---
sourceDocument: Zurich IT Service Management
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/it-service-management

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich IT Service Management

ft:clusterId :

    - itsm

bundleId :

    - itsm

workflow :

    - Technology


---

# Post Incident Report tab

# Post Incident Report tab {#ariaid-title1}

Release version: Zurich  
Updated July 31, 2025  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Post Incident Report tab

The Post Incident Report tab in ServiceNow's Zurich release is designed to document and analyze major incidents by capturing their causes, resolution actions, and team responses.
This helps major incident managers and teams evaluate the incident handling process, identify lessons learned, and determine follow-up actions to improve future incident management.
Show full answer Show less  

## Key Features

* **Editable Report:** Major incident managers can edit the report once the incident reaches the Resolved state.
* **Report Sections:**
  * **Overview:** Summarizes the incident details.
  * **Findings:** Documents root causes and lessons learned.
  * **Resolution:** Details the steps taken to resolve the incident.
  * **Timeline:** Shows all related activities including communications and tasks, which can be updated by regenerating the timeline.
* **Integration with Problem and Change Management:** Allows adding or managing related Problem or Change records directly from the report.
* **Continual Improvement Management (CIM) Plugin Support:** When activated, displays related improvement records linked to the incident.
* **Report Generation and Download:** Managers can view a complete compiled report and download it as a PDF document.
* **Related Links on Incident Form:**
  * **Regenerate PIR Timeline:** Available to major incident managers when the incident is Resolved, to update the timeline.
  * **Preview PIR:** Available to itil role users when the incident is Resolved or Closed, to preview the report.
* **Incident Response Timeline Calculation:** The "Time to Identify" metric measures the duration from the earliest related alert or incident creation to when the incident is proposed or created as a major incident, depending on the workflow.

## Practical Benefits

By using the Post Incident Report tab, ServiceNow customers can systematically document major incidents, enhance transparency in incident resolution, and facilitate continuous improvement through clear visibility of causes and corrective actions. The PDF report and timeline regeneration features enable easy sharing and updating of incident insights with stakeholders.  
The Post Incident Report tab helps you to understand the cause of
the major incident, and the actions taken by the teams to resolve the incident.  
The teams can assess the incident response and resolution process and determine follow-up action items. The post incident report is required to record the actions performed, the reasons for doing them, and findings.  
Note:  
The major incident manager can edit a report when the incident is in the Resolved state.  
Figure 1. View of the Post Incident Report tab  
The post incident report includes the following sections where a major incident manager can provide required information:

* Overview: Summary of the incident.
* Findings: Information on what caused the major incident and any lessons learned in the process.
* Resolution: Information on the resolution steps taken to resolve the issue. The major incident manager can also add or edit any related Problem or Change information by clicking Add or Manage respectively.
* Timeline: Information of all the activity feeds, not only of the incident but also of the incident communication plan and incident communication tasks related to the incident. You can update the timeline with the latest activity by clicking Regenerate Timeline.  
  Note:  
  The information that you provide for Overview, Findings, and Timeline gets updated in the Post Incident Report section on the Incident form.
{#mi-workbench-pir-tab__ul_pfs_41g_hdb}

If you activate the Continual Improvement Management (CIM) plugin (com.sn_cim), the
Related Improvement Records section is displayed in the report. This section displays the
Inbound CIM Integrations records.

When you click View Complete Report, all the information entered by the
major incident manager is compiled together and you can download the report in the .PDF format
by clicking Download Report PDF.  
The following links appear in the Incident form under the Related Links section:

* Regenerate PIR Timeline: This link appears when incident is in the Resolved state and the user has the major_incident_manager role.
* Preview PIR: This link appears when incident is in the Resolved or Closed state and the user has the itil role.
{#mi-workbench-pir-tab__ul_h1k_kn4_vgb}  
Note:  
On the downloaded report, under Incident Response Timeline, the time displayed in the timing type Time to Identify is calculated in the following ways:

* If you propose the incident as a major incident: The time indicates the time from creation of the first related alert for this incident or creation of the incident (in case there is no alert or the Event Management plugin is inactive), whichever occurs first, until the time the incident is first proposed as a major incident.
* If you create a major incident directly: The time indicates the time from creation of the first related alert for this incident or creation of the incident (in case there is no alert or the Event Management plugin is inactive), whichever occurs first, until the time the incident is promoted as a major incident.
{#mi-workbench-pir-tab__ul_cqg_qwd_5gb}
**Related concepts**   

* [Major Incident workbench --- Summary tab](https://www.servicenow.com/docs/W20USP2Ux~b_7hl1Kr060Q "The Summary tab provides a unified view of information in the form of a card layout. The information on impacted services, affected CIs, active outages, locations that are impacted, and child incidents helps to keep you informed about related records associated with an incident.")
* [The Communicate tab in the Major Incident workbench](https://www.servicenow.com/docs/aK1HM_a7q3MQa~AVKSeyBg "The Communicate tab helps you understand the progress of a communication plan and its related tasks.")
* [Major Incident workbench --- the Collaborate tab](https://www.servicenow.com/docs/yD9PlrV2Is9gqhQzY6MCXA "The Collaborate tab helps you to view and manage communication tasks that use conference as their communication channel.")  
**Related tasks**   

* [Associate a new post incident report](https://www.servicenow.com/docs/qNPsLPnsnLhR5Fig_xonnw "Create your own post incident report and associate the UI page with the View Complete Report button under the Post Incident Report tab. Using the customized report, you can add information that is specific to your organization.")

