NexaWorks
nexaworks
Signal library

Signals in Support tickets · 7 signals

The churn signals hiding in support tickets.

Zendesk, Intercom, Freshdesk — the support queue is where frustration shows up first, in writing.

Why this source matters

Written frustration is deliberate — the customer chose those words and hit send. Tickets are timestamped, categorized, and already structured, which makes them the cheapest source to instrument and the hardest for anyone to argue with.

Support ticketsTypical lead time: 30–90 daysFalse-positive risk: Medium

Ticket volume spike vs baseline

Ticket volume runs at 2x or more of the account's rolling baseline. Volume alone doesn't predict churn — but a sustained spike means the product is consuming the customer's week, and patience is finite.

Detection logic

Compare tickets opened in the last 30 days against the account's 6-month rolling average. Flag at 2x; escalate if the spike persists into a second month.

When it lies to you

New rollouts, migrations, and known platform incidents spike every affected account. Exclude incident-tagged tickets before computing the baseline.

Support ticketsTypical lead time: 30–60 daysFalse-positive risk: Low

Severity mix shifts up

The share of P1/P2 tickets rises even if total volume is flat. Customers escalate severity when they stop believing normal channels will fix it — that's a trust signal, not a volume signal.

Detection logic

Track the percentage of tickets marked high/critical per account per month. Flag a sustained 2x increase in share over the account's baseline.

When it lies to you

A single outage generates a burst of P1s across accounts. Require the shift to persist beyond the incident window.

Support ticketsTypical lead time: 30–90 daysFalse-positive risk: Low

Reopened tickets climb

The same issues get reopened — the customer is telling you the fix didn't hold. Reopens are the support metric most correlated with “we've lost confidence in this vendor.”

Detection logic

Count tickets reopened 2+ times per account per quarter. Flag at 3+ reopens; weight reopens on issues the customer marked “resolved” themselves.

When it lies to you

Genuinely complex integrations produce legitimate reopens. Distinguish “fix didn't hold” reopens from “new symptom discovered” ones.

Support ticketsTypical lead time: 14–60 daysFalse-positive risk: Medium

"How do I export my data" tickets

Tickets asking about data export, cancellation process, contract end dates, or API access for migration. Customers planning to leave ask how to take their data with them first.

Detection logic

Intent-classify tickets for export, cancellation, migration, and contract-end topics. Any single hit deserves a human look; two in a quarter is a pattern.

When it lies to you

Security reviews and data-residency audits generate export questions with zero churn intent. Check the requester's role — compliance teams ask differently than admins.

Support ticketsTypical lead time: 60–120 daysFalse-positive risk: Medium

Ticket sentiment turns negative

CSAT scores drop and negative language in ticket threads trends up over a quarter. Written frustration is deliberate — the customer chose those words.

Detection logic

Trend CSAT and text-sentiment per account over 90 days. Flag sustained declines; pair with volume to separate “angry and loud” from “quietly gone.”

When it lies to you

One bad support interaction or one difficult agent can tank a quarter's CSAT. Check agent-level distribution before blaming the account.

Support ticketsTypical lead time: 30–90 daysFalse-positive risk: Low

SLA breaches cluster on one account

First-response or resolution SLA breaches concentrate on a single account while others stay clean. The account is experiencing a worse product than everyone else — and noticing.

Detection logic

Compare SLA breach rate per account against the portfolio average. Flag accounts running 3x the average over 60 days.

When it lies to you

Understaffed support pods breach SLAs broadly — check whether the cluster is account-specific or pod-wide before flagging.

Support ticketsTypical lead time: 60–120 daysFalse-positive risk: High

Champion shifts to transactional channels

The champion stops calling the CSM and starts filing tickets instead. The relationship is being downgraded from partnership to vendor — quietly, through channel choice.

Detection logic

Compare the champion's ticket-filing rate vs direct CSM touch rate over time. Flag when ticket share of their interactions doubles from baseline.

When it lies to you

Some champions genuinely prefer async written channels. Establish the individual's baseline before reading intent into the shift.

How to instrument it

Volume vs the account's own baseline, severity mix over time, reopen counts, intent classification on cancellation-adjacent topics, and CSAT trend. The five queries cover 90% of ticket signal value. Always exclude incident-tagged tickets from baselines.

Common pitfalls

One platform outage skews every account at once — check account-specificity before flagging. CSAT suffers response bias (the angriest reply most). And tag hygiene decides everything: garbage tags in, garbage signals out.

Signals in the other sources

Get your free Account Risk Snapshot

We run signals like these against your 20 riskiest accounts — before you sign anything.