Some PDIs are currently unavailable, and PDI actions are paused. View the latest updates here. Read More

Incident Closure: Manual Close vs Auto-Close

Not applicable

Hello All,

 

In a Zurich OOTB implementation, incidents are automatically closed after "x" business days in the Resolved state.

However, analysts do not have access to either:

  • a Close Incident action;
  • a Closed state transition.

Is this considered standard behaviour in Agent Workspace, or is this normally a configurable design choice?

In previous ServiceNow implementations, we have seen both mechanisms coexist:

  • analyst-driven closure;
  • automated closure after a defined period.

Is there any ServiceNow best practice that recommends preventing analysts from manually closing incidents altogether?

Thank in advance

Daniel

1 ACCEPTED SOLUTION

pavani_paluri
Kilo Sage

Hi @Community Alums ,

 

Yes, what you're seeing can be considered OOTB behavior in recent ServiceNow releases, including Agent Workspace/Service Operations Workspace configurations where incidents move from Resolved to Closed automatically after a defined period. In many implementations, analysts are intentionally not given a direct transition to Closed.

The rationale is that Resolved represents "work completed by IT," while Closed represents the end of the incident lifecycle after allowing the caller or business users time to confirm the resolution. Auto-close helps ensure a consistent waiting period before final closure.

That said, this is ultimately a design choice rather than a strict platform requirement. Many organizations enable both:

  • Analyst-driven closure (manual Close action/state transition)
  • Automatic closure after a configurable number of days in Resolved

Both approaches are commonly used depending on operational requirements.

 

From a best-practice perspective, ServiceNow generally promotes:

  • Resolve the incident when the technical work is complete.
  • Allow a validation period for the user.
  • Automatically close if no further action is required.

The goal is to avoid premature closure and provide an opportunity for reopening if the issue persists.

 

However, there is no universal best practice that says analysts must never manually close incidents. Organizations with mature support processes often permit manual closure for specific groups, scenarios, or service desk roles when appropriate.

 

Therefore, if your analysts do not have a Close Incident action or a Closed state transition, I would interpret that as an implementation/configuration decision aligned with the resolved-to-auto-close model, rather than a hard ServiceNow platform limitation.

 

Mark it helpful if this helps you to understand. Accept solution if this give you the answer you're looking for
Kind Regards,
Pavani P

View solution in original post

1 REPLY 1

pavani_paluri
Kilo Sage

Hi @Community Alums ,

 

Yes, what you're seeing can be considered OOTB behavior in recent ServiceNow releases, including Agent Workspace/Service Operations Workspace configurations where incidents move from Resolved to Closed automatically after a defined period. In many implementations, analysts are intentionally not given a direct transition to Closed.

The rationale is that Resolved represents "work completed by IT," while Closed represents the end of the incident lifecycle after allowing the caller or business users time to confirm the resolution. Auto-close helps ensure a consistent waiting period before final closure.

That said, this is ultimately a design choice rather than a strict platform requirement. Many organizations enable both:

  • Analyst-driven closure (manual Close action/state transition)
  • Automatic closure after a configurable number of days in Resolved

Both approaches are commonly used depending on operational requirements.

 

From a best-practice perspective, ServiceNow generally promotes:

  • Resolve the incident when the technical work is complete.
  • Allow a validation period for the user.
  • Automatically close if no further action is required.

The goal is to avoid premature closure and provide an opportunity for reopening if the issue persists.

 

However, there is no universal best practice that says analysts must never manually close incidents. Organizations with mature support processes often permit manual closure for specific groups, scenarios, or service desk roles when appropriate.

 

Therefore, if your analysts do not have a Close Incident action or a Closed state transition, I would interpret that as an implementation/configuration decision aligned with the resolved-to-auto-close model, rather than a hard ServiceNow platform limitation.

 

Mark it helpful if this helps you to understand. Accept solution if this give you the answer you're looking for
Kind Regards,
Pavani P