---
sourceDocument: Zurich IT Service Management
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/it-service-management

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich IT Service Management

ft:clusterId :

    - itsm

bundleId :

    - itsm

workflow :

    - Technology


---

# Post Incident Report tab

# Post Incident Report tab {#ariaid-title1}

Release version: Zurich  
Updated July 31, 2025  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read  
The Post Incident Report tab helps you to understand the cause of
the major incident, and the actions taken by the teams to resolve the incident.  
The teams can assess the incident response and resolution process and determine follow-up action items. The post incident report is required to record the actions performed, the reasons for doing them, and findings.  
Note:  
The major incident manager can edit a report when the incident is in the Resolved state.  
Figure 1. View of the Post Incident Report tab  
The post incident report includes the following sections where a major incident manager can provide required information:

* Overview: Summary of the incident.
* Findings: Information on what caused the major incident and any lessons learned in the process.
* Resolution: Information on the resolution steps taken to resolve the issue. The major incident manager can also add or edit any related Problem or Change information by clicking Add or Manage respectively.
* Timeline: Information of all the activity feeds, not only of the incident but also of the incident communication plan and incident communication tasks related to the incident. You can update the timeline with the latest activity by clicking Regenerate Timeline.  
  Note:  
  The information that you provide for Overview, Findings, and Timeline gets updated in the Post Incident Report section on the Incident form.
{#mi-workbench-pir-tab__ul_pfs_41g_hdb}

If you activate the Continual Improvement Management (CIM) plugin (com.sn_cim), the
Related Improvement Records section is displayed in the report. This section displays the
Inbound CIM Integrations records.

When you click View Complete Report, all the information entered by the
major incident manager is compiled together and you can download the report in the .PDF format
by clicking Download Report PDF.  
The following links appear in the Incident form under the Related Links section:

* Regenerate PIR Timeline: This link appears when incident is in the Resolved state and the user has the major_incident_manager role.
* Preview PIR: This link appears when incident is in the Resolved or Closed state and the user has the itil role.
{#mi-workbench-pir-tab__ul_h1k_kn4_vgb}  
Note:  
On the downloaded report, under Incident Response Timeline, the time displayed in the timing type Time to Identify is calculated in the following ways:

* If you propose the incident as a major incident: The time indicates the time from creation of the first related alert for this incident or creation of the incident (in case there is no alert or the Event Management plugin is inactive), whichever occurs first, until the time the incident is first proposed as a major incident.
* If you create a major incident directly: The time indicates the time from creation of the first related alert for this incident or creation of the incident (in case there is no alert or the Event Management plugin is inactive), whichever occurs first, until the time the incident is promoted as a major incident.
{#mi-workbench-pir-tab__ul_cqg_qwd_5gb}
**Related concepts**   

* [Major Incident workbench --- Summary tab](https://www.servicenow.com/docs/W20USP2Ux~b_7hl1Kr060Q "The Summary tab provides a unified view of information in the form of a card layout. The information on impacted services, affected CIs, active outages, locations that are impacted, and child incidents helps to keep you informed about related records associated with an incident.")
* [The Communicate tab in the Major Incident workbench](https://www.servicenow.com/docs/aK1HM_a7q3MQa~AVKSeyBg "The Communicate tab helps you understand the progress of a communication plan and its related tasks.")
* [Major Incident workbench --- the Collaborate tab](https://www.servicenow.com/docs/yD9PlrV2Is9gqhQzY6MCXA "The Collaborate tab helps you to view and manage communication tasks that use conference as their communication channel.")  
**Related tasks**   

* [Associate a new post incident report](https://www.servicenow.com/docs/qNPsLPnsnLhR5Fig_xonnw "Create your own post incident report and associate the UI page with the View Complete Report button under the Post Incident Report tab. Using the customized report, you can add information that is specific to your organization.")

