Write the Triage Rules Before You Automate Them
An automated inbox does exactly what its rules say. If the rules were never written down, the system is guessing, and the guesses show up as misrouted complaints and auto-replies to the wrong people. This checklist gets the rules on paper first.
Work through it with the people who actually handle the inbox. Ticks are saved in your browser, so you can finish it over a few sittings.
Email Triage Rules Checklist
The rule set to write before any inbox automation is switched on.
Your ticks are saved in this browser, so you can work through the list over several sessions.
01Categories and owners
0/6Every message lands in one category, and every category has a name attached.
02Priority signals
0/5What tells the system a message matters more than the one next to it.
03Escalation and auto-reply rules
0/7When a message moves to a second person, and when a reply can go out without one.
04Templates and review
0/6Keeping the replies current and the rules honest after go-live.
A general framework. The categories, thresholds and exclusions that suit your inbox depend on what it receives. Where messages contain personal, health or legally sensitive information, confirm your privacy obligations before any third-party tool processes them.
What Good Triage Rules Look Like
Three properties separate a rule set that runs well from one that needs constant babysitting.
Every message lands in exactly one category
Categories must cover everything the inbox receives and must not overlap. A message that fits two categories gets routed by whichever rule fires first, which is arbitrary. A message that fits none sits in a catch-all nobody owns. Test the list against a week of real mail before trusting it.
Every category has a named owner
A category without an owner is a folder, not a rule. The owner is the person whose queue the message lands in and who is accountable for the response time. Name a backup for leave. If you cannot name an owner, the category is either unnecessary or the process is not ready.
The do-not-auto-reply list is written first
The most damaging automation mistakes come from replying to messages that should never get an automatic reply: complaints, legal notices, anything from a regulator, anything about a person. Write that list before any auto-reply case, and treat it as an override that beats every other rule.
How to Work Through It
Four passes over the same week of real mail. Each pass produces one part of the rule set.
Sort a sample by hand
Take a full week of inbox mail and put every message into a category. The categories you end up with, after merging duplicates, are your list.
Mark the signals
For each category, note what told you it belonged there: sender domain, subject words, an order number, a form source. Those are your rules and your priority signals.
Assign owners and triggers
Name the owner and backup for each category, then decide what makes a message escalate: age, keywords, sender type or a second message on the same thread.
Decide what gets an automatic reply
List the narrow cases where an automatic reply is safe, list the cases where it never is, and write the template for each safe case.
The Rules That Get Missed
Four parts of a triage rule set that most first drafts leave out, and that cause most of the problems after go-live.
Priority signals that are not keywords
Urgency is rarely stated in the subject line. It is in who sent it, whether they have written before, whether an order or job number is attached, and whether the message arrived through a form that promises a fast reply. Rules built only on words like urgent miss most of what is actually urgent.
- Known customer versus unknown sender
- Existing open job, order or ticket referenced
- Second message on a thread with no reply yet
- Source channel, for example a website form with a stated response time
Escalation triggers based on age
Most escalation rules fire on content. The one that catches the most problems fires on time: any message unactioned past a threshold goes to a second person. This is the rule that stops a misclassified message from sitting unseen in a folder for a week.
- Set an age threshold per category, shorter for enquiries and complaints
- Escalate to a named person, not to a group
- Escalation should also fire when the owner is marked out of office
- Review the escalation log weekly to find categories that are always late
The cases that must never get an automatic reply
An automatic reply to the wrong message is worse than no reply. A complaint that receives a cheerful template, a legal notice that receives a marketing sign-off, a bereavement that receives an opening-hours message: each is avoidable with a written exclusion list that overrides every other rule.
- Complaints and anything with a threat to leave or take action
- Legal, regulatory and insurance correspondence
- Anything about a death, illness or safety incident
- Messages from staff, contractors and suppliers about pay or contracts
A template library with an owner and a date
Templates decay. Prices change, hours change, a product is discontinued, and the template keeps sending the old answer. Every template needs a named owner and a review date, and the library needs one place where the current version lives.
- One template per safe auto-reply case, nothing generic
- Owner and last-reviewed date recorded on each template
- Anything with a price or a promise reviewed when either changes
- Retire templates that have not been sent in three months
Next Steps
Email Automation Setup Checklist
The four-stage rollout that puts these rules into production, starting with triage only.
Open the rollout checklist →AI Email Voice and Approval Checklist
Once triage is set, decide how drafted replies sound and what always needs a human.
Set the voice rules →Shared Inbox SLA Calculator
Check whether the owners you named have the hours to meet the response target.
Check the staffing →Frequently Asked Questions
Enough that every message has an obvious home and few enough that people can remember them. Most business inboxes settle between six and twelve. Fewer than that and the categories are too broad to route usefully. More than that and the boundaries blur, messages fit two categories and routing becomes arbitrary. Start with the categories that fall out of sorting a week of real mail by hand, merge anything that overlaps, and add a catch-all with a named owner for whatever is left.
A specific person, reviewed daily, with an age threshold that escalates anything left too long. The catch-all is where misclassified mail lands, so it needs more attention than any other category during the first months, not less. Track what ends up there. If the same kind of message keeps appearing, it needs its own category and rule. If the catch-all is empty for weeks, the rules are working.
Age is the most reliable trigger: any message past a threshold with no action goes to a second named person. Add content triggers for complaints, threats to leave, legal or regulatory senders and safety matters. Add a sender trigger for your most important customers. And add a thread trigger: a second message from the same sender on a thread with no reply is a strong signal that the first one was missed. Keep the list short enough that escalations are rare and acted on.
When the message is a narrow, predictable request with one correct answer that does not change by customer: an acknowledgement of receipt, opening hours, a document that is always the same, a confirmation that a form was received. Even then, include a way to reach a person. Anything involving a price, a commitment, a complaint, a dispute or personal circumstances should be drafted for a human to approve, or handled by a person from the start.
They can. Routing decides who in the business sees a message and which system processes it. If the inbox receives personal information, such as health details, financial circumstances or identity documents, check your obligations under the Privacy Act before routing that category to any third-party tool, and restrict who can see it inside the business. A separate sensitive category with a short owner list is a sensible default.
Weekly for the first month, then monthly. In the weekly review, look at what landed in the catch-all, what was escalated and what was misrouted. In the monthly review, retire categories that are empty, add categories for anything that keeps appearing in the catch-all, and check every template that mentions a price, a time or a policy. Name one person as the owner of the rule set, because an unowned rule set stops being reviewed within a few months.
Sources and further reading
- The Privacy Act 1988 (Office of the Australian Information Commissioner)
Got the Rules Written Down?
Send us your category list, owners and exclusion list. We will tell you what we would merge, what we would add and which cases we would never auto-reply to, before anything is switched on.