5 open tickets. 4 SLA signals need attention. 2 diagnostic sessions require escalation.
100.0% agreement with the seeded triage expectations.Queue position
The table keeps the operating decision and its evidence together: assigned priority, owning queue, SLA state, and the first matching knowledge article.
8 tickets shown.
| Ticket | Priority | Queue | Response | Resolution | Knowledge |
|---|---|---|---|---|---|
SUP-101Suspicious sign-in page opened from a message | P1 | Security Operations | Met | Breached | KB-SEC-001 |
SUP-102Design team loses access to office wireless | P2 | Network Operations | Met | Met | KB-NET-001 |
SUP-103Laptop reports critically low disk space | P3 | Endpoint Support | Breached | Within Target | KB-END-001 |
SUP-104Account locked after repeated password attempts | P2 | Identity & Access | Met | Met | KB-ID-001 |
SUP-105Finance group cannot edit a shared workspace | P2 | Workplace Applications | Breached | Breached | KB-COL-001 |
SUP-106Customer portal returns HTTP 502 for all users | P1 | Application Support | Met | Within Target | KB-APP-001 |
SUP-107External display not detected through a dock | P4 | Endpoint Support | Met | Met | KB-END-002 |
SUP-108Unfamiliar successful sign-in notification | P2 | Security Operations | Met | Within Target | KB-SEC-001 |
No tickets match these filters. Clear one or more filters to restore the queue.
Decision record
Open a ticket to inspect the matrix decision, security override, routing rule, knowledge match, and chronological audit trail.
SUP-101 Suspicious sign-in page opened from a message
Triage decision
- Matrix result: single_user impact + high urgency = P2.
- Security flag suspected_phishing requires P1; priority changed from P2 to P1.
- Security flag compromised_account requires P1; priority changed from P1 to P1.
- Category security routes to Security Operations.
- Matched 1 knowledge article(s) using visible ticket terms.
Knowledge matches
KB-SEC-001Suspected phishing containment unexpected sign-in link, credentials entered, unfamiliar sender
Audit timeline
- First Response
Verified the reporter through the approved identity workflow and asked them to stop using the affected session.
service-desk-01 - Triaged
Preserved the message and routed the case to Security Operations as a possible account compromise.
service-desk-01 - Escalated
Triggered account containment and session-revocation review; no destructive mailbox action was taken.
service-desk-01
SUP-102 Design team loses access to office wireless
Triage decision
- Matrix result: team impact + high urgency = P2.
- Category network routes to Network Operations.
- Matched 1 knowledge article(s) using visible ticket terms.
Knowledge matches
KB-NET-001Wireless DNS fault isolation wireless, dns does not resolve, wired connection works
Audit timeline
- First Response
Confirmed the affected scope and compared wireless and wired behavior before changing a client setting.
service-desk-02 - Triaged
Isolated the failure to DNS responses on the wireless segment and assigned Network Operations.
service-desk-02 - Resolved
Corrected the synthetic resolver policy, renewed one client lease, and verified internal and public name resolution.
network-queue-01
SUP-103 Laptop reports critically low disk space
Triage decision
- Matrix result: single_user impact + normal urgency = P3.
- Category endpoint routes to Endpoint Support.
- Matched 1 knowledge article(s) using visible ticket terms.
Knowledge matches
KB-END-001Recovery-safe disk pressure response low disk space, cannot save file, backup not confirmed
Audit timeline
- First Response
Collected disk-health and storage-usage evidence; did not delete user files or clear unknown folders.
service-desk-03 - Waiting
Paused cleanup until backup status and a recovery-safe deletion scope are confirmed.
service-desk-03
SUP-104 Account locked after repeated password attempts
Triage decision
- Matrix result: single_user impact + high urgency = P2.
- Category identity_access routes to Identity & Access.
- Matched 2 knowledge article(s) using visible ticket terms.
Knowledge matches
KB-ID-001Verified account-lockout recovery account locked, password attempts, cannot sign inKB-SEC-001Suspected phishing containment unfamiliar sign-in
Audit timeline
- First Response
Verified identity through the approved process before discussing account state.
service-desk-01 - Resolved
Cleared the lockout, required a password reset, and confirmed successful sign-in with multifactor authentication.
service-desk-01
SUP-105 Finance group cannot edit a shared workspace
Triage decision
- Matrix result: team impact + normal urgency = P2.
- Category collaboration routes to Workplace Applications.
- Matched 1 knowledge article(s) using visible ticket terms.
Knowledge matches
KB-COL-001Shared workspace permission recovery shared workspace, access denied, cannot edit
Audit timeline
- First Response
Confirmed that read access works and captured the affected group and workspace without collecting document contents.
service-desk-02 - Waiting
Requested owner approval before restoring the group's edit role.
service-desk-02
SUP-106 Customer portal returns HTTP 502 for all users
Triage decision
- Matrix result: organization impact + high urgency = P1.
- Category application routes to Application Support.
- Matched 1 knowledge article(s) using visible ticket terms.
Knowledge matches
KB-APP-001Bounded HTTP 502 isolation http 502, 502 response, portal unavailable
Audit timeline
- First Response
Verified the error from a separate network and recorded the response path without repeatedly refreshing the service.
service-desk-03 - Escalated
Proxy health was normal but the synthetic upstream health check failed, so the case moved to Application Support.
service-desk-03
SUP-107 External display not detected through a dock
Triage decision
- Matrix result: single_user impact + low urgency = P4.
- Category endpoint routes to Endpoint Support.
- Matched 1 knowledge article(s) using visible ticket terms.
Knowledge matches
KB-END-002Dock and display isolation dock, display not detected, display works elsewhere
Audit timeline
- First Response
Confirmed the display and cable work on another device before changing dock firmware.
service-desk-02 - Resolved
Applied the approved dock firmware update and verified charging, display detection, and wake behavior.
endpoint-queue-01
SUP-108 Unfamiliar successful sign-in notification
Triage decision
- Matrix result: single_user impact + normal urgency = P3.
- Security flag suspicious_login requires P2; priority changed from P3 to P2.
- Category security routes to Security Operations.
- Matched 1 knowledge article(s) using visible ticket terms.
Knowledge matches
KB-SEC-001Suspected phishing containment unfamiliar sign-in, unknown device
Audit timeline
- First Response
Verified the reporter and began the suspicious-login containment checklist.
service-desk-01 - Escalated
Routed the evidence to Security Operations for session review and containment.
service-desk-01
Diagnostic evidence
Each session stops when evidence is missing or a safety boundary requires escalation. Recorded observations stay separate from instructions.
DS-001Suspected phishing containment
SUP-101 · 2026-08-19T08:19:00Z
Escalated
The link was opened; escalate for endpoint and session review.
DS-001Suspected phishing containment
SUP-101 · 2026-08-19T08:19:00Z
-
Passed
reporter-verifiedReporter identity
Verify the reporter through an approved channel.
- Observed
- True
- Expected
- True
- Failure action
- Stop
-
Passed
message-preservedEvidence preservation
Preserve the suspicious message without forwarding or opening active content.
- Observed
- True
- Expected
- True
- Failure action
- Continue
-
Failed
link-openedLink interaction
Record whether the reporter opened the link.
- Observed
- True
- Expected
- False
- Failure action
- Escalate
DS-002Wireless DNS fault isolation
SUP-102 · 2026-08-19T09:50:00Z
Needs Attention
Name resolution failed; preserve the resolver assignment and continue with direct-IP evidence.
DS-002Wireless DNS fault isolation
SUP-102 · 2026-08-19T09:50:00Z
-
Passed
link-stateWireless link
Confirm that the client is associated with the intended wireless network.
- Observed
- True
- Expected
- True
- Failure action
- Stop
-
Passed
address-stateAddress assignment
Record whether the client has a valid managed address and gateway.
- Observed
- True
- Expected
- True
- Failure action
- Escalate
-
Passed
gateway-stateGateway reachability
Record gateway reachability without publishing the private address.
- Observed
- True
- Expected
- True
- Failure action
- Escalate
-
Failed
dns-stateName resolution
Compare direct IP reachability with internal and public name resolution.
- Observed
- False
- Expected
- True
- Failure action
- Continue
-
Passed
direct-ip-stateDirect IP reachability
Record whether a known public IP is reachable.
- Observed
- True
- Expected
- True
- Failure action
- Escalate
DS-003Recovery-safe disk pressure check
SUP-103 · 2026-08-19T12:18:00Z
Incomplete
Confirm a current recoverable backup or an approved alternative before deleting user data.
DS-003Recovery-safe disk pressure check
SUP-103 · 2026-08-19T12:18:00Z
-
Passed
disk-healthDisk health
Record the device's disk-health result before cleanup.
- Observed
- True
- Expected
- True
- Failure action
- Escalate
-
Not Recorded
backup-confirmedBackup state
Confirm a current recoverable backup or an approved alternative before deleting user data.
- Observed
- Not recorded
- Expected
- True
- Failure action
- Stop
DS-004Verified account-lockout recovery
SUP-104 · 2026-08-19T15:05:00Z
Completed
All recorded checks matched the expected evidence.
DS-004Verified account-lockout recovery
SUP-104 · 2026-08-19T15:05:00Z
-
Passed
identity-verifiedRequester identity
Verify the requester through the approved identity process.
- Observed
- True
- Expected
- True
- Failure action
- Escalate
-
Passed
compromise-screenCompromise indicators
Check for unfamiliar sign-ins, prompts, or repeated lockouts.
- Observed
- False
- Expected
- False
- Failure action
- Escalate
-
Passed
mfa-verifiedRestored sign-in
Confirm sign-in and multifactor authentication without collecting a code.
- Observed
- True
- Expected
- True
- Failure action
- Escalate
DS-005HTTP 502 boundary check
SUP-106 · 2026-08-19T15:34:00Z
Escalated
The proxy is reachable but the upstream is unhealthy; escalate to the owning application team.
DS-005HTTP 502 boundary check
SUP-106 · 2026-08-19T15:34:00Z
-
Passed
client-pathIndependent client path
Confirm the response from one separate network and record its timestamp.
- Observed
- True
- Expected
- True
- Failure action
- Stop
-
Passed
proxy-healthProxy reachability
Record the proxy or edge health result.
- Observed
- True
- Expected
- True
- Failure action
- Escalate
-
Failed
upstream-healthUpstream health
Compare the upstream health result with the proxy result.
- Observed
- False
- Expected
- True
- Failure action
- Escalate
DS-006Dock and display boundary check
SUP-107 · 2026-08-18T19:30:00Z
Completed
All recorded checks matched the expected evidence.
DS-006Dock and display boundary check
SUP-107 · 2026-08-18T19:30:00Z
-
Passed
display-known-goodKnown-good display path
Test the display and cable on a known-good workstation.
- Observed
- True
- Expected
- True
- Failure action
- Stop
-
Passed
dock-supportedDock compatibility
Confirm the dock is approved for the laptop model.
- Observed
- True
- Expected
- True
- Failure action
- Escalate
-
Passed
firmware-approvedFirmware change
Record whether the available firmware update is approved.
- Observed
- True
- Expected
- True
- Failure action
- Stop
-
Passed
post-change-verifiedPost-change verification
Verify charging, display detection, and wake behavior after the update.
- Observed
- True
- Expected
- True
- Failure action
- Escalate