Field Notes
Shared inboxes and the illusion of escalation
Escalation paths inside monitoring applications fail quietly when exceptions land in mailboxes nobody owns.
Many risk control monitoring applications can escalate. Fewer organisations can show who must act when the escalation email arrives. Shared inboxes with three claiming teams and no primary owner turn escalation into a forwarding contest.
What we examine
In fieldwork we ask for the routing table inside the application, then open the destination inbox with the operator present. We look for unread age, rules that auto-archive, and whether closing an email closes the exception in the application — or only clears the message.
A finding that travels well
Committees understand ownership gaps faster than configuration jargon. Write the finding as “escalations for control family X arrive in mailbox Y with no named primary” and attach a seven-day unread sample. Remediation is naming an owner and linking mailbox disposition back to the application status — not buying a new channel.
When to deepen the review
If routing is broken across several families, widen into a Full Application Control Audit. If only one family’s path is suspect, a Monitoring Gap Assessment may be enough.