Choose decision dimensions
Use signals your responders can observe and explain during an incident.
Customer impact
Define affected journeys, user segments, error rates, support volume, or revenue exposure that matter to your organization.
Scope and criticality
Account for affected services, regions, tenants, service tiers, and whether a safe workaround exists.
Data and compliance risk
Define the conditions that require immediate security, privacy, legal, or regulatory escalation outside the normal scale.
Configure response expectations
Tie each level to action, ownership, and communication rather than a color alone.
Roles and escalation
Specify when an incident lead, executive contact, security owner, customer support lead, or external partner must join.
Update cadence
Set a maximum time between stakeholder updates and define who can change that cadence as evidence changes.
Review requirement
Define when a postmortem is required, who reviews it, and the expected deadline for follow-up ownership.
Keep the decision traceable
Severity can change as impact becomes clearer; preserve why it changed.
Record the evidence
Attach the metrics, reports, and customer-impact facts that supported the current level.
Allow operator override
Let responders raise or lower severity with a written reason when configured thresholds do not represent the actual risk.
Review thresholds
After incidents, compare the assigned level with the response burden and observed impact, then configure the matrix when it produces misleading decisions.