Evidence Standard
Each ticket write-up follows a consistent support workflow so that the
investigation is understandable, repeatable and linked to a clear
business outcome.
- User report and business impact.
- Initial classification and priority.
- Checks completed and evidence gathered.
- Root cause or most likely cause.
- First-line fix or justified escalation decision.
- User-side and administrative validation.
- Work notes, communication and resolution outcome.
Impact and Urgency Model
The ticket scenarios use an ITIL-aligned model based on common IT
service-management practice. Impact measures how widely the issue
affects the organisation. Urgency measures how quickly action is
required. Priority is determined from their combination using the documented
service-management model.
Impact definitions
Impact definitions
|
|
| Impact |
Working definition |
| 1 - High |
Whole organisation, major service, multiple departments,
executive user, serious security risk or a business-critical
service unavailable.
|
| 2 - Medium |
A team, department, multiple users or an important business
function is affected.
|
| 3 - Low |
A single user, minor issue, available workaround, routine request
or limited business impact.
|
Urgency definitions
Urgency definitions
|
|
| Urgency |
Working definition |
| 1 - High |
Work stopped, no workaround, active security risk, same-day
deadline or a business-critical function is blocked.
|
| 2 - Medium |
Work is degraded, a workaround exists, same-day attention is
useful or the user can partly continue.
|
| 3 - Low |
Planned request, information request, minor inconvenience or work
that can safely wait.
|
Priority Matrix
Priority Matrix
|
|
| Impact |
Urgency |
Priority |
Example use |
| 1 - High |
1 - High |
1 - Critical |
Major outage or confirmed serious security incident. |
| 1 - High |
2 - Medium |
2 - High |
Major service degraded with a partial workaround. |
| 1 - High |
3 - Low |
3 - Moderate |
Large-scope issue without an immediate deadline. |
| 2 - Medium |
1 - High |
2 - High |
A department or multiple users are blocked. |
| 2 - Medium |
2 - Medium |
3 - Moderate |
A team issue where work is degraded but continuing. |
| 2 - Medium |
3 - Low |
4 - Low |
A low-urgency departmental request. |
| 3 - Low |
1 - High |
3 - Moderate |
A single user is fully blocked, such as a locked account. |
| 3 - Low |
2 - Medium |
4 - Low |
A single-user issue with an available workaround. |
| 3 - Low |
3 - Low |
4 - Low |
A routine planned request or minor issue. |
First-Line Priority Guidance
First-Line Priority Guidance
|
|
| Priority |
Use in the ticket investigations |
| 1 - Critical |
Used only for major outages, severe organisation-wide impact or a
confirmed serious security incident. First line records and
escalates immediately, applying a direct fix only when it is safe
and within scope.
|
| 2 - High |
Used for department-level or multi-user disruption, urgent
business-function issues or high-risk security events. First line
investigates promptly and escalates when required.
|
| 3 - Moderate |
Used for a blocked individual user or medium-impact issue. First
line normally owns the investigation and escalates only where the
fix requires additional privilege or specialist knowledge.
|
| 4 - Low |
Used for routine requests, minor faults, issues with workarounds
and planned user or device administration.
|
Resolver and Escalation Model
Fictional resolver identities are used to demonstrate first-line
ownership, secondary support and controlled escalation boundaries.
Resolver and Escalation Model
|
|
| Resolver |
Role |
Purpose |
| Chloe Bennett |
Service Desk Analyst |
Main first-line resolver for routine support tickets. |
| Daniel Smith |
IT Support Technician |
Secondary first-line resolver for queue work. |
| Kristian Nietzold |
IT Administrator |
Escalation resolver for privileged, higher-risk or
administrator-only changes.
|
Summary
- Impact and urgency are assessed separately.
- Priority reflects the combined business effect and required response.
- First line retains ownership while escalating only the privileged task.
- Every resolution requires technical or user-side validation.
- Work notes document actions, decisions and hand-offs clearly.
Back to Service Desk