# Create an escalation policy

`POST https://evohub.io/api/v1/escalation-policies`

Part of the [On-Call API](https://docs-dev.evohub.io/oncall.md) reference · operationId `createEscalationPolicy`.

Creates a policy: who is notified about an alert, in what order, and how often
it repeats. `team_id` defaults to the caller's first team and must be a team
the caller is in.

Rules for the policy and its `steps` (the whole list is replaced):

- At least one step. `target_type` is `user`, `schedule`, `webhook` or `slack`.
  A `user` step needs `target_user_id`, a `schedule` step
  `target_schedule_id`; a `slack` step (legacy) needs `target_slack_channel_id`.
- `delay_minutes` (the wait before the step) is one of 1, 2, 3, 5, 10, 15, 30
  or 60; only the first step may be 0, meaning at once.
- `attempts` is 1–10 (0 or omitted means 1). With more than one attempt,
  `attempt_delay_minutes` is one of the same intervals.
- `notify_method` is empty (each person's own notification preferences),
  `push`, `call` or `email`. SMS is not available for new steps; existing SMS
  steps can be kept when a policy is updated.
- A user named by a step must be a member who can respond to alerts. A
  `target_chat_channel_id` must be one of the organization's Microsoft Teams
  channels.
- With `repeat_enabled`, `repeat_count` is 1–5 and `repeat_delay_minutes` one
  of the intervals above.
- `ack_timeout_minutes` is 0 (off) or 1–1440; when set, `ack_timeout_repeat`
  is 1–5 and `ack_timeout_reach` is `others` (default) or `acker_first`.

**Permission (API-key scope):** `oncall:escalation:write`.

## Authorization

Any one of:

- `bearerAuth` (oncall:escalation:write)
- `apiKeyHeader` (oncall:escalation:write)

Where:

- `bearerAuth`: HTTP Bearer — An EvoHub API key (`evohub_…`) as a bearer token.
- `apiKeyHeader`: API key in the header `X-API-Key` — An EvoHub API key (`evohub_…`).

## Request body (required)

Content type: `application/json`

Type: `EscalationPolicyWrite`

- `name` (string, max length 100)
- `description` (string)
- `team_id` (string)
- `repeat_enabled` (boolean)
- `repeat_count` (integer, min 0, max 5)
- `repeat_delay_minutes` (integer)
- `ack_timeout_minutes` (integer, min 0, max 1440)
- `ack_timeout_repeat` (integer, min 0, max 5)
- `ack_timeout_reach` (string, one of ``, `others`, `acker_first`)
- `steps` (array of EscalationStepWrite, required, min items 1)
  - `step_number` (integer)
  - `delay_minutes` (integer): 0 (first step only), 1, 2, 3, 5, 10, 15, 30 or 60.
  - `target_type` (EscalationTargetType, required, one of `user`, `schedule`, `webhook`, `slack`)
  - `target_user_id` (string)
  - `target_schedule_id` (string)
  - `target_schedule_layer_id` (string)
  - `target_webhook_url` (string)
  - `target_slack_channel_id` (string)
  - `target_slack_channel_name` (string): Only together with `target_slack_channel_id`.
  - `target_chat_channel_id` (string)
  - `notify_method` (NotifyMethod, one of ``, `push`, `call`, `email`, `sms`)
  - `attempts` (integer, min 0, max 10): 1–10; 0 or omitted means 1.
  - `attempt_delay_minutes` (integer): Needed when `attempts` is more than 1.

## Responses

### 201 — The policy.

Content type: `application/json`

Type: `object`

- `data` (EscalationPolicy, required)
  - `id` (string)
  - `org_id` (string)
  - `team_id` (string)
  - `name` (string)
  - `description` (string)
  - `repeat_count` (integer)
  - `repeat_delay_minutes` (integer)
  - `repeat_enabled` (boolean)
  - `ack_timeout_minutes` (integer): Escalate again when an acknowledged alert stays unresolved this long; 0 is off.
  - `ack_timeout_repeat` (integer): How many times that may happen per alert.
  - `ack_timeout_reach` (string, one of ``, `others`, `acker_first`): `others` goes past whoever acknowledged; `acker_first` reminds them once first. Empty means `others`.
  - `steps` (array of EscalationStep)
    - `id` (string)
    - `policy_id` (string)
    - `step_number` (integer)
    - `delay_minutes` (integer): Wait before this step.
    - `target_type` (EscalationTargetType, one of `user`, `schedule`, `webhook`, `slack`)
    - `target_user_id` (string)
    - `target_schedule_id` (string)
    - `target_schedule_layer_id` (string): Page only this layer of the schedule.
    - `target_webhook_url` (string)
    - `target_slack_channel_id` (string): A Slack channel this step also posts to.
    - `target_slack_channel_name` (string)
    - `target_chat_channel_id` (string): A Microsoft Teams channel this step also posts to.
    - `notify_method` (NotifyMethod, one of ``, `push`, `call`, `email`, `sms`)
    - `attempts` (integer): How many times the step notifies before the policy moves on.
    - `attempt_delay_minutes` (integer)
    - `created_at` (string (date-time))
    - `updated_at` (string (date-time))
  - `external_source` (string)
  - `external_id` (string)
  - `created_at` (string (date-time))
  - `updated_at` (string (date-time))
- `success` (boolean, required, value `true`)

### 400 — The body is not JSON (`INVALID_BODY`), or a rule below is broken (`VALIDATION_FAILED`, the field is named in `details`).

Content type: `application/json`

Type: `ValidationError`

- `error` (object, required)
  - `code` (string, required, value `VALIDATION_FAILED`)
  - `message` (string, required)
  - `details` (array of object, required)
    - `field` (string)
    - `message` (string)

### 401 — No API key was sent, or it is unknown, revoked or expired (`UNAUTHORIZED`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.

### 403 — The key lacks the scope (`FORBIDDEN`), or `team_id` names a team the caller is not in (`NOT_IN_TEAM`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.

### 404 — A step names someone who is not a member of the organization (`NOT_A_MEMBER`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.

### 422 — A step names a person who cannot respond to alerts (`CANNOT_RESPOND`), or asks for SMS (`NOTIFY_METHOD_UNAVAILABLE`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.

### 429 — Too many requests (`RATE_LIMITED`). Wait `Retry-After` seconds.

Headers:

- `Retry-After` (integer): Seconds to wait.

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.

### 500 — Something went wrong on EvoHub's side (`INTERNAL_ERROR`). Retry later.

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.

### 503 — Whether the person may be paged could not be checked right now; nothing was changed (`MEMBER_CHECK_UNAVAILABLE`). Retry shortly.

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.

## Example request

```bash
curl -X POST 'https://evohub.io/api/v1/escalation-policies' \
  -H 'Content-Type: application/json' \
  -H 'Authorization: Bearer <TOKEN>' \
  -d '{
  "name": "Platform critical",
  "steps": [
    {
      "attempts": 2,
      "step_number": 1,
      "target_type": "schedule",
      "delay_minutes": 0,
      "target_schedule_id": "5b1c7d2e-8f3a-4b9c-a0d1-e2f3a4b5c6d7",
      "attempt_delay_minutes": 5
    },
    {
      "step_number": 2,
      "target_type": "user",
      "delay_minutes": 10,
      "notify_method": "call",
      "target_user_id": "4c2a9e7b-1d3f-4a8c-b6e5-9f0a1b2c3d4e"
    }
  ],
  "team_id": "a3f9c2e1-7b4d-4c8a-9e6f-2d1b0c9a8f7e",
  "description": "Page the rota, then the lead",
  "repeat_count": 2,
  "repeat_enabled": true,
  "ack_timeout_reach": "others",
  "ack_timeout_repeat": 1,
  "ack_timeout_minutes": 30,
  "repeat_delay_minutes": 15
}'
```
