Incident Management Platform  ·  View 25 of 34  ·  5 · Runtime

Escalation Exhausted — The Worst Outcome Is Loud

Nobody acknowledged through three steps. The policy's final step is a broadcast, and reaching it opens an incident against the platform.

Editable source SVG draw.io All views
Escalation timers Dispatcher Primary Secondary Management layer Owning team Platform rotation 1. step 1 · 5 min 2. push · SMS · voice 3. no ack · step 2 4. push · SMS · voice 5. primary keeps ringing 6. no ack · final step 7. voice · every channel 8. broadcast to whole team 9. state: exhausted 10. platform SEV2 · route B 11. repeat broadcast every 5 min Escalation Exhausted — The Worst Outcome Is Loud Exhausted is a state, not an ending. It stays open, keeps broadcasting, and opens an incident against the platform, because either the policy or the rota is wrong. v 1.0 · owner Reliability Architecture · date 2026-09

Decisions

  • Every escalation policy must end in a defined final step, and the policy editor refuses to save one that does not. The final step is a management layer plus a broadcast to the whole owning team (ADR-23).
  • Earlier targets keep being notified when later steps begin. Escalation adds people; it does not stop calling the primary, who may simply have been in a lift.
  • Exhausted is a state that stays open. The broadcast repeats every 5 minutes until someone acknowledges, and a SEV2 is opened against the platform itself, sent on carrier B to the platform rotation.

Why a platform incident

  • Exhaustion means the rota, the contact data or the policy is wrong, and all three are the platform's configuration. Treating it as someone else's missed page is how the same exhaustion happens next month.

Target

  • Zero silent exhaustions. Every exhaustion reviewed, with the contributing factor recorded against the rotation.