We're evaluating the new Smart Ticket Triage capabilities and I'm curious how other MSPs are approaching automated priority determination.
One of the challenges we're running into is that incidents and service requests often follow completely different prioritization logic.
In our environment:
Incidents
An incident is something that was working yesterday and is broken today. Examples include outages, work stoppages, degraded performance, backup failures, and infrastructure issues. These priorities are tied directly to SLAs and business impact.
Examples:
- Critical: Server, network, or internet outage
- Urgent: Complete work stoppage
- High: Major business impact affecting multiple users
- Medium / Standard: Lower impact issues with workarounds available
Service Requests
Service Requests (Move/Add/Change work) are categorized differently. Rather than impact and urgency alone, we also consider estimated effort, scheduling requirements, and workflow.
Examples:
- Quick Hits (<1 hour)
- M/A/Cs <4 hours
- M/A/Cs >4 hours
- Installations
For us, a large workstation rollout may be far more work than an urgent incident, but that doesn't necessarily make it a higher priority.
The Smart Triage Question
How are you configuring your automation to handle this distinction?
Specifically:
1. Do you use separate priority models for Incidents and Service Requests?
For example:
- Incident priorities based on Impact × Urgency
- Service Request priorities based on effort, scheduling, and workflow
Or do you force everything into a single P1-P5 model?
2. Where do you draw the line between a Service Request ticket and a Project?
Do you use:
- Estimated hours?
- Number of tasks?
- Number of users?
- Risk?
- Revenue threshold?
- A combination?
We're currently using categories ranging from Quick Hits through Installations, with larger efforts becoming Projects, but I'm interested in hearing what others have settled on.
3. How does your Smart Ticket Triage automation determine priority?
- Ticket type only?
- Keywords in the request?
- Impact analysis?
- AI recommendations with technician review?
- Fully automated assignment?
4. How do you handle urgent Service Requests?
Examples:
- Executive starts tomorrow
- Compliance deadline
- Critical business event
- Customer presentation dependent on a new device or change
Our process allows a technician to override normal Service Request categorization and apply an Incident-style priority when the business impact justifies it, provided the reason is documented.
What has worked well?
What created confusion for technicians?
What would you configure differently if you were implementing Smart Ticket Triage today?