IT Ticket Priorities and SLAs: How They Should Work
September 8, 2026
A good SLA distinguishes a company-wide outage from a routine request. Here is how severity, response targets, and escalation should work in practice.

An IT service-level agreement should create shared expectations about urgency. It should not pretend every ticket has the same business impact.
A company-wide outage, suspected security incident, and single-user software question all deserve support—but not necessarily the same response path.
Severity and priority are related but not identical
Severity describes the impact of the problem. Priority describes how quickly the support team should act based on impact, urgency, and business context.
For example, a problem affecting one executive before a major client meeting may have limited technical scope but high business urgency.
Example: Critical or Priority 1
A critical incident usually has broad business impact or serious security implications.
Examples may include:
- Most or all employees unable to work
- Company-wide internet or network outage
- Critical production system unavailable
- Suspected active ransomware
- Widespread account compromise
- Major business service outage with no workaround
These incidents typically receive the fastest response and immediate escalation.
Example: High or Priority 2
A high-priority issue may significantly affect a department, important employee, location, or business process without creating a company-wide outage.
- Several employees cannot access a key application
- Important shared mailbox or file service unavailable
- Office printer or conference system failure immediately before a major event
- One critical employee has no viable workaround
Example: Normal or Priority 3
Normal support requests affect productivity but have a workaround or limited impact.
- Single-user application issue
- Peripheral or docking-station problem
- Standard software troubleshooting
- Non-urgent permissions request with approval
Example: Low or planned request
Low-priority work may include scheduled changes, questions, minor cosmetic problems, equipment requests, or tasks that do not currently prevent work.
Response time is not resolution time
This distinction matters. A 30-minute response target means the provider acknowledges or begins handling the incident within that window. It does not guarantee every technical problem will be fully resolved in 30 minutes.
Resolution may depend on diagnosis, vendor response, replacement hardware, internet providers, software defects, user availability, or other factors outside the helpdesk's direct control.
The SLA should define the support clock
Ask whether targets apply during business hours, around the clock for critical issues, or through another coverage model. A provider may offer 24/7 monitoring and critical response while normal helpdesk requests remain business-hours support.
Our guide to what 24/7 IT support actually means explains those distinctions.
Escalation should be defined
When the first technician cannot resolve an issue, there should be a path to more specialized support. Employees should not need to reopen a new ticket to reach a higher tier.
Critical incidents also need management escalation so communication continues while technicians work the problem.
Users should be able to update urgency
A ticket's impact can change. If a minor issue suddenly affects an entire department or a deadline becomes business-critical, the support team needs that context.
Avoid SLA gaming
Metrics become less useful when the goal is merely to hit a number. Automatically closing tickets, sending empty acknowledgments, or repeatedly pausing the support clock can make reports look good while employees remain blocked.
What a useful SLA should explain
- Severity or priority definitions
- Response targets for each level
- Support hours
- After-hours handling for critical incidents
- How users report urgent issues
- How escalation works
- What response time means
- How vendor-dependent issues are handled
The best SLA gives both sides a common language for urgency. Two Factor's IT Helpdesk Services use defined escalation and support expectations rather than treating every ticket as interchangeable.