Why do SEV levels exist?
Without a shared scale, every incident starts with a negotiation: is this bad? Whom should I bother? SEV levels replace that negotiation with a lookup. Once an incident is labeled SEV1, nobody debates whether it deserves a dedicated incident channel or an executive update—the label carries the playbook with it. The scale also makes reporting possible: “we had three SEV1s this quarter, down from seven” is a meaningful sentence only if SEV1 means the same thing every time. The numbering convention runs opposite to intuition for newcomers: lower number = worse incident. A SEV1 is an emergency; a SEV5 is a note.What does a typical SEV scale look like?
There is no universal standard—every organization tunes definitions, and many use only three or four levels. The following five-level scheme is a common starting point:
Two design choices matter more than the exact wording. First, definitions should be observable—“affects more than X% of customers,” not “really bad”—so two responders reach the same answer. Second, each level must map to concrete response behavior; a severity that changes nothing about the response is just decoration. In Rootly, severity levels and their notification behavior are configured under severities.