Every Page Is a Claim
Last reviewed · content updated
IntermediateWhat you'll learn
~15 min- Classify every alert rule as page, sub-critical, or delete, using whether a human can act on the symptom it names
- Treat the fatigue ceiling as a capacity number that feeds the coverage decision, not a mood to manage around
- Run the acknowledgment chain - sent, acknowledged, escalated, owned - as a designed, auto-escalating handoff
Before the detail — Decision: classify every alert rule as a page, a sub-critical notice, or a deletion, using whether a human can act on the symptom it names. Outcome: on-call carries pages that demand action now and nothing else, and the fatigue a page costs becomes a number the next lesson’s coverage decision can plan around. Artifact: the reclassified alert inventory — one row per rule, one disposition, one reason. Status of what follows: reusable guidance.
Prompt first: run the hygiene review, not a vibe check
Here is our alert inventory - one row per rule, with trigger,last-fired timestamp, firing history, recorded responder action,and owner [paste].
Assign PAGE, SUB-CRITICAL, or DELETE using the stated actionabilitytest. Flag any rule whose last-fired timestamp, owner, action, orobserved-receipt evidence is missing. Do not invent missing facts.The mechanical pass prevents a memory-driven debate.
A page is a claim on someone’s night
FieldDesk serves 300 field technicians, and a page about it is a claim that a specific person must act on a specific problem now. Repeated empty pages train indifference to the next real one.
Data Products 6.1 (a separate training in this series) settles the routing question — page on blocking failures, digest the rest. This lesson begins after that routing decision and owns actionability, fatigue, and acknowledgment mechanics.
A hygiene review that finds even one rule nobody can defend is the assessor’s finding you found first, and it is cheaper every time it runs on a calendar instead of after a bad week.
Alert on the symptom, not the story underneath it
Rob Ewaschuk’s alerting philosophy, still the clearest statement of the actionability test, opens with the rule the hygiene review enforces: “Every page should be actionable; simply noting ‘this paged again’ is not an action.” His second rule names where to point the rule: “alert on the symptom” — the 500, the error a field crew actually sees — not on a cause several layers underneath it that merely correlates with trouble. A connection-pool gauge climbing is a cause; a work-order screen timing out in a truck is a symptom. Page on the second one, because it is the one a human can confirm without first learning the system’s internals, and because a symptom-based page stays true even when the cause changes next quarter.
Ewaschuk’s term is sub-critical alert, not ticket or low priority. Zero Trust 5.1 holds any detection to the same standard — a rule nobody has watched fire is unverified — which is what keeps the sub-critical tier from becoming the place rules go to be ignored.
The fatigue ceiling is a capacity number
Ewaschuk states the fatigue limit plainly: “I can only do this a few times a day before I get fatigued.” This is a qualitative capacity input, not a page-count rule. Lesson 1.3 applies the separately verified incident cap; this lesson only removes pages that fail the actionability test. Removing non-actionable pages recovers capacity the rota would otherwise have to staff.
Sent, acknowledged, escalated, owned
An alert that clears the actionability test still has to reach a person, and the chain it travels has four states worth naming because each one can silently fail: sent (the rule fired and something dialed a number or opened a channel), acknowledged (a specific human confirmed receipt), escalated (nobody acknowledged in time, so it moved to the next name on the list), owned (someone has said, out loud, that fixing this is theirs right now). A page that is merely sent and never acknowledged has not reached anyone — it has reached a log line.
One incident-management vendor’s guidance (2026-07-21) calls automatic escalation non-negotiable; house practice adopts it: acknowledgment has a deadline and responders cannot disable escalation during a shift.
For every PAGE, the inventory records the acknowledgment deadline and next escalation target; that documented chain prevents a silent handoff.
Stop and escalate when the hygiene review turns up a rule with no owner, no runbook, and a fire history nobody can explain — that rule does not get a disposition from this exercise at all. It goes to the engineering manager for the service it names, because deleting a rule nobody understands can hide a real signal, and paging on it forever wastes a human on a mystery. Who takes that rule on as a named owner is a staffing question for 1.3’s coverage decision, not a checkbox in this review.
A rule has repeatedly paged on-call, and every recorded response says it self-resolved before a human action. What disposition does the actionability test give it?
Key takeaway
A page is a claim that a specific human must act on a specific symptom right now, and the hygiene review that sorts an existing library into PAGE, SUB-CRITICAL, and DELETE is how an alert set earns the fatigue it spends. The acknowledgment chain — sent, acknowledged, escalated, owned — turns a claim into a person’s responsibility with a deadline, not a hope. Lesson 2.2 takes the PAGE rules this review keeps and gives them the sharpest actionability test available: a burn rate against an objective, proven with a unit test instead of a promise.
LEADERSHIP DECISION fund a recurring hygiene review of the alert library, not a one-time cleanup - the fatigue ceiling it protects is what 1.3's coverage plan is staffed againstPRACTITIONER ACTION sort every existing rule into PAGE / SUB-CRITICAL / DELETE against the actionability test, name an owner for every rule that survives, and wire non-negotiable auto-escalation behind every PAGESUCCESS MEASURE zero page-channel rules that a reviewer cannot match to a specific human action in the documented review period - an audit finding avoided