Incidents

Escalation

Escalation policies automatically re-assign an incident that stays in the Open state for too long to another team or to a user.

An escalation policy guarantees that an incident will always be handled: if an incident stays in the Open state (that is, without being acknowledged) for too long, it is automatically escalated, meaning re-assigned to another team or to a specific user, who is then notified in turn.

How it works

Escalation policies are defined per team: they apply to the incidents assigned to that team. The image below shows an example of an incident escalating from an L1 team to an L2 team, either automatically or manually.

Escalation workflow

Your organization and processes may require different escalation policies. If, for example, you want a managerial escalation (the incident is escalated from the employee on call to their line manager if no action has been taken after a few hours, then to the next manager, etc.) rather than a technical escalation as in the example above, this is possible through configuration. For example, you can define an escalation policy like this one:

Example of managerial escalation

Note: A multi-level escalation is achieved by chaining teams: the L1 team escalates to the L2 team, which has its own escalation policies (to the L3 team, etc.).

Configuration

Escalation policies are configured from the main Teams tab, by selecting a team and then the Escalations menu. Each policy includes:

  • a name that describes it (for example "Escalate to the IT team")
  • conditions (optional) that incidents must meet to be escalated: no condition, at least one of the conditions (OR), or all of the conditions (AND). As for routing rules, a condition relates to the priority of the incident (equal to, more critical than, ...) or to its tags (contain / do not contain)
  • a delay (After), from 1 minute to 1 week, beyond which the incident is escalated if it has not been acknowledged
  • the escalation target (Escalate to): a team or a user

Policies are evaluated sequentially, in the order shown on screen: the first policy whose conditions are met is applied. A policy with no condition therefore applies to all incidents that don't meet the conditions of the previous policies.

Escalation policies can be created and edited by Owners and Responders. A step-by-step guide is available on the How to configure automatic escalations? page.

Note: The routing map lets you visualize the complete path of an incident, from the routing rules to the end of the escalation chain.

Manual escalation

You can also escalate any incident manually, from its page, by re-assigning it to any team or user using the Re-assign action.

Escalation or reopening?

Escalation only applies to incidents in the Open state. To prevent an Acknowledged incident from being forgotten, use reopening policies instead: they automatically re-open it after a given delay (which restarts notifications, and then escalations).