> For the complete documentation index, see [llms.txt](https://knowledge.whiteintel.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://knowledge.whiteintel.io/monitoring/watchlists.md).

# Watchlists

Watchlists define the assets WhiteIntel monitors on your behalf. Adding an identifier to a watchlist enables continuous detection and alerting for that asset, and populates the corresponding views in Your Dashboard and Watchlist Events.

**Availability:** All plans. Groups and multiple alert recipients require an Enterprise or Threat Intelligence subscription. Some identifier types require a Threat Intelligence subscription.

<figure><img src="/files/Tp1TqLF3iyXvvwHYWQi0" alt=""><figcaption></figcaption></figure>

### Identifier types

* **Domain** — a registrable domain. Triggers on leaks against the website or any account using that email domain.
* **Subdomain** — a specific host to monitor independently. Subdomains share the domain quota.
* **Email address** — an individual mailbox.
* **IP address** and **Computer name** — device-level identifiers. Require a Threat Intelligence subscription.
* **Keyword** — a free-text term to monitor for dark web mentions.
* **Github repository** — a repository to monitor for exposed secrets.

A Definitions tab on the page describes each type and the tier required to use it.

<div align="left"><figure><img src="/files/0AHYAB622WlLXhIo179w" alt=""><figcaption></figcaption></figure></div>

### Adding an identifier

1. Choose the identifier type and enter the value.
2. For domains and subdomains, choose the **Record type** to alert on: corporate, consumer, or both.
3. Choose who to notify, and any delivery options.
4. Review the summary and confirm.

Each identifier type draws from its own pool of available identifiers in your subscription. The form shows how many remain and links to upgrade when a pool is exhausted.

### Notifications and recipients

The primary recipient is the signed-in user's email by default. On Enterprise and Threat Intelligence subscriptions, one additional recipient can be added from your organization's members. Individual accounts can only notify their own email.

### Delivery options

Depending on the identifier type and your integrations, you can enable:

* **Detect look-alike domains** (for domains),
* **Push to Jira**,
* **Push to Slack**,
* **Include usernames as CSV** in alerts.

Options that require an integration or a higher tier are shown with the relevant indicator.

### Groups

On Enterprise and Threat Intelligence subscriptions, identifiers can be filed under groups, such as one group per business unit or subsidiary. Groups can be created, renamed, color-coded, and deleted, and identifiers can be assigned individually or in bulk. Group views are then available throughout the Dashboard.

<figure><img src="/files/Xo8MhtKCWaCHVo1u6Trd" alt=""><figcaption></figcaption></figure>
