How escalation works
An escalation chain is an ordered list of steps that Signalog follows when an alert goes unacknowledged. Each step specifies a delay and a target — if nobody responds within the delay, the alert escalates to the next step. This ensures that critical incidents always reach someone, even if the primary on-call person is unavailable.
Defining an escalation policy
Escalation policies are created under On-Call > Escalation Policies. Each policy has a name and a series of steps.
Step structure
Each step defines:
- delay_minutes — How long to wait before executing this step. The first step typically has a delay of
0(notify immediately). Subsequent steps add time for the previous person to respond. - target — Who to notify. Can be:
- A specific user — Always notifies this person regardless of the on-call schedule.
- The current on-call from a specific schedule — Dynamically resolves to whoever is on-call at the time of the alert.
Example escalation policy
Step 1: 0 minutes → Current on-call (Primary Schedule)
Step 2: 5 minutes → Current on-call (Secondary Schedule)
Step 3: 15 minutes → @sarah (Engineering Manager)
Step 4: 30 minutes → @ops-team (notify all members)
In this example:
- The primary on-call person is notified immediately.
- If unacknowledged after 5 minutes, the secondary on-call person is notified.
- If still unacknowledged after 15 minutes total, the engineering manager is paged directly.
- After 30 minutes, the entire ops team is notified as a last resort.
What “unacknowledged” means
An alert is considered unacknowledged until someone explicitly acknowledges it — either by clicking Acknowledge on the incident in the Signalog dashboard, or by responding to the alert notification (depending on the channel type).
The escalation chain pauses the moment someone acknowledges. If the incident is acknowledged at step 2, step 3 and beyond will not fire.
Integration with on-call schedules
Escalation policies and on-call schedules work together:
- The on-call schedule determines who is responsible at any given time.
- The escalation policy determines what happens if that person doesn’t respond.
When an escalation step targets “current on-call from Schedule X,” Signalog looks up the schedule at the time of escalation (not at the time of the original alert). This means if a shift handoff happens during an escalation, the new on-call person receives the escalated notification.
Notification channels per step
Each user in the escalation chain is notified through their configured notification channels. Users can set their preferred channels in Settings > My Profile > Notifications:
- Email — Always available.
- Slack DM — If the Slack integration is connected and a Slack user ID is mapped.
- Phone/SMS — If a phone number is configured (available on higher-tier plans).
For critical escalation steps (e.g., step 3+), consider configuring multiple channels per user to maximize the chance of getting a response.
Repeat behavior
You can configure the escalation policy to repeat after all steps have been exhausted. When enabled, the chain starts over from step 1. Set a maximum number of repeats to prevent infinite loops — typically 2 or 3 repeats is sufficient.
Next steps
- Set up on-call schedules to define who is on-call
- Configure alert channels for your team
- Understand the incident lifecycle to see escalation in context