01
State the symptom and scope
What is failing, who is affected, where it occurs, whether it is reproducible, and whether the impact is one user, one device, one site, or shared infrastructure.
Everyday IT · Escalation
The next engineer should not have to rediscover the scope, repeat every comparison test, or guess why you stopped.Hand off the evidence, the risk, and the exact question that remains.
A strong handoff can be short if it contains the right information.
01
What is failing, who is affected, where it occurs, whether it is reproducible, and whether the impact is one user, one device, one site, or shared infrastructure.
02
Record known-good comparisons, browser-vs-client results, direct-path tests, service state, relevant logs, permissions, timestamps, or other evidence that narrowed the layer.
03
List targeted actions already taken and their results. Also note important things intentionally not changed because of risk, scope, ownership, or missing authorization.
04
Do not end with “please investigate.” Name the unresolved layer or decision: firewall route, Conditional Access policy, storage health, inheritance design, server availability, vendor behavior, or another specific next question.
Do not erase the path that ruled things out.
Comparison
If the same user works on another device or another user works on the affected device, include that result because it narrows the next engineer's starting point.
Reachability
Examples: portal reachable but authentication rejected, VPN connected but UNC failed, browser mailbox healthy but desktop Outlook failed, or Windows detected no scanner over the dock path.
Change result
A targeted change that produced no improvement is useful when it was justified and documented. It prevents unnecessary repetition.
Intermittent
Record whether the issue follows an application launch, user sign-in, location, time of day, reboot, password change, or another repeatable trigger.
Escalation is often triggered because the blast radius changed.
Data
Call out unsynced files, unique local data, restore risk, failing storage, retention concerns, or any step that could alter historical content.
Privilege
Identify when the next step requires firewall administration, Global Administrator, Domain Admin, production server access, or another privileged boundary.
Dependency
Document the suspected domain controller, DNS, firewall, mail flow, storage, hypervisor, backup, security, or vendor dependency instead of handing over only the end-user symptom.
Rollback
If configuration was changed, include the prior state, export, screenshot, ACL capture, or other rollback reference when available.
The goal is signal, not a wall of ticket history.
Summary
One or two sentences that make the user impact and scope clear.
Evidence
List the few tests and findings that materially changed the investigation.
Actions
Include targeted remediation, outcome, and current system state.
Ask
End with the unresolved decision, access boundary, or infrastructure question that caused the escalation.
Escalate the investigation, not just the ticket.
A good handoff preserves the work already done and gives the next engineer a smaller problem than the one you started with.
Make the handoff reproducible.
State who, what, where, and when is affected before handing off the ticket. Scope the problem
Record the known-good test and the single variable that changed. Use a known-good comparison
Include current state, attempted changes, rollback status, and the risk that stopped the work. Document the safe boundary