Incident Management in Service Operations Workspace

  • Release version: Australia
  • Updated March 12, 2026
  • 3 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Incident Management in Service Operations Workspace

    Incident Management within Service Operations Workspace (SOW) enables you to efficiently create, manage, investigate, communicate, and resolve incidents. The workspace provides a structured incident record page organized into multiple tabs to support end-to-end incident handling. This functionality is essential for ServiceNow customers seeking to streamline incident resolution and improve service reliability.

    Show full answer Show less

    Key Features

    • Overview Tab: Displays key incident details such as Summary, Impact, Cause, and Resolution. Allows adding comments and work notes to facilitate communication. The layout is customizable to suit your operational needs.
    • Investigation Tab: Helps analyze affected Configuration Items (CIs) with classes cicomputer or ciserver by displaying real-time metrics. Supports remedial actions to resolve CI issues, requiring Agent Client Collector (ACC) or Microsoft Endpoint Configuration Manager (MECM) adapters and supports macOS, Windows, and Linux systems. Display customization is available.
    • Communicate Tab: Facilitates communication with stakeholders during incident phases. Available when Major Incident Management or Task/Incident Communications Management plugins are active and configured, enabling structured communication workflows.
    • Post Incident Report Tab: Available for major incidents once resolved, this tab allows generation and publication of reports to review causes, resolutions, and identify process improvements, supporting continuous improvement efforts.
    • Details Tab: Shows detailed incident information including descriptions, assignments, and related records, with configurable fields for tailored views.
    • Related Records Tab: Lists all records tied to the incident, such as task SLAs and affected CIs, providing a comprehensive context.
    • Contextual Side Panel: Offers quick access to record information, expert collaboration through Microsoft Teams, and recommendations to accelerate incident resolution.

    Practical Usage

    • Create and manage incidents directly in SOW, with the ability to initiate related tasks like problems, changes, or service requests from the incident record.
    • Use the Investigation tab’s Playbook remedial actions to resolve CI-related issues efficiently.
    • Close incidents once satisfactorily resolved and reopen them if necessary from within the workspace.
    • Track incident progress and updates via the incident list page and contextual side panel for enhanced situational awareness.

    Configuration and Requirements

    Some tabs and features require specific configurations or plugins:

    • Investigation tab requires ACC or MECM adapters installed and configured.
    • Communicate tab requires Major Incident Management or Communications Management applications activated and configured.
    • Post Incident Report tab is available only when Major Incident Management is active and the incident is resolved.

    Benefits and Outcomes

    Using Incident Management in Service Operations Workspace helps your organization:

    • Improve incident resolution speed and accuracy with integrated metrics and remedial actions.
    • Enhance stakeholder communication through structured communication options.
    • Gain insights from post-incident analyses to prevent future occurrences and optimize processes.
    • Maintain comprehensive incident records with easy navigation and collaboration tools.

    You can create and manage your incidents in Service Operations Workspace.

    Figure 1. Tabs of an incident record page in Service Operations Workspace
    Tabs of an incident record

    Overview tab

    This tab displays the following information about an incident:
    • Summary
    • Impact
    • Cause
    • Resolution

    From the Compose section, you can add comments and work notes for the incident.

    The Overview tab displays the field information along with the field labels, including when you're in read mode.

    For more information on the fields displayed on the Overview tab, see View and update incident information on the Overview tab.

    You can customize the display of the information on the Overview tab. For more information, see Customize the Overview tab for an incident.

    Investigation tab

    This tab enables you to investigate any affected CIs with the ci_computer or ci_server class associated with the incidents. The tab displays the metrics information of the associated primary CI or any affected CI that is selected, which helps you to analyze and resolve the issue. You can use the various remedial actions on this tab to resolve the CI-related issues.

    By default, the tab displays metrics information of the primary affected CI associated with the incident. But you can also select and view the information for any affected CI with the ci_computer or ci_server class that is associated with the incident. For information about how you can set up Investigation Framework, see Setting up Investigation Framework in Service Operations Workspace.

    Note:
    • The tab is visible only if the Agent Client Collector (ACC) or Microsoft Endpoint Configuration Manager (MECM) adapters are installed and configured.
    • The tab displays the metrics information for the CI only in the following conditions:
      • Agent Client Collector or Microsoft Endpoint Configuration Manager (MECM) is installed for the associated CI. This helps to retrieve the metrics data for the CI.
      • The associated CI class is a CMDB CI computer.
    • This feature supports only the macOS, Windows, and Linux operating systems.

    You can also customize the display of the metrics information on this tab. For more information, see Customize the Investigate tab.

    For more information on the metrics displayed on this tab, see Features of the Investigation tab.

    Communicate tab

    This tab displays all the communication tasks and options that enable you to communicate with the stakeholders in the various phases of an incident. This tab is available only if any of the following conditions are met:For more information on the features of the Communicate tab, see Communicating with stakeholders about incidents and major incidents in SOW.

    Post incident report tab

    This tab enables you to generate, configure, publish, and export a post incident report for a major incident after it's resolved. The post incident report enables you to review the cause and resolution of the major incident and also identify potential process gaps. Based on this information, you can take preventive measures to avoid the issue in the future or to handle the major incident in a better way. This tab is available only if the following conditions are met:For more information on the features of the Post incident report tab, see Review and update a post incident report.

    Details tab

    This tab displays detailed information about the incident. For example, the short description, assignment details, and related records. For more information on how you can configure fields in this tab, see Configure a task record form in Service Operations Workspace.

    Related records tab

    This tab provides a list view of the records associated with the incident. For example, task SLAs and affected CIs.

    Contextual side panel

    From this section, you can view record information and recommendations, collaborate using Microsoft Teams, and reach out to experts on-call to resolve incidents quickly.

    For more information about Incident Management, see Incident Management.