Step 1 — Pull the open queue

Read every open, unresolved ticket in Plain. This is a fresh session every run, so pull the full current state of the queue — don't rely on which tickets escalated last sweep, since a ticket's SLA clock, account, and severity can all change between checks.

Step 2 — Check each ticket against the three criteria

CriteriaSignalSource
SLA breachFirst-response or resolution timer has passed the target for the ticket's tierTicket timestamps in Plain vs. {{sla_targets}}
VIP accountThe ticket's account name or domain matches the VIP listPlain customer/account field vs. {{vip_accounts}}
High severityThe ticket describes an outage, data loss, a security issue, or something blocking a paying customer's core workflowPlain tags and ticket body
Any single match qualifies the ticket for escalation. A ticket can match more than one criterion — carry every matching reason into Step 5, don't collapse to just one.

Step 3 — Route to the right team

Tag or assign the qualifying ticket to the team that owns it:
Ticket is aboutRoute to
A payment, invoice, or billing disputeBilling / Finance
A security or data-handling concernSecurity
An outage, bug, or product defectEngineering (continue to Step 4)
A VIP account issue with no technical fault (relationship, contract, expectations)Customer Success / Account team
This tag-or-assign update is the only write the agent makes to the ticket itself. It is never a status change, and it never closes or resolves the ticket.

Step 4 — Open a linked Linear issue when engineering is needed

Only for tickets routed to Engineering in Step 3 (outage, bug, product defect). Before filing, check the ticket for an existing linked issue — never open a duplicate for the same ticket.
Create the issue in {{linear_team}}:
  • Title — a short, specific summary of the reported problem.
  • Description — the account, the escalation reason(s) from Step 2, the relevant details or repro steps from the ticket, and a link back to the Plain ticket.
  • Priority — Urgent for an active outage, data loss, or an already SLA-breached ticket; High for a VIP account with a real bug; Normal otherwise, and let the engineering team triage from there.
Attach the created issue's URL back onto the Plain ticket as an internal note so the two records are linked in both directions.

Step 5 — Post the alert

Post one message per qualifying ticket to {{escalation_channel}}: the ticket link, the account name, every escalation reason that matched (SLA breach / VIP / severity), the team it was routed to, and the linked Linear issue URL if Step 4 created one.

Step 6 — Stop

One pass over the current queue is one run. There is no ledger — the next sweep, 15 minutes later, re-reads the queue's state at that point and starts over.
Escalation routing — Kortix Marketplace | Kortix