Skip to main content

Incident Toolkit

Toolkit
Workflow
INCIDENT SERVICE LEVEL AGREEMENTS
CUSTOMER PRIORITIZATION GUIDE
Incident States
Documentation Guidelines

Incident Service Level Agreements

Major Incidents affect critical services or large groups of users and require urgent, coordinated response.

Customer Incidents impact a single user or small group and are handled through normal support channels.

PriorityResponseResolutionSchedule
P1 - Critical15 min4 HoursMajor INC: 24x7
Customer INC: 8 am - 5 pm Weekdays (Excluding Holidays)
P2 - High1 Hour9 HoursMajor INC: 24x7
Customer INC: 8 am - 5 pm Weekdays (Excluding Holidays)
P3 - Moderate4 Hours18 HoursBoth: 8 am-5 pm Weekdays
Excluding Holidays
P4 - Low9 Hours45 HoursBoth: 8 am-5 pm Weekdays
Excluding Holidays
Image of SLA response and resolution times

Incident Priority Matrix

Incident States Explained

Incident states track where an issue is in its lifecycle and define what’s expected at each stage. Using the correct state — and updating it consistently — ensures accurate reporting, timely handoffs, and clear communication with customers and teams.

StateWhat It MeansWhat Should Happen Here
NewIncident has been reported but not yet triaged.Review initial details, confirm incident validity, and assign for investigation.
AssignedThe incident has been routed to the correct team or individual.Acknowledge assignment, review context, and begin initial investigation.
Work in ProgressInvestigation and resolution work is actively underway.Document troubleshooting steps, engage additional teams if needed, and communicate status updates.
On HoldProgress is paused due to an external dependency (e.g., waiting on user, vendor, or scheduled task).Add clear notes explaining the reason for the hold and next steps. Update when the block is resolved.
ClosedWork has been completed but verification or follow-up is pending.Validate that service is restored and all steps are documented.
Closed CompleteIncident is fully resolved, verified, and documented.Ensure final resolution notes are added and customer communication is complete.

Clear, consistent documentation ensures that incidents can be understood, escalated, and analyzed by anyone — now or in the future. It also improves communication with users, helps identify recurring issues, and supports accurate reporting.

Documentation AreaWhat to IncludeWhy It MattersExample
Work NotesStep-by-step troubleshooting actions, findings, and technical analysis.Ensures continuity if the ticket is reassigned and supports RCA later.“Checked DNS records → Found misconfigured A record → Updated and flushed cache.”
Customer UpdatesPlain-language status, progress, any needed user actions, and next steps.Keeps customers informed and reduces repeated inquiries.“We’re currently investigating the login issue. Next update in 1 hour.”
Closure NotesFinal resolution, cause, validation steps, and any follow-up recommendations.Provides a complete record for reporting and future reference.“Authentication error caused by expired SSO token. Renewed and confirmed functionality.”