Zendesk SLA Breach
A Zendesk SLA breach is a target that ran out of time. Which target, on whose clock, and why nobody noticed are three separate questions.
What counts as a Zendesk SLA breach
Zendesk doesn't have one SLA clock per ticket. It has a clock per target, and each one breaches independently. A ticket can hit its first reply target comfortably and still breach the next reply target six hours later.
The targets available cover the shape of most agreements: first reply time, next reply time, periodic update, requester wait time, agent work time, and total resolution time. A policy attaches targets to conditions and priorities, so an urgent ticket gets a tighter number than a low one.
A breach means the clock for one of those targets passed its target without the qualifying event. Nothing stops. The ticket stays open, work continues, and the record of the miss stays attached to the ticket.
When the clock is not running
Half the "false breach" arguments come from misunderstanding the clock, so this is worth getting exact.
Alerts before the fact, not after
A notification that fires on breach is a record of failure. A notification that fires before it's a chance to prevent one.
The pattern that works is an automation checking tickets approaching their target, notifying the group rather than the individual assignee. Group notification matters, because the single most common reason a ticket breaches is that its assignee is off sick, on holiday or in a meeting. Telling only them guarantees silence.
Alongside that, build a view sorted by time remaining on the SLA and keep it on a wall or a second monitor. Views update continuously, which makes them better than notifications for the last hour before a target. Notifications interrupt. Views inform.
Resist the urge to alert at four thresholds. Two is plenty: one warning with enough time to act, and one on the breach itself for the record.
Reporting on breaches usefully
Explore has SLA metrics built in, and the number most teams pull is attainment: the percentage of targets met. Fine as a headline, useless for diagnosis.
What actually helps:
The SLA attainment calculator is a quick way to sanity check what a given target actually implies for your volume before you promise it.
The five causes behind most breaches
Nobody owned it. Unassigned tickets breach more than any other category. Route on creation so nothing waits in a pile with no name on it.
The assignee was away. Individual assignment plus an absence equals a breach. Assign to groups, or reassign automatically when someone is out.
The wrong clock. Calendar hours on a policy for a team that works nine to five produces breaches that never happened in reality.
Coverage gaps. If tickets arriving at 16:45 on Friday consistently breach, your target and your rota disagree. One of them has to move, and it is usually cheaper to move the target.
The same question answered twice. A customer writes in twice, the second ticket sits unassigned because someone is already handling the first, and it breaches quietly. The work got done and the metric records a failure. That one is worth checking for before you conclude your team is slow.
Frequently asked questions
Can you be warned before a breach rather than after?
Yes, and you should be. A Zendesk SLA notification fires on an automation before the target expires, which is the only useful Zendesk SLA breach alert. Zendesk SLA reporting after the fact tells you what you already failed.
What counts as an SLA breach in Zendesk?
Any single target passing its time limit without the qualifying event. Each target has its own clock, so one ticket can meet first reply and breach resolution.
Does a breach stop the SLA clock?
No. The target is recorded as breached and work continues. Other targets on the same ticket keep running independently.
How do I get notified before an SLA breach?
Build an automation on tickets approaching the target and notify the group, not the assignee. Pair it with a view sorted by time remaining for the final hour.
Why does Zendesk show a breach when we replied in time?
Usually a clock mismatch. Check whether the policy uses business or calendar hours, whether the right schedule is attached to the group, and whether holidays are configured.
Can I remove a breach from a ticket?
The record of a met or missed target isn't something you edit after the fact. If a policy was wrong, fix the policy and note the correction in your reporting rather than trying to rewrite history.
Breaches on work already done
A duplicate sitting unassigned breaches while the real ticket gets answered. Merging on arrival removes that failure mode.
Start free trial14-day free trial. No credit card required.