.
  • With saved-search history when earlier matches should be included in the initial review queue.
Scope filters narrow the candidate activity before the query is evaluated. When no scope filters are selected, the subscription watches the whole organization.

How matching works

Subscriptions evaluate incoming activity and record each event at most once per subscription. The selected mode determines how the query is applied: Natural-language matching is semantic, so review the first results and narrow the scope or rewrite the query if it is too broad. Full-text matching is literal; it does not expand synonyms or interpret a natural-language question. For a subscription created from a saved search, Forge keeps the saved search’s query and filters. You can choose whether to seed the subscription with the saved search’s existing results or start with new matching activity only.

What it shows

  • Query mode and source (scratch or saved search).
  • Scope chips for selected integrations, directory users, and devices.
  • The number of matched sessions and matching events.
  • The matching method for each event, including semantic, full-text, or standard-filter matches.
  • Links back to the matching session or event in Live activity.

Good uses

  • Watch for unapproved AI products or known risky phrases.
  • Monitor activity from a selected integration, directory user, or device.
  • Follow a sensitive cohort while validating a new source or rollout.
  • Keep a recurring policy-review pattern visible until ownership or scope is settled.
  • Track an investigation theme across new sessions without rebuilding the search each time.

Workflow

1

Start from a question

Example: “Which finance devices are using unapproved AI products?”
2

Build or reuse a search

Choose a matching mode and narrow it with integration, directory-user, or device scope. Use a saved search when you already have the right query.
3

Check sample matches

Open a few sessions in Live activity to confirm that the results represent actionable evidence.
4

Save the subscription

For a saved search, include history only when earlier matches belong in the initial queue.
5

Tune it

Narrow noisy subscriptions, or broaden the query and scope when expected matches are missing.

Query examples

A good subscription has a clear next action. If nobody knows what to do when it matches, refine the query or make it a one-time investigation.