Escalation Engine
It is 9:15 AM on Thursday at the Rixensart vaccine manufacturing campus. During the TIER 2 weekly review, the Production Director notices that a critical action — "Replace non-OEM vacuum pump gasket on Lyo Chamber 4" — has been sitting at TIER 1 for six days, three days past its due date. But she did not discover this by accident. ProBeya's escalation engine automatically promoted the action to TIER 2 on Tuesday, notified her team, and placed it on today's review agenda. The action is now visible at the right level of the organization, with the right people, at the right time.
This is management by exception in practice. The system does the watching. The leaders do the deciding.
The TIER Hierarchy: Why It Exists
The tiered management system originated in the Toyota Production System and was adapted for pharma manufacturing by companies like Danaher, Johnson & Johnson, and Novartis. The principle is simple: decisions should be made at the lowest competent level. When that level cannot resolve an issue — due to authority, resources, or cross-functional complexity — the issue escalates upward.
TIER 3 ── Site / Executive Level
| Monthly steering committee
| Capital decisions, regulatory strategy, cross-site coordination
|
TIER 2 ── Department / Value Stream Level
| Weekly management review
| Resource allocation, cross-team dependencies, budget decisions
|
TIER 1 ── Shop Floor / Operational Team Level
Daily standup (5-15 minutes)
Frontline problem solving, shift-level issues
ICH Q10 Section 2.3 emphasizes "management responsibility" and "management review" as pillars of the pharmaceutical quality system. The TIER hierarchy operationalizes this: TIER 1 catches the problem, TIER 2 allocates resources, and TIER 3 makes strategic decisions. The escalation engine is the connective tissue that ensures issues flow between these levels without getting lost.
The escalation engine is your early warning system. If you are consistently surprised by problems at TIER 3 that should have been resolved at TIER 1 or TIER 2, the issue is not the escalation engine — it is the escalation rules. Tighten the trigger days, enable auto-escalation, and review the escalation dashboard monthly.
Configuring Escalation Rules
Escalation rules define when and how actions move between tiers. Rules are configured per board, allowing different SQCDP domains to have different escalation policies. A safety issue should escalate faster than a cost optimization action.
Setting Up Rules
- Navigate to the board settings.
- Open the Escalation Rules tab.
- Click + Add Rule.
Each rule has the following parameters:
| Parameter | Description | Example |
|---|---|---|
| From Tier | Source tier level (1 or 2) | 1 |
| To Tier | Destination tier (must be greater than From Tier) | 2 |
| Trigger Days | Days past due date before escalation fires | 3 |
| Auto-Escalate | Whether escalation happens automatically or requires manual approval | true |
| Notify Users | Users notified when this rule triggers | Department manager, shift lead |
| Active | Whether this rule is currently enabled | true |
Here is the escalation policy used at several Top 10 pharma manufacturing sites:
| Rule | From | To | Trigger Days | Auto | Rationale |
|---|---|---|---|---|---|
| Safety actions | TIER 1 | TIER 2 | 1 day | Yes | Safety cannot wait — immediate visibility |
| Quality actions | TIER 1 | TIER 2 | 2 days | Yes | OOS/deviations have regulatory clock ticking |
| Delivery/Cost actions | TIER 1 | TIER 2 | 5 days | Yes | Operational but lower urgency |
| All actions | TIER 2 | TIER 3 | 5 days | No | Executive escalation requires human judgment |
The key insight: auto-escalation for TIER 1 to TIER 2 (volume is high, speed matters) and manual escalation for TIER 2 to TIER 3 (executive attention is scarce, context matters).
Rule Evaluation Logic
The escalation engine evaluates rules on a regular schedule (configurable, recommended: every 15 minutes):
- Find all actions where status is not
doneorverifiedanddueDate < now - Calculate
overdue_days = today - dueDate - For each action, check if an active rule matches its current
tierLeveland ifoverdue_days >= triggerDays - If
autoEscalate = true, automatically escalate the action - If
autoEscalate = false, flag the action for manual escalation and notify the configured users
Disabling Rules
Rules can be temporarily disabled without deletion by toggling the Active switch. This is useful during:
- Plant shutdowns or holiday periods
- Organizational transitions (new department structure)
- Planned maintenance windows where overdue actions are expected
Auto-Escalation: What Happens
When auto-escalation triggers, ProBeya executes a precise sequence:
- The action's
tierLevelis updated to the destination tier - The
escalatedAttimestamp is recorded - The
escalatedFromfield captures the escalation chain for traceability - Notifications are sent to all users in the rule's notify list
- An entry is added to the action's activity timeline: "Auto-escalated from TIER 1 to TIER 2 (3 days overdue)"
The original assignee remains unchanged. The higher-tier manager receiving the notification decides whether to reassign, add resources, or remove blockers.
Every auto-escalation event is logged with the actor as system, the source as auto, and the full escalation chain. This creates an immutable record showing that the organization's escalation policy was executed as configured — a powerful evidence point during GMP inspections when auditors ask "How do you ensure overdue CAPAs receive management attention?"
Manual Escalation: When Humans Override the Clock
Sometimes the clock is not the right trigger. A shift supervisor may recognize that an action needs TIER 2 support before it becomes overdue — perhaps because a cross-departmental dependency was discovered, or because a safety observation requires immediate executive visibility.
- Open the action detail panel
- Click the Escalate button (upward arrow icon)
- Select the target tier level
- Add an escalation note explaining why
- Confirm the escalation
Manual escalation follows the same process as auto-escalation but is tagged as source = "manual" in the escalation history. The note field is critical: it provides context that the receiving manager needs to make a decision.
Decision Framework: When to Manually Escalate
| Situation | Escalate? | Rationale |
|---|---|---|
| Action blocked by another department | Yes | Only TIER 2 can coordinate cross-department resources |
| Safety concern requiring capital investment | Yes | TIER 3 budget authority needed |
| Action on track but complex | No | Let TIER 1 work the problem — escalation is not delegation |
| Repeated recurrence of a resolved action | Yes | Pattern indicates systemic issue beyond TIER 1 scope |
| Action owner on leave, no backup assigned | Yes | TIER 2 can reassign and reset the timeline |
De-Escalation: Closing the Loop
Once a higher-tier manager has made a decision — approved budget, allocated headcount, removed a cross-departmental blocker — the action returns to the appropriate level for execution.
- Open the action detail panel
- Click the De-escalate button (downward arrow icon)
- Select the target tier level (must be lower than current)
- Add a de-escalation note describing the resolution or decision
- Confirm the de-escalation
De-escalation does not reset the due date. If the action is still overdue after de-escalation, it may re-trigger escalation based on active rules. Update the due date to reflect the new timeline agreed at the higher tier.
Escalation Dashboard
The Escalation Dashboard provides the consolidated view that TIER 2 and TIER 3 leaders need during their review meetings.
Active Escalations Table
Shows all actions escalated at least once that are not yet resolved:
| Column | Description |
|---|---|
| Action | Title and linked board |
| Original Tier | Where the action started |
| Current Tier | Where it sits now |
| Days Overdue | Calendar days past due date |
| Escalated On | When the last escalation occurred |
| Assignee | Current responsible person |
Escalation Funnel
A visual summary showing action distribution across tiers:
TIER 1: 42 actions (35 on track, 7 overdue)
TIER 2: 8 actions (5 on track, 3 overdue)
TIER 3: 2 actions (1 on track, 1 overdue)
In a healthy organization, the funnel narrows sharply. If TIER 2 and TIER 3 are holding a disproportionate number of actions, it signals either that TIER 1 teams lack resources or that the organization is over-escalating.
Trend Chart
A time-series chart showing escalation volume per week/month, broken down by direction (escalation vs. de-escalation) and source (auto vs. manual). A rising trend in auto-escalations is a leading indicator of operational stress.
Track the ratio of auto-escalations to manual escalations. A healthy ratio is roughly 60/40. If auto-escalations dominate, teams may be ignoring due dates. If manual escalations dominate, due dates may be set unrealistically and the auto-escalation rules need recalibration.
Escalation History Timeline
Every action maintains a complete chain of custody:
Mar 15, 09:00 Created at TIER 1 by Alice (source: tier_meeting)
Mar 15, 09:05 Assigned to Bob
Mar 18, 10:00 Auto-escalated to TIER 2 (3 days overdue)
Notified: Carol (dept manager), Dave (shift lead)
Mar 19, 14:30 Reassigned to Eve by Carol
Mar 21, 11:00 De-escalated to TIER 1 by Carol
Note: "Budget approved, proceed with OEM gasket order"
Mar 23, 16:00 Status changed to Done by Eve
Mar 24, 09:00 Verified by Carol
This timeline satisfies the "complete, consistent, accurate" data requirements of EU GMP Annex 11 and provides the evidence chain that auditors expect when reviewing CAPA effectiveness.
Cron Job Setup
The auto-escalation engine runs via a protected HTTP cron endpoint.
Endpoint: POST /api/cron/escalation
Authentication: Requires the x-cron-secret header matching the CRON_SECRET environment variable.
Recommended schedule: Every 15 minutes (*/15 * * * *)
# Example: crontab entry
*/15 * * * * curl -s -X POST https://your-instance.probeya.com/api/cron/escalation \
-H "x-cron-secret: $CRON_SECRET" \
-H "Content-Type: application/json"
Each run:
- Fetches all active escalation rules across all organizations
- Queries overdue actions matching
fromTier+triggerDays - Auto-escalates matching actions to
toTier(ifautoEscalate = true) - Sends 24-hour pre-warning notifications to action owners approaching threshold
- Creates notifications for users in the rule's
notifyUserIdslist - Logs all escalation events to the activity audit trail
Never expose the CRON_SECRET in client-side code or public URLs. The endpoint returns 401 if the secret is missing or incorrect.
Permissions
| Action | Required Role |
|---|---|
| View escalation dashboard | Any board member |
| View escalation history on actions | Any board member |
| Configure escalation rules | Department manager or above (escalate permission) |
| Auto-escalation (system) | Automatic — no user role required |
| Manual escalation | Board admin or workspace admin |
| Manual de-escalation | Board admin or workspace admin |
Related Features
- Action Log — The actions that flow through the TIER hierarchy
- KPI Boards — Red KPIs trigger actions that may later escalate
- TIER Meeting Mode — Review escalated items during meeting agendas
- Problem Solving — Investigate root causes of escalated issues
- Templates — Escalation rules are included in board templates