## Why It Matters

A report gets assigned, everyone means to get to it, and then a week passes. The SLA clock keeps running whether or not anyone remembers. Stalled report nudges close that gap: Kit watches assigned reports, reminds the owner privately when one goes quiet, and — only if that fails — tells your program admins.

## What Counts as "Gone Quiet"

Kit checks every hour. A report is quiet when nobody on your team has done any of these since it was assigned:

- Changed its status
- Replied to the researcher
- Added an internal note
- Re-assessed its severity

> [!NOTE]
> A message **from the researcher** does not count. Inbound mail isn't your team acting — otherwise a chatty researcher could keep a forgotten report permanently un-nudged.

## How Long Kit Waits

The wait scales with severity, derived from the resolution targets on your [SLA settings](/csirt/program/sla_config/edit). By default a report may idle **25% of its severity's resolution target** before the first reminder: a Critical report on a 48-hour target is nudged after 12 quiet hours, while a Low report on a much longer target waits days.

Two exceptions worth knowing:

- A report nobody has assessed yet is measured against your **acknowledgment** window instead — it's late on triage, not on remediation.
- Reports assessed as **Informational** are never nudged. They're real, but not worth pushing anyone about.

## What the Owner Gets

One reminder, on one channel — never both:

- A **Slack DM**, if their Slack account is connected to Kit.
- Otherwise, an **email**.

Either way it carries the same four actions:

| Action | What it does |
|--------|--------------|
| **Snooze for 3 days** | Defers the reminders for three days |
| **Snooze for 7 days** | Defers them for a week |
| **I'm waiting on the researcher** | Moves the report to Needs Clarification, which stops your clock |
| **Open the report** | Jumps straight to it in Kit |

From the email, these work without signing in — the link itself is the authority, and it retires as soon as the report moves on: a new owner, a new status, or a snooze all end it. From Slack, the buttons act as *you*, so your Slack account has to be connected to your Kit account; if it isn't, Kit says so and asks you to open the report instead.

If the next round of silence would escalate, the reminder says so before it happens.

## Snoozing

Each owner gets **two snoozes per stall** by default. Once they're spent, the reminders resume and Kit moves on to escalation instead. Any real activity on the report — a status change, an internal note, a reassignment — ends the stall and refills the budget.

## Escalation to Admins

After the owner has been reminded and the report still hasn't moved, Kit tells your program admins **once**, asking them to reassign it, take it, or check in with the owner.

> [!IMPORTANT]
> Admin escalation is the one message nobody can mute for themselves. It exists precisely because the private reminders already failed — a personal notification setting must not be able to sink it.

## The Daily Digest

Lower-severity reports don't send an individual reminder. They surface on your dashboard under **Needs Attention** and in a once-a-day summary email of everything waiting on you, sent at 9am in **your own** time zone.

Which severities take the quiet path is up to you (**Quiet threshold**, default High). At the default, Super Critical, Critical and High reports interrupt someone right away, while Medium and Low take the quiet path (Informational is never nudged at all). A report nobody has assessed yet is treated as urgent and nudges immediately — an unknown severity is not a reason to go quiet. Super Critical and Critical always send immediately, whatever the threshold is set to.

## Where Stalls Show in Kit

- A badge on the report itself: nudged, snoozed until a date, or escalated.
- A **Snooze** menu in the report header, so you can defer without leaving the page.
- A **Stalled Reports** row in **Needs Attention** on your VDP dashboard, which opens the filtered list — plus a one-click snooze on the row.

## Settings

Admins configure this under [Program Settings → SLAs](/csirt/program/sla_config/edit), in the **Response nudges** section:

| Setting | Default |
|---------|---------|
| Send nudges | On |
| Idle before the first nudge | 25% of the resolution target |
| Hours between nudges | 48 |
| Nudges before escalating | 2 |
| Snoozes per stall | 2 |
| Escalate to program admins | Yes |
| Quiet threshold | High |

## Muting Your Own Reminders

Owner reminders are yours to pause; admin escalations are not.

- **Slack** — turn off **VDP report reminders** under Settings → Slack Notifications.
- **Email** — unsubscribe from **Security program activity** in your email preferences.
- [Holiday Mode](/docs/holiday-mode) also pauses routine reminders while you're away.

## Quick Checklist

- [ ] Confirm your [resolution targets](/csirt/program/sla_config/edit) are realistic — the nudge clock is derived from them
- [ ] Decide your **Quiet threshold**: which severities are worth interrupting someone for
- [ ] Leave **Escalate to program admins** on unless you have a reason not to
- [ ] Ask your team to connect Slack so reminders arrive as DMs rather than email
- [ ] Make sure open reports are actually assigned — an unassigned report is never nudged