How to distinguish a critical incident from a normal request?
The priority must combine impact and urgency. A failure that stops billing, security, support, or many users usually has a high priority; An individual consultation with an alternative available can wait. The position of the person reporting should not be the only criterion.
Risks to review
- Respond in order of pressure and leave an interruption with greater impact unanswered.
- Mark everything as urgent until the classification becomes useless.
- Close cases without confirming with the user that the function was recovered.
- Do not relate multiple reports that come from the same cause.
Safe recommendations
- Define levels with concrete examples of impact and response time.
- Register affected service, users, location, time, symptoms and available alternative.
- Group related incidents and maintain central communication.
- Tier by knowledge, permissions and risk, not just elapsed time.
- Confirm restoration and document cause, solution, and recurrence.
- Review trends monthly to convert repeated failures into preventative actions.
When to seek specialized help
- There is no single channel and cases arrive through chats, calls and scattered messages.
- The interruptions are repeated and no cause or solution is documented.
- Service agreements, metrics or escalation need to be defined between providers.
Reference sources
These public sources provide general good-practice guidance. They do not replace an assessment of your environment.

