Skip to content

Hello, How can we help?

Back to FAQ

How to escalate project risks

Last updated: 7 May 2026


What this does

Escalation is the workflow that lifts a risk from "noted on the risk register" to "someone senior has been told and owns the response". IMPACT supports three escalation levels with explicit notification, deadlines, and an audit trail so nothing slips silently.

Current access and functionality

  • Verified against the current impact-web, impact-client, and impact-marketplace code on 2026-05-07.
  • In impact-web, users must be signed in and working in an active workspace. Navigation and write actions are role-, permission-, and entitlement-aware; unavailable modules are hidden or disabled instead of being universally visible.
  • In impact-client, the mobile app covers day-to-day work such as tasks, checklists, projects, surveys, members, dashboards, and marketplace template usage. Administrative setup and some advanced configuration remain web-first.
  • Project creation and management are available to company admins, owners, project coordinators, and project managers according to the permission matrix. Project members may only see assigned or permitted project content.

Before you start

  • The risk must already be registered — see .
  • You need to know the escalation path: usually project manager → portfolio lead → company admin/owner. Configure the path per workspace under Settings → Risks → Escalation path.

The three levels

LevelTriggersWho's notifiedDefault deadline
L1 — Team leadLikelihood × Impact crosses a low thresholdTeam lead + risk owner5 working days to acknowledge
L2 — Project managerL1 deadline passed without acknowledgement, OR severity raisedPM + business sponsor3 working days
L3 — Admin/OwnerL2 deadline passed, OR severity = CriticalAdmin/Owner + audit log entry24 hours

Severity ratings come from the risk's Likelihood × Impact matrix (1-5 each).

Steps

Manual escalation

  1. Open the risk from Risks → All risks or from the project's risk panel.
  2. Click Escalate.
  3. Pick the target level (L1 / L2 / L3).
  4. Add a one-line context note (e.g., "vendor confirmed they can't meet date").
  5. Confirm. IMPACT:
    • Notifies the level's recipients (email + WhatsApp if their notification preferences include it).
    • Sets a response deadline.
    • Logs the action with timestamp + actor.

Automatic escalation

  1. Enable in Settings → Risks → Auto-escalation.
  2. Pick the auto-trigger thresholds (e.g., "auto-escalate to L2 if severity ≥ 16").
  3. IMPACT runs the check every 4 hours.
  4. Auto-escalations carry an AUTO tag so the recipient knows it wasn't a colleague's manual judgement.

Acknowledging and responding

  1. Recipients see the escalated risk on their dashboard with a red "Action needed" badge.
  2. They click Acknowledge to stop the deadline countdown, then add a response plan in the risk's discussion thread.
  3. Until acknowledged, IMPACT sends a daily reminder.

De-escalation

  1. Once a risk is mitigated (likelihood or impact rating drops, or response is in flight and shrinking the exposure), open the risk → De-escalate.
  2. Pick the new level (or "no escalation needed").
  3. IMPACT keeps the prior escalation in the audit log; de-escalation is a state change, not a deletion.

Tips

  • Don't auto-escalate everything. Auto-escalation is for the few risks you cannot afford to forget. Most risks should escalate manually so the human judgement of "is this actually a problem yet?" stays in the loop.
  • L3 should be rare. If you find yourself escalating to L3 weekly, your L2 process is broken — fix that, not the L3 cadence.
  • Use the discussion thread. The escalation notification puts a specific risk in front of someone, but the discussion thread is where the actual response gets coordinated. Drive resolution there, not over email.

Common issues

  • Issue: Escalation didn't reach the recipient — Fix: Check Settings → Risks → Escalation path has the right user mapping. Also verify the recipient's notification preferences allow risk-channel pings.
  • Issue: Auto-escalation fired during a planned outage — Fix: Pause auto-escalation under Settings → Risks → Auto-escalation → Pause schedule for known maintenance windows.
  • Issue: Audit log shows multiple escalations for one risk — Fix: Each escalation is a separate event. To see the current state, look at the risk's status badge, not the count of historical escalations.