- Minor: low impact, usually handled within working hours, and most customers are unlikely to notice.
- Major: significant impact that usually needs an immediate response, sometimes with a workaround in place.
- Critical: very high impact, like a full outage or a data breach, where immediate response is required.
Managing severities
You can manage severities in Settings → Severities. Managing severities requires the Manage organization settings permission. Each severity has:- Name: what the severity is called, for example Major. Keep it short, since it appears anywhere an incident’s severity is shown.
- Description: an explanation of when this severity applies. This is the most useful field to get right, because it’s what helps a reporter pick the correct severity under pressure. A good description answers questions like: what’s the likely impact on the business, what customer communications are needed, and who might need to be involved.
Using severities
Once set up, severities show up throughout the incident lifecycle:- When declaring: reporters pick a severity as they open an incident, setting expectations from the very first moment.
- As things develop: severity isn’t fixed. Raise or lower it as you learn more, and everyone stays in sync with how serious the incident currently is.
- To drive automation: use severity as a condition in workflows, for example escalating to a wider group or notifying leadership only when an incident is Critical.
- For reporting: filter and group incidents by severity in Insights to understand trends, like whether major incidents are becoming more frequent.