Escalation alerts notify additional people when an alert still needs attention. When an alert isn't acknowledged, isn't resolved, or the condition is still active after a configured wait time, Device Health can trigger a new alert for a different Group — such as facilities, biomed, or an on-call team — who weren't part of the original alert notifications.
Use escalation alerts when additional people should be notified if the alert remains unacknowledged, unresolved, or active after a set amount of time. For example, if a Portal Light Offline alert isn't acknowledged within 30 minutes, Device Health can trigger an escalation alert for a facilities manager or on-call team.
How escalation alerts differ from reminders
Reminders and escalation alerts both help when an alert still needs attention, but they work differently. Reminders notify the same people again. Escalation alerts notify additional people through a different Group.
| Reminders | Escalation alerts | |
|---|---|---|
| What they do | Send more notifications for the original alert | Trigger a new alert for a different Group |
| Who receives them | The same recipients configured on the original Alert Rule | The Group assigned to the Escalation Alert Rule |
| Purpose | Keep the original recipients aware until the alert is acknowledged or resolved | Notify additional people when the alert still needs attention |
| How configured | In the Actions step of an Alert Rule | As a separate Escalation Alert Rule assigned to the original rule |
How escalation works
Escalation has two parts: an Escalation Alert Rule and an escalation assignment on the original Alert Rule.
Escalation Alert Rule
An Escalation Alert Rule is a separate Alert Rule. It defines:
- The Group that can acknowledge or resolve the escalation alert.
- How that Group is notified.
- Any reminders or additional escalations for the escalation alert.
You can assign one Escalation Alert Rule to multiple Alert Rules. This lets you reuse the same escalation behavior across similar alerts without setting it up each time.
Escalation assignment
You assign an Escalation Alert Rule to a regular Alert Rule — for example, a Portal Light Offline or Battery Level rule. Each assignment defines:
- When (trigger condition): what must still be true when the wait time ends.
- After (wait time): how long Device Health waits before checking whether to escalate.
- Then (Escalation Alert Rule): which Escalation Alert Rule is used (it defines the Group and how they're notified).
If the trigger condition is met when the wait time ends, Device Health triggers an escalation alert.
Trigger conditions
When the wait time ends, Device Health checks whether the escalation should trigger. Each escalation assignment uses one trigger condition.
| Trigger condition | Escalation triggers if… |
|---|---|
| Not Acknowledged | The original alert hasn't been acknowledged. |
| Not Resolved | The original alert hasn't been resolved. |
| Condition Active | The condition that triggered it is still occurring — for example, the Portal Light is still offline. |
Not Acknowledged is common when a fast initial response is required. For example, you might escalate a Portal Light Offline alert if no one acknowledges it within 30 minutes.
To escalate for more than one condition, add more than one escalation assignment to the Alert Rule.
Escalation levels
An escalation alert is a full alert, so it can have its own reminders and its own escalation. This lets you create multiple escalation levels.
Example:
- A Portal Light Offline alert triggers.
- Notifications are sent to the original recipients.
- Reminders are sent at the configured intervals.
- After 30 minutes, the alert still isn't acknowledged, so a level-1 escalation alert triggers for the facilities Group.
- The level-1 escalation alert sends its own notifications and reminders.
- After 60 minutes, the level-1 escalation alert still isn't resolved, so a level-2 escalation alert triggers.
Device Health links related alerts in the Escalation Chain. You can open the Escalation Chain from an alert's detail view to see each linked alert, its status, and its notification history.
Who can act on an escalation alert
Users with access to alerts can view escalation alerts. The Group assigned to the Escalation Alert Rule controls who can acknowledge or resolve the escalation alert.
- Escalation alert: only members of the assigned Group can acknowledge or resolve it.
- Original alert: the original alert follows its normal alert permissions.
The original alert and the escalation alert are resolved separately. Resolving the escalation alert doesn't resolve the original alert.
From the Escalation Chain view, a user can act on linked alerts when they have permission for each alert. For example, a facilities manager may be able to resolve both the original alert and the escalation alert in one action.
Groups are managed in the Kio Cloud Users app, not in Device Health. A Group can be either a Managed Group created in Kio Cloud, or an SSO Group synced from your organization's identity provider. Either type can be assigned to an Escalation Alert Rule.
When a pending escalation is canceled
Device Health cancels a pending escalation when:
- The original alert is resolved: all pending escalations for that alert are canceled.
- The original alert is acknowledged: pending escalations with the trigger condition Not Acknowledged are canceled. Escalations with Not Resolved or Condition Active are not canceled.
- The condition returns to normal: pending escalations with the trigger condition Condition Active are canceled — for example, the Portal Light comes back online.
- The Escalation Alert Rule is disabled or deleted.
If the wait time ends and none of these apply, the escalation alert triggers.
Compliance context
Escalation alerts create a traceable record when an alert needs additional response. Each escalation alert has its own acknowledgment, resolution, notification history, and activity record. The full escalation history is available from the alert detail view, so teams can review who was notified, when the alert escalated, and how each linked alert was handled.