How to distinguish a critical incident from a normal request?

The priority must combine impact and urgency. A failure that stops billing, security, support, or many users usually has a high priority; An individual consultation with an alternative available can wait. The position of the person reporting should not be the only criterion.

Risks to review

  • Respond in order of pressure and leave an interruption with greater impact unanswered.
  • Mark everything as urgent until the classification becomes useless.
  • Close cases without confirming with the user that the function was recovered.
  • Do not relate multiple reports that come from the same cause.

Safe recommendations

  1. Define levels with concrete examples of impact and response time.
  2. Register affected service, users, location, time, symptoms and available alternative.
  3. Group related incidents and maintain central communication.
  4. Tier by knowledge, permissions and risk, not just elapsed time.
  5. Confirm restoration and document cause, solution, and recurrence.
  6. Review trends monthly to convert repeated failures into preventative actions.

When to seek specialized help

  • There is no single channel and cases arrive through chats, calls and scattered messages.
  • The interruptions are repeated and no cause or solution is documented.
  • Service agreements, metrics or escalation need to be defined between providers.

Reference sources

These public sources provide general good-practice guidance. They do not replace an assessment of your environment.