Policy
Settings › Organizations › the organization › SLA sets, per severity, the target time to acknowledge and the target time to resolve, and the coverage window: 24x7, or business hours in the organization's time zone. Outside a business-hours window the clock does not run.
Measurement
Timestamps for queue entry, acknowledgement (first assignment) and closure or escalation are written once and never edited. Time to acknowledge and time to resolve are computed from them, within the coverage window. The alert queue shows remaining time per alert; the alert page shows the timers; an approach warning fires at the threshold set in the policy, and a breach raises a notification.
Reporting
The monthly SLA report, generated on schedule and delivered to the customer portal, shows per severity the number of alerts, the share met, breached and pending, and the median times. The same figures are on the organization's page in the console at any time.
Exclusions
Suppressed matches never enter the queue and never start a clock. Alerts closed as duplicates through correlation are excluded. Everything else counts; if a source was delayed, the report shows the breach with its reason.