War-game a support escalation ladder before a severity-one teaches customers that your "24/7" path still depends on one pager who is offline.
Escalation ladders fail when tiers are names without owners, when handoff SLAs are hope, when status language stays vague while customers invent their own narrative, and when executives join late without the same facts frontline already has. A pretty flowchart is not evidence that the ladder survives a holiday weekend incident.
Freeze the ladder
State each tier, who owns it by role and backup, the time boxes between tiers, the customer-facing update cadence, and the success metric after the next real incident. Attach the current runbook, on-call roster, severity definitions, and sample status copy. If support, eng, and comms disagree on when a ticket becomes an incident, reconcile before the war game.
Write the decision you will make if the war game finds nothing new, and the delay criteria if backups or status ownership are missing.
Seats that matter
- Frontline support. What they can resolve without waking anyone, and what they cannot.
- On-call eng. Whether severity definitions match how pages actually fire.
- Angry customer. The update cadence and honesty bar they would demand in public.
- Comms and legal. What can be said on the status page without creating new liability.
- Skeptic. The claim that looks strongest and is least sourced.
Give every seat the same runbook. Secret "call me on my cell" paths for one executive create fake coverage.
Loop the review
Feed Pingpong the ladder, roster, and sample status notes. First pass steelmans the design. Later passes attack from frontline, on-call, customer, and comms seats. Final pass turns surviving objections into clearer time boxes, named backups, or rewritten status templates. Delete dual-counted "always covered" claims and invented mean-time-to-engage.
When severity definitions depend on customer spend rather than user harm, force angry-customer and frontline seats to attack until each severity has observable triggers. Spend-based shortcuts create quiet VIP paths that leak and destroy trust. Write the customer-facing update template into the package so night-shift support is not inventing language during the first public post.
Ask on-call and comms seats to walk a dual-incident timeline with names and minutes, not with "we escalate as needed." If the timeline requires a hero who is not on the roster, the ladder is fiction. Fix backups and status ownership before the next peak load.
Force a holiday-weekend narrative: two severity-ones overlap, the primary on-call is unreachable, and a large account posts publicly. If that story is stronger than your backup plan, fix the package before the next peak. Related: war-game a customer escalation, stress-test a support policy change, stress-test an SLA change, pretend you are the angry customer, review a crisis comms plan, and the war-game decisions hub. Process: how to run a Pingpong.