A complete pack, redacted, shown in full
This is the highest-leverage page on the site, so it is not a screenshot and it is not a sample chapter. It is an entire pack, built from one provider’s published pages, with the provider’s identifying details replaced by redactions and nothing else changed.
Built from a provider in the ten-to-forty-nine band whose support page publishes a one-business-hour response commitment and a three-tier table. The provider is not a client and did not participate; every input was public.
Output 1 — Ticket-category taxonomy
Extract: eight of the fifty-one rows. Every row maps a category onto a tier the provider already publishes, and states whether first line owns it.
| ID | Category | Published tier | First line owns it |
|---|---|---|---|
| ACC-01 | Password reset, standard user | Essential | Yes |
| ACC-03 | Mailbox delegation request | Essential | Yes, with named approver |
| ACC-07 | Privileged account request | Managed | No — escalate on receipt |
| PRN-02 | Print queue stalled, single user | Essential | Yes |
| PRN-05 | Print server unavailable, site-wide | Managed | No — escalate on second user |
| NET-04 | Site-wide connectivity loss | Managed | No — escalate immediately |
| END-11 | Device replacement, warranty in force | Complete | Yes, to the point of dispatch |
| SEC-02 | Suspected phishing message reported | Managed | Yes, triage only; escalate on any click |
Output 2 — First-line response template pack
Extract: two of the eighteen templates. Both are written in the provider’s own published service language, including its own quoted response window.
PRN-02 — Print queue stalled, single user
Subject: [Provider] — your print issue, ticket {{ref}}
Thanks for letting us know. I can see the print queue on your machine has stalled — this is something we clear from our side, so there is nothing you need to do. I am doing that now and will confirm within the one business hour response window we hold ourselves to. If the job still does not appear after that, reply to this message and I will move it to our escalation team.
SEC-02 — Suspected phishing message reported
Subject: [Provider] — thanks for reporting that message, ticket {{ref}}
Thank you for reporting this rather than deleting it — that is exactly the right thing to do. Please do not click anything in the message or reply to it. I am checking whether anyone else on your tenancy received it. Two questions so I can close this properly: did you click any link or open any attachment, and did you enter any details on a page it opened? If the answer to either is yes, say so and I will escalate immediately.
Output 3 — Escalation-rule sheet
Extract: five of the fifty-one rules. Every rule names a trigger, because a rule without a trigger is a preference.
| ID | First line closes when | Escalates on trigger |
|---|---|---|
| ACC-01 | Identity confirmed by the agreed method and reset delivered | Third reset for the same user in 30 days |
| ACC-03 | Named approver on file has confirmed in writing | No named approver on file for that client |
| PRN-05 | Never — not a first-line close | Second affected user, or any shared device |
| NET-04 | Never — not a first-line close | On receipt; page the on-call engineer |
| SEC-02 | User confirms no click, no attachment, no credentials entered | Any click, any attachment opened, any credentials entered, or a second report on the same tenancy |
Output 4 — Ranked documentation-gap list
The full list as delivered, twelve entries, ranked by how often an untriaged category recurs against how little is written down for it.
- Mailbox delegation approvals — 4th most frequent category; no named approver recorded for six of eleven clients.
- Privileged access requests — no written rule; currently decided by whoever picks up the ticket.
- Site-wide print failures — escalation happens, but on no stated trigger, so it happens late.
- Phishing reports — triage questions are asked inconsistently; two of the four engineers ask neither.
- Device replacement thresholds — the tier table implies a threshold the desk cannot state.
- Out-of-hours definition — the published commitment says “business hours” without defining them per client time zone.
- Repeat-caller handling — no rule for the third contact on one issue.
- New-starter onboarding — a checklist exists but is not linked to a ticket category.
- Third-party vendor tickets — nobody owns the waiting-on-vendor state.
- Licence requests — no threshold above which the account manager is told.
- Backup restore requests — not in the tier table at all.
- Ticket closure wording — no standard, so the response commitment is claimed inconsistently at close.
This list is the part clients quote back most often, because it is the only artefact that says where the desk is thin in the order the desk should fix it.
We turn the service tiers an MSP already publishes into a written first-line triage system — taxonomy, replies, escalation rules — delivered in ten business days without a single call.
Buy the First-Line Triage Pack
From US$1,200 · fixed scope
Fixed scope · Ten business days · No calls, ever