IT Service Management AI agent collection Triage and categorize ITSM incidents agentic workflow
Summarize
Summary of IT Service Management AI Agent Collection: Triage and Categorize ITSM Incidents Agentic Workflow
The Triage and categorize ITSM incidents agentic workflow in ServiceNow automates the assignment of incident categories, subcategories, related services, service offerings, configuration items (CIs), and links major incidents or known problems to incidents. This AI-powered workflow streamlines incident triaging to improve accuracy and efficiency by leveraging multiple AI agents that autonomously update incident records based on the incident’s short description and context.
Show less
Key Features
- Automated Categorization: Assigns incident categories and subcategories using AI based on the incident’s short description.
- Service and Configuration Item Classification: Automatically links the incident to the relevant service, service offering, and configuration item (CI).
- Major Incident and Problem Linking: Searches for related major incidents or ongoing problems and links them to the current incident, enabling faster resolution and better incident management.
- Trigger Configuration: Supports both automatic and manual triggers based on incident state, assignment, and priority to initiate the workflow.
- AI User Configuration: The workflow runs under a configurable AI agent user with assigned roles to ensure secure and appropriate execution.
- Plugin Requirement: Requires activation of the Incident Management - Major Incident Management plugin to enable major incident linking.
- Customization: The workflow can be duplicated and modified to meet specific organizational needs; semantic indexing for the Problem table must be enabled when modifying the workflow.
How it Works for ServiceNow Customers
When an incident is created or updated meeting trigger conditions, the workflow executes a sequence of AI agents:
- Categorize ITSM Incident AI Agent: Updates the Category and Subcategory fields and adds work notes.
- Classify Service and CI AI Agent: Assigns Service, Service Offering, and Configuration Item fields and appends comments and work notes.
- Link Major Incident or Problem AI Agent: Links related major incidents or known problems to the incident and updates additional comments.
Users receive category recommendations through the ServiceNow AI Agent Studio interface and can complete incident triaging efficiently. The workflow runs autonomously and does not require manual input during execution.
Practical Benefits
- Improved Incident Handling: Reduces manual effort and human error in incident categorization and linking to related records.
- Faster Resolution: By automatically linking related major incidents and problems, it helps prioritize and address critical incidents promptly.
- Consistent Data Quality: Ensures standardized classification and association of incidents with services and CIs.
- Integration with ServiceNow Tools: Works seamlessly with AI Agent Studio and Otto panel for enhanced user interaction and incident management.
Use the Triage and categorize ITSM incidents AI agent team to assign incident categories and subcategories. Then, assign the service, service offering, and the configuration items (CI), and also link major incidents, and known problems autonomously.
Triage and categorize ITSM incidents agentic workflow overview
Using the Triage and categorize ITSM incidents agentic workflow, autonomously assign incident categories by assigning a category and a subcategory to incidents based on the incident short description. After categorizing the incident, assign the service, service offering, and configuration item (CI) related to the incident. Then, automatically link incidents to major incidents or known problems.
Triage and categorize ITSM incidents agentic workflow
- Automatically categorizes the incidents.
- Then, assigns the related service, service offering, and configuration item (CI).
- Then, searches for related major incidents and if found, links them to the incident.
- If no major incidents are found, then it searches for related problems, and if found, links them to the incident.
- Navigate to .
- Select Triage and categorize ITSM incidents.
Setting automatic or manual triggers for the agentic workflow
| Type of trigger | Field values |
|---|---|
| Automatic |
|
|
|
| Manual |
|
Setting the AI user as the Run as user
The ITSM Worker AI Agent user record is of identity type AI agent and is available by default. You can create users of this type and assign roles to the users based on your needs.
- Navigate to the Define key requirements screen.
- Go to the Select the entity this agentic workflow will run as section.
- In the Run as field, select AI user.
- In the AI user field, select the desired AI agent user.
AI agents used in the Triage and categorize ITSM incidents agentic workflow
The Triage and categorize ITSM incidents agentic workflow uses a team of AI agents to automatically categorize incidents, then assign the service, service offering, and configuration item (CI) related to the incident and then links associated major incidents or known problems.
| AI agent | AI agent role |
|---|---|
| Categorize ITSM incident AI agent | Automatically assigns incidents to categories, and subcategories, based on the incident's short description. |
| Classify service and CI AI agent | Automatically assigns service, service offerings, and configuration items (CI) to the incidents. |
| Link major incident or problem AI agent |
Important:
To search for related major incidents, you must activate the Incident Management - Major Incident Management plugin (com.snc.incident.mim). For more information, see Activate Major Incident Management.
|
Assigning incident categories
- Review the information in the Describe and connect screen and in the Define trigger screen. Make the necessary updates, and then select Save and Continue.
- In the Select display screen:
- Choose where you want the agentic workflow output to be displayed.
- Use the arrow next to the display option to add roles that can access the agentic workflow.Note:The itil role is added by default.
- Select Save and test.
The agent executes the request for the agentic workflow.
In the AI Agent Studio, the human agent gets notified as soon as the category recommendation is generated so that they can follow the on-screen instructions and complete the task. For more information, see Request the generative AI capabilities in ITSM by using the ServiceNow Otto panel.
Automate the categorizing an incident, then automatically link them to major incidents or known problems in the Otto panel
When an incident is updated and the trigger conditions are met, an execution plan is created. The incident fields are updated based the execution by each AI agent.
- Enter a message in the Otto panel, such as, "triage incident INC0010010".
All executions are autonomous and the AI agent does need user inputs in any of the steps during the execution.
- The first AI agent, which is the Categorize ITSM incident AI agent does the following:
- Updates the following fields in the incident record after the execution:
- Category
- Sub-category
- Updates any changes in the Work notes field.
The orchestrator then moves to the next available agent.
- Updates the following fields in the incident record after the execution:
- The second agent, which is the Classify Service and CI AI agent updates the following fields in the incident record after the execution:
- Service
- Service offering
- Configuration item
- The third agent, which is the Link major incident or problem AI agent updates the parent incident or problem field in the incident's related record. The AI agent updates the changes in the Additional comments field.
- The Categorize ITSM incident AI agent populates the Category and Subcategory fields.
- The Classify service and CI AI agent populates the Service, Service offering, and Configuration items fields.
- The Link major incident or problem AI agent populates the Parent incident or the Problem field.