Declare It
Last reviewed · content updated
IntermediateWhat you'll learn
~16 min- Distinguish an incident from a problem and size a severity ladder to the responses a team can actually mount
- Run the one incident state machine and explain why a regulatory determination is never one of its states
- Explain why a commercial severity ladder and a federal major-incident determination measure different things
Before the detail — Decision: lower the threshold for declaring, size the severity ladder to the responses the team can mount, and keep the incident’s state machine separate from any regulatory determination. Outcome: small incidents become practice reps instead of near-misses nobody named, and a federal determination never gets confused with a severity level. Artifact: a declared incident in the one state machine, with any determination recorded as its own dated entry. Status of what follows: the incident/problem split and severity ladder are common baseline; low-threshold declaration is strong optional; this shared lifecycle is emerging; M-25-04’s harm-test determination is required only where it applies to a covered agency.
Prompt first: draft the severity ladder, not the call
Here is a list of the kinds of disruptions our team has handled inthe last six months [paste short descriptions, no incident contentneeded]. For each one, tell me:
1. Would you call this an INCIDENT (an unplanned interruption) or a PROBLEM (an underlying cause with no interruption yet)?2. Given [N] severity levels I'll define separately, which level fits the response we actually mounted - not the response we wish we had mounted?
Then draft a severity ladder with exactly as many levels as we havegenuinely distinct responses (who gets paged, whether we notifycustomers, whether an executive gets called) - not more, and notfewer. Where an item does not clearly fit, say so instead of forcinga level.
Do not decide anything. This is a draft for the team that ownsdeclaring to review and correct.The agent can sort a list of past disruptions into a proposed ladder faster than a team can argue about it from scratch — but sizing a ladder to responses you can actually mount, and choosing who gets to declare, is a decision for the people who will be paged by it, not for a draft.
Incident, problem, and the case for a low threshold
ITIL — a widely used IT-service-management framework — draws a line most teams blur: an incident is the unplanned interruption itself, and a problem is the underlying cause, a separate practice with its own backlog, worked on a different clock because nobody is standing in a hallway waiting for the fix. FieldDesk’s connection-pool leak was a problem long before it caused an incident; the incident was the 27 minutes field crews spent on radio.
One widely used incident-management guide puts the declaration threshold plainly: “If you are unsure of whether response is required, trigger our incident response process.” A small incident that gets declared, run through the state machine below, and closed quickly is a practice rep the team gets for free. A small incident that never gets declared because it felt too minor to name is the rep the team doesn’t get — and the first time the same failure shows up at scale, nobody has run the motions.
Sizing severity to what you can actually do
A severity ladder is not a feelings scale: its number of levels should equal the number of distinct responses the team can mount — who gets paged, which communications occur, and who reviews reportability. If every level triggers the same response, it is one severity with several names. One widely cited paging vendor’s five-level ladder illustrates the point: its top level “warrants public notification and liaison with executive teams,” its bottom level is cosmetic, and the levels in between correspond to a different combination of who is paged and who is told. A three-level ladder where every level pages the same three people and updates the same channel is not a ladder — it is one severity with three names.
Meridian’s committed severity matrix (scripts/t8-substrate/incident/severity-matrix.yaml) has three levels: severity level 1 (SEV1) pages the commander, service on-call, and communications lead with a 15-minute executive notification; SEV2 pages service on-call only; SEV3 creates a ticket. Three levels, three genuinely different responses.
A ladder sized to real responses is the difference between a severity that tells someone what to do and one that only tells them how worried to sound.
One state machine, and what it is not
Every declared incident moves through exactly one lifecycle: detected → declared → mitigated → resolved → reviewed, with a direct detected → dismissed exit for a signal that turns out not to be an incident at all. Six states, five transitions, no synonyms — “open,” “in progress,” and “monitoring” are not states here, because a second vocabulary is how a team eventually reports in the wrong one.
That state machine belongs to the incident, not to a decision record. A regulatory determination is a dated entry with its own timestamp and decider, never a state value. AI Assurance 5.5 — a separate training in this series — tracks release decisions on a state machine of their own, approved and rejected among its values: a different machine from this one, not a second vocabulary for it.
Keeping the two machines separate is what lets a reviewer answer “was this ever declared a major incident?” without also having to ask “or do you mean resolved?”
The seam: your ladder is not their test
The commercial starting practice is a severity ladder sized to Meridian’s responses and a deliberately low declaration threshold. The federal delta is the M-25-04 harm test, issued 2025-01-15, which binds the covered agency: significant effects on national security, foreign relations, the economy, public confidence, civil liberties, or public health and safety. A breach involving 100,000 individuals forces that agency to make a determination; it is not the definition of a major incident. The handoff artifact is the dated determination entry: criteria, timestamp, agency decider, and evidence. What is not equivalent: Meridian’s SEV1 is not a federal major incident.
Meridian never makes that determination itself — it is a vendor in this contract, not the covered agency, and the harm test belongs to the agency on the receiving end of Meridian’s notification (4.2 carries the clock that notification feeds). Getting that distinction right on paper, once, is cheaper than a contracting officer re-reading Meridian’s severity history line by line after the fact.
Stop and escalate when the facts arguably meet the harm test or reach the 100,000-individual review threshold. Meridian’s clock desk records and routes the facts; the covered agency’s authorized official makes and dates the M-25-04 determination.
A SEV-1 incident is declared, paging the commander and executives within 15 minutes, and it is resolved within the hour with no data ever leaving the system. Did this incident meet a federal major-incident determination?
Practice status — among organizations that run a declared-incident process, commercial and federal
| Practice | Status | Also called |
|---|---|---|
| incident vs. problem as separate practices | common baseline | ITIL incident/problem split |
| severity ladder sized to distinct responses, not to feelings | common baseline | SEV levels / priority tiers |
| lower-the-threshold declaration norm | strong optional | early incident declaration |
| one shared state machine for the incident’s lifecycle | emerging | unified incident lifecycle taxonomy |
| federal major-incident determination as a harm test | required where M-25-04 applies; no commercial equivalent | major-incident determination |
Scale: required | common baseline | strong optional | reference-shop (seen only at organizations that publish their own practice) | emerging
Key takeaway
An incident is an interruption, declared low and often, sized to a ladder with as many levels as the team has genuinely distinct responses — and it moves through one shared state machine, detected → declared → mitigated → resolved → reviewed (or dismissed), that never holds a regulatory determination as one of its values. A federal major-incident determination is a separate harm test on criteria Meridian does not control, recorded as a dated entry, and your severity ladder does not answer it for you. Lesson 1.3 turns to the decision behind all of this: whether the organization can actually staff the response its ladder promises.
LEADERSHIP DECISION set the declaration threshold low and name who may declare, so small incidents become practice reps instead of near-misses nobody namedPRACTITIONER ACTION size the severity ladder to responses you can actually mount, run every declared incident through the one state machine, and record any federal determination as its own dated entrySUCCESS MEASURE every declared incident traceable to exactly one state at any instant, and zero regulatory determinations inferred from a severity level instead of recorded on their own - an audit finding avoided