Make monday.com work with Microsoft 365 & SharePoint →
TICK logo

TICK

lmtify

2 installs, since May 26, 2026.   1 installs/month.   App updated May 22, 2026. Listing updated June 2, 2026.

Paid No touch

Trigger automations based on real time in status.

TICK — Your key to time-in-status driven automation.

Trigger automations and workflows based on how long tasks actually stay in a status, with no date columns, manual updates, or workarounds. Designed to feel like a native platform experience.

No additional automation limits. Usage follows your monday.com plan.

At its core, TICK introduces a new type of trigger based on time in status.

As soon as a task enters a status, the clock starts ticking. Tasks already in the status are also included, so tracking starts immediately without missing anything.

Based on configurable time stages, the trigger runs over time, enabling actions to be triggered at each stage as time progresses, with execution within minutes once conditions are met.

Built for fast escalation workflows, TICK supports up to 72 hours of continuous tracking.

Use TICK to detect stuck tasks, notify the right people, escalate delays, move items, update statuses, assign owners, or trigger the next step in your workflow.

Whether you manage operations, support, delivery, approvals, or internal processes, TICK helps you respond the moment work stays too long where it should not.

Build simple reminders or advanced multi-stage workflows where actions evolve over time, with step-by-step responses.

TICK also provides a tracking view of your board, giving you clear visibility into tasks and their time in status.

View each task’s details, stay on top of delays, and understand how work progresses over time.

For a higher-level view, add the dashboard widget to monitor outcomes across all triggers on selected boards.

See completed outcomes summarized as Healthy, At Risk, or Breached over 24-hour, 7-day, and 30-day windows.

Time in status can be tracked based on either continuous wall-clock time or configured working hours.

Additional control and visibility are available via Sidekick AI skills.

Security & Compliance

Security

Does the developer periodically perform penetration testing?

Not answered

Does the developer have a dedicated security and privacy point of contact for such issues or questions?

Not answered

Does the app restrict redirects and forwards only to approved destinations, or show a warning when redirecting to potentially untrusted content?

Yes
The app restricts redirects and forwards to approved destinations only.

Does the app protect against mass parameter assignment attacks?

Yes
API handlers do not bind incoming request bodies directly to database records. Each endpoint reads only the expected fields, validates them, and writes updates using explicit, server-controlled field lists. Sensitive attributes (tokens, roles, installation identity) are set by the server from verified session context, not from client-supplied parameters.

Does the app perform encoding and sanitization on all user supplied parameters to protect against Cross-Site Scripting?

Yes
Yes. User input is escaped when displayed, validated on the server, and the app does not render user data as HTML. A Content-Security-Policy adds extra protection against script injection.

Does the developer protect all state-changing actions against Cross-Site Request Forgery (CSRF)?

Yes
Yes. State-changing requests require authenticated session proof, so actions cannot be triggered from another site using the user’s browser alone.

Does the developer have mechanisms to notify monday.com in case of a security breach?

Yes
Yes

Does this developer have a process for installing application-level updates and security patches for the service (such as software packages and databases)?

Yes
Yes. We keep the service up to date through regular dependency updates and controlled application releases. The app runs on AWS managed services, which receive platform security patches from AWS. Critical security fixes are prioritized and deployed as soon as practicable.

Compliance

Is the app certified with the information security standard ISO/IEC 27001:2022?

Not answered

Is the app compliant with the Health Insurance Portability and Accountability Act (HIPAA)?

Not answered

Is the app certified with System and Organization Controls (SOC 2 or SOC 3)?

Not answered

Is the app compliant with the General Data Protection Regulation (GDPR)?

Not answered

Data

Does the app send any data outside of monday.com? If yes, indicate whether the data is customer-submitted (e.g., board names, item names, doc content) or non-customer-submitted (e.g., account ID, board ID, user ID).

Yes
Yes. The app processes and stores data on the developer’s infrastructure (AWS) to provide the service. It also calls the monday.com API as required for the integration. Customer-submitted data (limited): Automation/trigger configuration chosen by the user (board, columns, filters, timing, working hours) Labels/metadata needed to run triggers (e.g. status/group/team filter names) We do not store full document content, and item names are fetched from monday.com for display only (not persisted on our servers) Non-customer-submitted data: Account ID, app/installation ID, board ID, item ID, user ID (as identifiers) auth tokens (encrypted) Subscription/recipe/integration IDs, webhook event metadata, audit/security logs We do not store user email/name from monday.com webhooks.

Where does the app store logs data?

aws
AWS managed services

Where does the app store the app data?

DB
AWS managed services

Does the developer ensure application logs do not contain secrets or personally-identifiable information (PII)?

Yes
Yes. Logs are designed not to include secrets or unnecessary PII. Auth tokens raw request bodies are not written to logs. User email/name from monday.com webhooks are stripped before processing. Audit logs store only allowlisted configuration and security events, not full customer content. Where a monday.com user ID is needed for audit reference, it is stored as a hashed reference and encrypted, not in plain text.

Is customer data segregated from the data of other customers (for example logically or physically)?

Yes
Yes. Customer data is logically segregated. Each monday.com account has its own tenant scope; data is stored and accessed by installation ID, so one customer cannot access another’s data. All customers share the same AWS infrastructure, but records are separated at the application and database level.

Privacy

Does the developer enforce multi-factor authentication on employees access to systems which may process customer data?

Yes
Yes

Does the developer protect access to customer data based on the principle of least privilege?

Yes
Yes. Access to customer data follows least privilege at both the application and AWS layers. Each service component runs under its own role with permissions limited to the specific resources it needs.

Reviews

No reviews yet.

Historical data

Installation history

We have data for December 28, 2024 onwards only. Collected sometime after 00:00 UTC daily.

Total number of installs

Change in total number of installs in last 1 day(s)

Compares the number of installs on each date with 1 days previously:

Max
Min
Current

Change in total number of installs in last 7 day(s)

Compares the number of installs on each date with 7 days previously:

Max
Min
Current

Change in total number of installs in last 30 day(s)

Compares the number of installs on each date with 30 days previously:

Max
Min
Current

Change in total number of installs in last 90 day(s)

Compares the number of installs on each date with 90 days previously:

Max
Min
Current

Change in total number of installs in last 180 day(s)

Compares the number of installs on each date with 180 days previously:

Max
Min
Current

Ratings history

Categories history

Each of the following is a yes/no answer, so the graphs show 1 for yes, and 0 for no.

In "Featured" category?

In "Editor's choice" category?

In "Trending this week" category?

App metadata

ID: 10001199App ID: 11115673Listing updated: June 2, 2026