SLA Breach Alert Response
T-30 alerts triaged. Tickets reassigned or escalated to prevent breach. Breach logs captured for weekly pattern review. Leadership reports surface concentration patterns.
Before you start
- SLA targets documented per priority and customer tier
- Help desk SLA tracking enabled with breach alerts
- Escalation path for breaches
- Active ticket near or in SLA breach
- Customer context (plan, contract terms)
- Current ticket status and assignee
The steps
- Detect impending breach (T-30 minutes) — Help desk alert fires 30 minutes before SLA breach. Pull the ticket: priority, customer tier, current assignee, last activity. Quick check: is the assignee online? On vacation? Has the customer responded recently and we missed it?
- Triage who can act in the next 30 minutes — If the assignee is online and active, ping them in Slack with 'SLA breach in 30 — can you take this?' If they're not available, identify a backup with the right skill set. Don't wait until breach to act — at T-30, the goal is prevention.
- Reassign or escalate as needed — Reassign the ticket to whoever can act. If no one's available, escalate to the team lead — they decide whether to pick up directly or pull from another team. SLA breaches that leadership doesn't know about are worse than breaches they handle.
- Send a customer-facing update if breach occurs — If breach is unavoidable, send a proactive update to the customer: acknowledge the delay, explain what you're doing, give a new ETA. Silence after a breach is the failure that loses customers. The proactive update softens it.
- Log breach and root cause — After resolution, log: ticket, breach amount (minutes/hours over), root cause (volume, agent absence, complex ticket, etc.). Aggregate weekly: are breaches trending up? In a particular team? At a particular hour?
- Surface patterns to leadership — Weekly breach report to support leadership: count, root causes, customer impact. If breaches are concentrated in one shift or queue, that's a staffing issue. If they're distributed, may be a volume issue. Patterns drive the fix.
If it goes wrong
Alerts fire but no one is monitoring the channel
Alert routing must include a paging escalation if no one acks within 5 minutes. Silent alerts are worse than no alerts.
Tickets reassigned multiple times without resolution
Cap reassignments at 2. Beyond that, escalate to a manager who picks up directly. Reassignment is not a substitute for ownership.
Breaches logged but not analyzed
Weekly breach review meeting — non-negotiable. If logs aren't analyzed, breaches don't get fixed.
All OpenLabor playbooks