Currently there is no way to know if a tech or a customer who has access to their tenant creates a very broad rule - basically ones that disregard ALL alerts for a specific issue - unless I go in and happen to come across it during an audit. This seems to be a huge blind spot for a broad rule to get created and go unnoticed until an issue arises. Either create a permission group that simply greys that option out so someone can’t create it or the ability to audit it and generate alerts around it so it can be addressed then and there.
