Section 3 · 20 min
An Alert Just Arrived — Now What?
Seven steps, every time.
This is the core of the session. Work through the responder journey step by step, then we do it live in JSM.
The notification is not the work item. The alert in JSM is.
The responder journey
Step 3 in focus: acknowledge = ownership
Acknowledge
I have seen this alert and I am taking responsibility for responding to it.
Before
Alert
→ No responder has taken responsibility
After acknowledge
Alert
→ You are actively responding
Acknowledging helps the response system, and your teammates, understand that someone is working the alert.
Step 4 in focus: two levels of information
What I need right now
- What happened?
- Priority
- Affected system / service
- Immediate action
- Ownership
Deeper technical context
- Extra properties
- Monitoring details
- Links
- IDs
- Technical metadata
- Attachments
- External system references
Immediate operational information should be easy to find. Deeper technical context remains available when you need it.
Step 5 in focus: how to ask for help
Current anti-pattern
- I need help
- Forward alert email
- Hope someone sees it
Correct JSM behaviour
- I need help
- Open alert
- Add responder / team
- Add context
- Shared operational record
- Clear ownership
- Shared context
- Visible participation
- Better audit trail
- Less duplicate effort
- Everyone works from the same operational record
Key Concept 3
Forwarding an email does not transfer operational responsibility.
Live demo
- Open
- Assess
- Acknowledge
- Add note
- Add responder
- Review service / context
- Close
Responder anti-patterns
Working only from email
Why it is a problem: The alert record does not reflect actual ownership, investigation or collaboration, so nobody else can see what is really happening.
Preferred behaviour: Open and work the alert in JSM.
Forwarding notifications to get help
Why it is a problem: Forwarding email does not formally add the recipient to the response or establish ownership.
Preferred behaviour: Add responders or teams in JSM.
Acknowledging just to stop notifications
Why it is a problem: Acknowledgement indicates someone has taken operational responsibility. Silencing an alert you are not working hides the fact that it is still unowned.
Preferred behaviour: Acknowledge when you are actually taking ownership.
Closing before the work is complete
Why it is a problem: Closing communicates that no further operational action is required.
Preferred behaviour: Close only when the alert no longer requires response.
Treating every alert as an incident
Why it is a problem: Alerts are signals. Many can be resolved by one responder without formal incident coordination.
Preferred behaviour: Create or escalate to an incident when coordinated response is warranted.