Some PDIs are currently unavailable, and PDI actions are paused. View the latest updates here. Read More

Michael Hansen
ServiceNow Employee

Derek Kitzleman, ITOM Outbound Product Manager Moving day is deceptively simple. The truck shows up, the boxes go in, and for about twenty-four hours you feel like you've accomplished something. Then reality sets in. You don't actually know where the breaker box is. You find a room you'd forgotten the last owners converted into a workshop. Something in the garage is plugged into an outlet you can't account for, and it takes you three weeks to figure out it's the sump pump.

 

None of that is a flaw in the house. It's just what happens when you inherit something complex and don't get a proper walkthrough. 

 

IT organizations move into new infrastructure constantly — new cloud accounts, new AI platforms, new SaaS tools your own employees signed up for without telling anyone. ITOM Visibility exists to give you that walkthrough: what's actually here, what it's connected to, and what to do the moment something stops working. This quarter's release is mostly about shortening the gap between moving in and actually knowing your way around.

 

It's always move day for IT infrastructure

 

 

Getting the lights on without hunting for the breaker box

 

Buying ITOM should feel like moving into a furnished house. Too often it feels like moving into an empty one, with the furniture sitting in a warehouse somewhere and no instructions for assembly. Customers license Discovery and Event Management, and then spend weeks figuring out how to actually turn them on.

 

The new ITOM Product Hub is the breaker box, labeled. It's a single place to install, update, and maintain every ITOM Visibility and AIOps app you're entitled to, with one-click promotion from sub-prod to production and built-in enablement content so you're not hunting through community forums for the right video.

 

Sitting next to it is the Configuration Console, which walks you step by step through setting up Discovery and Event Management — the two areas where customers historically stall out before ever reaching the more advanced capabilities. June's release adds Now Assist–guided configuration for Alert Grouping, so even that setup step gets a coach standing next to you instead of a manual. Every change is tracked automatically, so you always know what got flipped and when.

 

Together, these two features solve the same problem from two angles: less time between buying the house and actually living in it.

 

MichaelHansen_1-1785184120232.png

 

 

Finding out what's plugged in that you didn't approve

 

Every house has an outlet nobody remembers wiring. In IT, that outlet is Shadow AI — the SaaS tools and AI assistants your employees are already using in their browser, invisible to any inventory you've built.

 

MichaelHansen_2-1785184484903.png

 

ITOM URL Discovery plugs that gap using the ACC browser extension, which is optional and privacy-conscious by design — it only monitors admin-whitelisted URLs, and nothing runs without explicit configuration. What comes back is genuinely useful: accessed domains by category, the most-visited tools, usage broken down by role and device. All of it normalizes straight into ITOM and CMDB, so for the first time you can answer a governance question about AI adoption with actual data instead of a shrug.

 

There's a practical payoff here too. A good chunk of shadow SaaS turns out to be redundant licenses nobody's using. Finding that is the difference between guessing at a SaaS budget and actually managing one.

 

 

The irrigation system still running on a previous schedule

 

New homeowners often discover that the sprinklers come on every night at 5 a.m., right on schedule, controlled by an app they've never opened, tied to an account that isn't theirs. Nothing about the house told them this existed. It only surfaces because the water bill is higher than it should be, or a system update quietly breaks it.

 

MichaelHansen_3-1785184815678.png

 

AI agents will be the next household automation account.  They'll have the same habit of showing up somewhere and just... running. A team spins one up in AWS Bedrock or Azure AI Foundry, it works, and months later nobody outside that team knows it's there — let alone what it's connected to or what depends on it. It's not malicious. It's just how fast AI development moves compared to how fast governance catches up.

 

AI Agent Topology Mapping is the walkthrough that finds the controller, figures out whose account it's on, and maps what it's wired into. It natively discovers AI agents and models running in AWS Bedrock and Azure AI Foundry, populates them into the CMDB as proper CI records, and traces what each one connects to, depends on, and would take down if it failed.

 

That distinction matters because service-graph-style discovery shouldn't just tell you an asset exists without telling you how it fits into anything. Topology mapping gives you the actual wiring diagram: agents and models sitting in Service Maps and Asset Inventory right alongside the infrastructure you already track, ready for impact analysis and cost allocation instead of running quietly on someone else's account.

 

An electrician who tells you what's actually wrong

 

Anyone who's ever had a contractor open a wall and go quiet for a long time knows the feeling: something's wrong, and you're about to get a very expensive explanation of what. Discovery troubleshooting has traditionally worked the same way — an attribute doesn't populate, and the fix means someone manually digging through nested JSON logs or escalating to engineering for what turns out to be a two-minute problem.

 

MichaelHansen_4-1785185148028.png

 

The AI Agent for Discovery, now in controlled availability, is the electrician who actually explains the problem before touching anything. Ask it why an attribute didn't populate, and it identifies the specific pattern step at fault, the CIs affected, and the root-cause error, then hands back a structured remediation path. At this stage, it works in exploratory mode, one attribute per session, but it turns what used to be a multi-hour investigation into a conversation — and it's a clear preview of where discovery troubleshooting is headed as it moves toward broader availability.

 

The renewal notice that finds you instead of the other way around

 

Every homeowner inherits a maintenance calendar they didn't write — the HVAC service contract, the flood insurance renewal, the warranty that lapses if nobody calls in time. Certificates work the same way: always due again eventually, easy to forget until one expires and takes an application down with it. Large certificate inventories make that worse, because tracking renewals means checking a workspace nobody logs into unless something's already gone wrong.

 

MichaelHansen_5-1785186103283.png

 

Certificate Task Fulfillment via MS Teams brings that reminder to where people already are, instead of waiting for them to go check the workspace. Certificate Inventory and Management can now post a proactive notification directly in Microsoft Teams when a certificate needs attention, and owners can trigger the renewal from that conversation.

 

It's worth being precise about scope here: at this stage it's task notifications and renewal triggers — an alert with an action button, not a full working session inside Teams. A more complete chat-based experience is planned for a future release. What ships now still removes a real piece of friction: nobody has to remember to go check a workspace that only matters once a year.

 

Two other additions round out certificate handling this quarter, and they're worth naming separately even though they land in the same release. Support for Venafi-managed certificates connects Certificate Inventory and Management directly to CyberArk's Venafi platform, so organizations already standardized on Venafi for certificate authority and CSR generation can request, renew, and revoke certificates without leaving ServiceNow — no more switching tools mid-workflow to get a renewal actually issued. Azure Key Vault Integration, separately, gives private keys generated during fulfillment a secure place to live instead of sitting wherever they landed. It's foundational work at this stage — full automation of that storage step is coming in a future release — but it's the piece that has to exist before anything downstream can build on top of it.

 

Broader Impact

 

Any one of these six things would be a solid release on its own. A labeled breaker box. A step-by-step setup guide. A browser extension that surfaces shadow AI. A CMDB record for an agent no one knew was running. A Teams notification for a certificate. A diagnostic assistant that explains itself.

 

Together, they show where ServiceNow is putting its effort this quarter: the fundamentals of IT operations. Knowing what you have. Making it easy to act on that knowledge instead of hunting for it. That's not a new mission, but it's an easy one to underinvest in, because discovery work rarely gets noticed until it's missing. This release is six separate proofs that it's getting the attention it deserves.

 

That matters because governance, cost control, and AI oversight all depend on visibility that actually holds up. You can't govern an agent you don't know exists. You can't control spend on a SaaS tool nobody logged. Every capability here removes one more place where "I'm not sure" was an acceptable answer.

 

 

 

MichaelHansen_7-1785187129432.png

 

 

Closing Reflection

 

There are two ways to own a house.

 

In one, every project starts with guesswork — which wire feeds which breaker, whether that wall is load-bearing, why the water pressure dropped. You figure it out through five years of trial and error, one surprised phone call to a contractor at a time.

 

In the other, you have the facts before you start. You know where the panel is, what's on each circuit, what's been touched and when. The project still takes work. But it starts from knowledge instead of guessing.