Usually two things: how quickly you will first respond, and how quickly you will resolve. Response is within your control; resolution frequently is not.
Promising a resolution time on issues that depend on a third party is how SLAs get breached for reasons nobody could have prevented.
A four-hour response clock that runs through the night is a promise to staff overnight. Either you mean that or the clock should pause outside business hours.
This single configuration decision causes more meaningless breach reports than anything else, and it is usually a default nobody revisited.
Cautiously. Resolution often depends on third parties you do not control.
Only if you staff overnight. Otherwise business hours should pause them.
Waiting on the customer, always. Waiting on a third party is a decision to make explicitly.
Half an hour with your own data usually saves reading three of these. The guides will still be here afterwards.