Decision Thresholds & Escalation
A decision threshold defines when evidence is sufficient for a specific action. An escalation threshold defines when the exposure, uncertainty, conflict or required authority exceeds the current decision boundary.
A threshold is a predeclared transition rule.
It converts an observed state into a permitted action, authority change or review requirement. It is not merely a target, preference or severity label.
A decision threshold is the minimum evidence or state condition required to authorize a named action. An escalation threshold is the condition that transfers, expands or coordinates decision authority because consequence, scope, conflict, uncertainty or commitment exceeds the current mandate.
Different transitions require different signals.
Using one universal score creates hidden trade-offs and makes authority boundaries ambiguous.
Action threshold
Minimum support required to initiate a named intervention.
Escalation threshold
Point at which current authority or coordination becomes insufficient.
Stop threshold
Condition that terminates an action because harm, futility or limits are reached.
Reopen threshold
New evidence or state change requiring the decision to be reconsidered.
Commitment threshold
Gate before an additional tranche of dependency, capital or irreversibility.
Crisis threshold
Transition to exceptional governance when normal controls cannot contain exposure.
A number without operating semantics is not a threshold.
Every field below must be explicit enough that two authorized operators reach the same transition from the same evidence.
| Field | Required question | Valid example | Invalid example | Failure prevented |
|---|---|---|---|---|
| Signal | What exactly is observed? | Confirmed affected identities. | Risk is high. | Interpretation drift. |
| Unit & direction | How does crossing occur? | ≥ 3 identities within 30 min. | Several incidents. | Ambiguous activation. |
| Evidence rule | What qualifies as support? | Two independent telemetry sources. | Team concern. | Evidence substitution. |
| Window | Over what period? | Rolling 30-minute window. | Recently. | Stale aggregation. |
| Authority | Who owns the transition? | Incident commander role. | Management. | Decision vacuum. |
| Permitted action | What becomes authorized? | Isolate named segment for 60 min. | Take necessary steps. | Unbounded response. |
| Reset/reopen rule | How does state leave the threshold? | Zero new identities for 2 hours + review. | When safe. | Permanent emergency state. |
Escalate for a reason—not from anxiety or hierarchy.
Select the observed condition. Every response is stored directly in HTML and works without JavaScript.
Observed state
Evidence passes the playbook threshold; exposure and action remain inside delegated authority.
Act within the declared boundary.
Use the authorized response, record evidence and monitor the next escalation trigger. Do not escalate merely to transfer accountability.
Observed state
The decision now affects multiple systems, teams, contracts or stakeholder groups.
Expand coordination before action expands.
Bring affected owners into one decision record. Preserve a single incident state, define coordination authority and prevent parallel contradictory actions.
Observed state
The current owner has a material conflict, bears only part of the loss or benefits from one outcome.
Transfer the decision, not just the briefing.
Disclose the conflict and move final authority to an independent role with access to the same evidence, affected-party information and correction mechanisms.
Observed state
The normal decision process cannot finish before the cost of delay crosses its acceptable bound.
Authorize bounded temporary action.
Use the narrowest reversible response that prevents threshold breach. Preserve evidence, set automatic expiry and require retrospective review.
Observed state
Exposure is systemic, potentially irreversible, externally material or beyond ordinary recovery capacity.
Activate exceptional coordination.
Establish one accountable command structure, protect essential functions, coordinate required external parties and set explicit criteria for returning to ordinary governance.
Escalation is a controlled state transition.
Every handoff must carry the decision question, current state, evidence, urgency, requested authority and next trigger.
Signal crosses
Named condition exceeds its boundary.
OBSERVEConfirm semantics
Unit, source, window and quality pass.
VERIFYName the reason
Scope, authority, time, conflict or exposure.
ROUTETransfer state
Evidence, unknowns and requested decision.
CONTEXTAuthority confirms
Owner, clock and permitted action declared.
OWNResponse executes
Scope remains inside authorization.
CONTROLReturn or reopen
State exits escalation by explicit rule.
CLOSEEvidence sufficiency and authority sufficiency are different questions.
Strong evidence does not grant legal or organizational authority. High authority does not repair weak evidence.
| Evidence state | Exposure state | Authority state | Permitted posture | Escalation |
|---|---|---|---|---|
| Strong | Bounded | Sufficient | Execute declared action. | No; monitor next trigger. |
| Strong | High/systemic | Insufficient | Contain only if preauthorized. | Escalate authority immediately. |
| Weak | Bounded | Sufficient | Probe, monitor or wait. | Escalate only if uncertainty cannot be reduced locally. |
| Weak | High + urgent | Insufficient | Narrow reversible protection. | Emergency authority + rapid review. |
| Conflicting | Material | Conflicted | Preserve state; no final action. | Independent decision authority. |
| Stale | Changed | Any | Reopen; invalidate prior threshold. | Route by new exposure state. |
Thresholds must survive contact with time and changing context.
A registry makes each transition inspectable, testable and maintainable.
| Trigger ID | Condition | Transition | Owner | Expiry/review |
|---|---|---|---|---|
| TRG-ACT-01 | Evidence reliability ≥ declared minimum and expected loss favors action. | Observe → Act | Decision owner | On source or prevalence change. |
| TRG-ESC-02 | Impact crosses two organizational units. | L1 → L2 | Cross-functional lead | When shared scope ends. |
| TRG-TIME-03 | Remaining decision window < normal review duration. | L1/L2 → L3 | Emergency authority | Automatic expiry after window. |
| TRG-STOP-04 | Collateral harm exceeds declared bound. | Act → Stop | Control owner | Before any restart. |
| TRG-REOPEN-05 | Key assumption invalidated or state changes class. | Closed → Review | Original owner | New decision record required. |
| TRG-RESET-06 | Exposure below threshold for defined stabilization period. | Escalated → Normal | Escalation authority | Closure audit. |
Five domains. Five different reasons to escalate.
Select a case to inspect its threshold, escalation reason, authorized response and reset rule.
Escalate when the attack path exceeds local containment authority.
A single suspicious endpoint may remain local. Confirmed identity compromise across critical services changes both scope and authority.
Escalate when a local page decision changes cluster ownership.
A weak page can be edited locally. A proposed merge that changes canonical ownership, internal routing and several dependent nodes requires architectural authority.
Escalate when service failure becomes concentration exposure.
A routine SLA miss belongs to vendor management. Repeated failure on a single-source critical dependency becomes an executive continuity decision.
Scale is a new decision, not a reward for a positive signal.
A pilot owner may optimize the test, but cannot authorize structural market commitment without economics, capacity and downside evidence.
Escalate based on consequence, not model confidence alone.
A low-impact draft can remain delegated. An output affecting rights, safety, payment or public claims requires evidence and authority outside the model pipeline.
Do not escalate a problem without a decision request.
The receiving authority needs a compact state transfer, not a raw data dump.
| Package field | Content | Why required | Failure if absent |
|---|---|---|---|
| Decision request | Exact approval, choice or authority required. | Defines what the receiver must decide. | Escalation becomes information forwarding. |
| Current state | Observed condition, scope, time and trend. | Anchors the decision in now. | Old severity label substitutes for state. |
| Threshold crossed | Trigger ID and supporting measurement. | Explains why escalation occurred. | Hierarchy replaces rules. |
| Evidence & unknowns | Support, contradictions and missing facts. | Prevents false certainty. | Authority receives advocacy, not evidence. |
| Options | Feasible actions, including containment and wait. | Prevents one-option escalation. | Approval becomes ceremonial. |
| Clock | Decision deadline and delay consequence. | Sets review priority. | Urgency is asserted but not bounded. |
| Next trigger | Escalate, stop, reset or reopen condition. | Controls the next transition. | Emergency state persists indefinitely. |
Bad escalation either arrives too late or never ends.
These patterns destroy threshold discipline.
Severity without semantics
A color or score has no measurable transition rule.
Authority ambiguity
Multiple roles can advise, but nobody owns the final decision.
Escalation as avoidance
A local owner transfers accountability despite sufficient mandate.
Data dump
The receiver gets evidence but no decision question or clock.
Emergency permanence
Exceptional authority has no expiry or return condition.
Threshold gaming
Definitions or windows shift to avoid or force escalation.
Make thresholds and authority transitions machine-readable.
RAG systems should retrieve the transition rule together with evidence, authority, expiry and reset—not a detached severity score.
Store the transition, not just the trigger.
This record makes activation and deactivation inspectable.
{
"trigger_id": "TRG-ESC-ID-03",
"signal": "confirmed_affected_identities",
"operator": ">=",
"value": 3,
"window_minutes": 30,
"evidence_rule": "two_independent_sources",
"transition": "L1_to_L2",
"authority": "cross_functional_commander",
"permitted_action": "segment_identity_services",
"reset_rule": "zero_new_cases_120m_plus_review"
}Decision thresholds and escalation, clarified.
Operational answers to the most common governance errors.
What is a decision threshold?
It is a predeclared condition specifying when available evidence or an observed state is sufficient to authorize a named action.
What is an escalation threshold?
It is the condition that transfers, expands or coordinates authority because consequence, scope, conflict, uncertainty or commitment exceeds the current mandate.
Is a severity score a threshold?
Not by itself. A threshold requires measurable semantics, direction, time window, evidence rule, authority, permitted action and reset or reopen condition.
Does escalation always mean stronger action?
No. It can mean broader coordination, independent review, legal assessment, added resources or transfer of authority while the operational action remains unchanged.
When should a decision be reopened?
Reopen when a key assumption is invalidated, evidence changes materially, the context crosses a declared boundary or monitoring shows the selected action is no longer adequate.
How do you prevent escalation overload?
Delegate bounded authority, define unambiguous triggers, suppress duplicate escalations, provide a decision request and reset escalated states when the exit condition is met.
What should an escalation package contain?
The exact decision request, current state, crossed trigger, evidence and unknowns, feasible options, time boundary, affected parties and next transition rule.
Who should own a threshold?
A named role must own its definition, measurement source, review cadence and change control. A separate authorized role may own activation when independence is required.
Continue through the complete Decision Intelligence system.
Thresholds activate decisions. Monitoring determines whether their assumptions remain true and whether the system should continue, stop or reopen.
Decision Intelligence
Structure choices through objectives, alternatives, evidence, uncertainty, trade-offs, commitment and review.
A threshold must change state, authority or action.
Define the signal before observing it. Bind it to evidence and time. Name the authority. Limit the response. Preserve the decision package. Declare how escalation ends and when the decision must reopen.