Operator resource

Incident Severity Matrix Template

Adapt this worksheet to your services, risk appetite, and escalation policy. Severity should make response expectations explicit; it should not replace operator judgment or hide the evidence behind a decision.

Updated August 2, 2026

Choose decision dimensions

Use signals your responders can observe and explain during an incident.

Customer impact

Define affected journeys, user segments, error rates, support volume, or revenue exposure that matter to your organization.

Scope and criticality

Account for affected services, regions, tenants, service tiers, and whether a safe workaround exists.

Data and compliance risk

Define the conditions that require immediate security, privacy, legal, or regulatory escalation outside the normal scale.

Configure response expectations

Tie each level to action, ownership, and communication rather than a color alone.

Roles and escalation

Specify when an incident lead, executive contact, security owner, customer support lead, or external partner must join.

Update cadence

Set a maximum time between stakeholder updates and define who can change that cadence as evidence changes.

Review requirement

Define when a postmortem is required, who reviews it, and the expected deadline for follow-up ownership.

Keep the decision traceable

Severity can change as impact becomes clearer; preserve why it changed.

Record the evidence

Attach the metrics, reports, and customer-impact facts that supported the current level.

Allow operator override

Let responders raise or lower severity with a written reason when configured thresholds do not represent the actual risk.

Review thresholds

After incidents, compare the assigned level with the response burden and observed impact, then configure the matrix when it produces misleading decisions.