Classify by business impact.
| Severity | Definition | Initial response | Channel |
|---|---|---|---|
| P1 Critical | Covered production service unavailable, active data-loss event or critical security incident | Under 15 minutes where contracted | 24/7 contracted channel |
| P2 High | Material production impairment with substantial user or revenue impact | 1 hour where contracted | Contracted support channel |
| P3 Medium | Non-critical impairment with a workaround | 4 hours where contracted | Contracted support channel |
| P4 Low | Question, planned change or minor issue | 24 hours where contracted | Standard support channel |
Send enough to begin triage.
- Customer and affected service
- Observed start time and current impact
- Environment, region and affected users
- Recent changes and known dependencies
- Error messages, monitoring links and safe reproduction steps
- Technical contact and change authority
One thread, increasing depth.
1. Operations desk
Receives the incident, validates scope and impact, opens the incident record and begins triage.
2. Technical escalation
Brings the appropriate systems, cloud, network, database, security or application owner into the same incident path.
3. Service owner
Handles priority conflicts, customer communication and decisions that cross technical or commercial boundaries.
4. Executive escalation
Reserved for material business impact or unresolved ownership, not as a replacement for the incident channel.
Response does not remove dependencies.
Resolution may require customer approval, developer action, third-party provider work, additional capacity or restoration from backup. The incident owner coordinates the agreed path but cannot promise a fixed resolution time for causes outside the contracted boundary.
See the governing Service Level Agreement.