Skip to main content
Rekkeh uses severity levels and lifecycle statuses to help your security team prioritize work and track incidents and emergencies from start to finish. This page explains the definitions and rules that govern how records move through the system.

Incident severity levels

Every incident is assigned a severity level. Severity affects filtering, sorting, and escalation rules.
Emergency alerts do not use the same severity scale. They have their own status lifecycle with time-sensitive transitions.

Emergency statuses and transitions

Emergencies use a fixed set of statuses. The stored status in Rekkeh maps to a Gate Ops label that responders see in the field.

Allowed status transitions

Emergencies must move through statuses in order. The allowed transitions are:
  • triggered to broadcasting
  • broadcasting to acknowledged
  • acknowledged to in_progress
  • in_progress to resolved
  • resolved to closed
Once an emergency is closed, it cannot be reopened. If follow-up work is needed, create a linked incident or a new emergency.

Incident list filters

In the Estate Admin dashboard you can filter the incidents list by: Combine filters to narrow the exact queue you are working. For example, filter by Open + High + Critical to see the highest-priority unreviewed items.

Emergency SLA

Rekkeh tracks response time from trigger to first acknowledgment. The default target is 5 minutes. Admins can see SLA performance in the emergency timeline and in historical reports. Missed SLA events are flagged automatically for review.
Filter incidents by severity and status daily to keep the queue manageable and ensure nothing stays in Open past its expected window.