War-game a pager policy by testing whether severity classes, escalation paths, and silence rules still protect sleep and customers when alerts spike and the on-call list looks short.
Pager policies fail when "customer impact" is undefined, when severity dual-counts the same event as urgent and as informational, and when silence windows live only as tribal knowledge. The review needs one written definition of a page-worthy alert, one owner who can deny a new page, and a documented consequence when a page fires without a runbook.
Freeze the policy proposal
Write the severity classes, required evidence, escalation ladder, silence rules, and acknowledgment SLAs. Attach the last thirty days of pages with outcomes, false-positive rates, and any customer-visible impact. Identify exclusions in plain language. If a class of alert is omitted from the policy, show how that omission affects risk rather than leaving it as a footnote.
Name the approval choice and the conditions that force a hold. Include the ticket fields that compute eligibility so two reviewers can reproduce the same allow or deny label from the same packet.
Seat the pager from both sides
- Service owner
- Defends why the new alert must page and what customer harm a delay would cause.
- On-call engineer
- Challenges noise, missing runbooks, and whether the alert reuses an untested path.
- Observability lead
- Tests signal quality, ownership, and whether the alert bypasses required coverage checks.
- SRE manager
- Checks whether rotation capacity matches the claimed page volume.
- Skeptic
- Finds the strongest urgency claim with the weakest runbook evidence.
Run pressure cases on the policy form
Use Pingpong to walk through a noisy dependency alert, a partner deadline that wants 24/7 paging, a security signal that arrives mid-freeze, and a request to waive the runbook because staging already looked green. For each case, start from the documented policy language. Ask who can expand severity and which evidence is required to reverse a deny. Any step that depends on an unnamed person becomes an on-call condition.
Ask the room to replay one historical page under the proposed rules. If the historical case would have woken people while later showing no customer impact, revise the policy before treating it as standard.
Compare the proposal with the observability lead seat and an on-call rotation stress test. If runbook ownership is unclear, review a runbook ownership map. More operating decisions live in the war-game decisions hub.
Publish the pager path only after a dry run can reproduce the same allow or deny label from the stored ticket fields without manual reinterpretation.