Skip to content

Ticket Escalation Criteria: L1 to L2

This article is a process guide rather than a troubleshooting scenario, so it uses a slightly different structure from the rest of the knowledge base.

Purpose

This guide defines when an L1 agent should escalate a ticket to L2, and how to do it so the next agent can pick up the issue without repeating work that's already been done.

When to Escalate to L2

  • The issue requires administrator-level access you don't have, such as server configuration, directory management, or network device settings.
  • You've completed all the standard L1 steps in the relevant KB article and the issue is still unresolved.
  • The issue affects multiple users or a whole location, suggesting an infrastructure problem rather than a single-device issue.
  • The issue involves a security concern, such as a suspected compromised account, unusual login activity, or malware that basic tools can't remove.
  • The user is a VIP, or the issue has a deadline you can't reasonably meet at L1 (for example, a meeting starting in ten minutes).
  • You're unsure how to proceed, and further attempts risk making the issue worse, such as a risk of data loss.

How to Escalate

  1. Confirm you've followed the relevant KB article's steps and documented what you tried.
  2. Update the ticket with a clear, chronological summary of the troubleshooting already performed.
  3. Set the ticket priority based on business impact, not personal urgency.
  4. Assign the ticket to the correct L2 queue or team.
  5. Notify the user that the issue has been escalated, and give a realistic expectation for follow-up.
  6. Stay available for questions from L2 in case they need more information from the user.

What to Include in an Escalation

  • The exact error messages or screenshots.
  • The steps already taken and their results.
  • Whether the issue is isolated to one user or affects multiple people.
  • Any relevant timestamps: when the issue started, and when it was last working normally.
  • The user's device details (OS version, device name or asset tag) if relevant.