---
sourceDocument: Australia IT Service Management
sourceDocumentLink: https://www.servicenow.com/docs/r/it-service-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia IT Service Management

ft:clusterId :

    - itsm

bundleId :

    - itsm

workflow :

    - Technology


---

# Incident Management in Service Operations Workspace

# Incident Management in Service Operations Workspace {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Incident Management in Service Operations Workspace

Incident Management in Service Operations Workspace (SOW) enables ServiceNow customers to efficiently create, manage, investigate, communicate, and resolve incidents within a unified interface.
It is designed to streamline incident handling by providing multiple specialized tabs that display key incident details, facilitate investigation of affected configuration items (CIs), manage communications with stakeholders, and generate post-incident reports for continuous improvement.
Show full answer Show less  

## Key Features

* **Overview Tab:** Displays essential incident details including summary, impact, cause, and resolution. Users can add comments and work notes here. This tab supports customization to tailor the incident view to business needs.
* **Investigation Tab:** Allows investigation of affected CIs (specifically cicomputer or ciserver classes) by showing relevant metrics from Agent Client Collector (ACC) or Microsoft Endpoint Configuration Manager (MECM). This helps in diagnosing and resolving issues related to primary or other selected affected CIs on supported operating systems (macOS, Windows, Linux). This tab is visible only when ACC or MECM adapters are configured.
* **Communicate Tab:** Provides tools to communicate with stakeholders during various incident phases. Available when Major Incident Management is active or communication management applications are installed, enabling structured communication workflows for both regular and major incidents.
* **Post Incident Report Tab:** Enables generation, configuration, publication, and export of post incident reports for major incidents once resolved. This supports analysis of root causes, resolutions, and identification of process gaps to improve future incident handling.
* **Details and Related Records Tabs:** Display comprehensive incident information such as assignment details, descriptions, and related records including task SLAs and affected CIs, facilitating deeper context for incident management.
* **Contextual Side Panel:** Offers quick access to caller and asset information, collaboration tools like Microsoft Teams, and expert on-call contacts to accelerate incident resolution.
* **Incident Lifecycle Management:** Includes creation of incidents, tracking investigations, applying remedial actions through playbooks, closing resolved incidents, and reopening incidents if necessary. Incidents can be linked to problem records, change requests, or service requests directly from the incident record.

## What This Enables You To Do

* Manage incidents end-to-end within a single workspace, improving efficiency and visibility.
* Analyze and resolve incidents faster by investigating affected CIs with real-time metrics and remedial actions.
* Communicate effectively with stakeholders using integrated communication workflows tailored for incident and major incident scenarios.
* Leverage post incident reports to learn from major incidents and enhance processes to prevent recurrence.
* Customize views and workflows to align with specific organizational requirements and improve user experience.
* Collaborate seamlessly with internal teams and experts to accelerate resolution times.

## Practical Considerations

* To access the Investigation tab and related CI metrics, Agent Client Collector or MECM adapters must be installed and configured.
* Major Incident Management plugin must be activated and configured to use major incident communication and post incident report features.
* Customization options are available for the Overview and Investigation tabs to tailor incident data presentation.
* Incident records support creating related problem, change, or service request tasks to streamline ITSM processes.

By leveraging Incident Management in Service Operations Workspace, ServiceNow customers can expect improved incident handling efficiency, enhanced communication, and better insights for continuous service improvement.  
You can create and manage your incidents in Service Operations Workspace.

Figure 1. Tabs of an incident record page in Service Operations Workspace

## Overview tab {#incident-sow__section_nmr_wsq_5sb}

This tab displays the following information about an incident:

* Summary
* Impact
* Cause
* Resolution
{#incident-sow__ul_swm_ptq_5sb}

From the Compose section, you can add comments and work notes for the incident.

The Overview tab displays the field information along with the field labels, including when you're in read mode.

For more information on the fields displayed on the Overview tab, see [View and update incident information on the Overview tab](https://www.servicenow.com/docs/6ZJ5lZc63TAqEOfGcrEQHg "View and update the incident information, such as summary, impact, cause, and resolution, from the Overview tab. This incident information helps you analyze the issue and resolve the incident quickly.").

You can customize the display of the information on the Overview tab. For more information, see [Customize the Overview tab for an incident](https://www.servicenow.com/docs/NxOtbf6LUBNU84sL3lR~nA#customize-overview-tab-incident-sow "Modify the Overview tab of an incident record page to display the summary and other information of the incident for an agent.").

## Investigation tab {#incident-sow__section_fyn_kvn_b5b}

This tab enables you to investigate any affected CIs with the ci_computer or ci_server class associated with the incidents. The tab displays the metrics information of the associated primary
CI or any affected CI that is selected, which helps you to analyze and resolve the issue. You can use the various remedial actions on this tab to resolve the CI-related issues.

By default, the tab displays metrics information of the primary affected CI associated with the incident. But you can also select and view the information for any affected CI with the ci_computer or
ci_server class that is associated with the incident. For information about how you can set up Investigation Framework, see [Setting up Investigation Framework in Service Operations Workspace](https://www.servicenow.com/docs/wRwSWi27I0unm9kxKoAGYg "Set up the Investigation Framework in Service Operations Workspace to enable the display of the CI metrics information on the Investigation tab of the Incident records.").  
Note:  
* The tab is visible only if the Agent Client Collector (ACC) or Microsoft Endpoint Configuration Manager (MECM) adapters are installed and configured.
* The tab displays the metrics information for the CI only in the following conditions:
  * Agent Client Collector or Microsoft Endpoint Configuration Manager (MECM) is installed for the associated CI. This helps to retrieve the metrics data for the CI.
  * The associated CI class is a CMDB CI computer.
  {#incident-sow__ul_adx_wjp_b5b}
* This feature supports only the macOS, Windows, and Linux operating systems.
{#incident-sow__ul_zkt_1l4_b5b}

You can also customize the display of the metrics information on this tab. For more information, see [Customize the Investigate tab](https://www.servicenow.com/docs/NxOtbf6LUBNU84sL3lR~nA#customize-investigate "Customize on how the CI related metrics information is displayed on the Investigate tab of the Incident record.").

For more information on the metrics displayed on this tab, see [Features of the Investigation tab](https://www.servicenow.com/docs/gyB5gBeg0YpnxHXFVC_fng "The Investigation tab displays CI metrics information along with various options. Use the options and the metrics information to view the data that helps to resolve the CI-related issues.").

## Communicate tab {#incident-sow__section_plt_3z4_1bc}

This tab displays all the communication tasks and options that enable you to communicate with the stakeholders in the various phases of an incident. This tab is available only if any of the following conditions are met:

* For a major incident - The Major Incident Management (sn-sow-mim) plugin is active and configured in Admin Center, for Service Operations Workspace. For more information, see [Setting up Major Incident Management in Service Operations Workspace](https://www.servicenow.com/docs/4rpRmqsxj_4aD~jWKTy97A "Set up Major Incident Management (MIM) to manage major incidents from the incident record page in Service Operations Workspace. A major incident (MI) is an incident that results in significant disruption to the business and has a high business impact.").
* For Incident -- The Task Communications Management and Incident Communications Management applications are installed, active, and configured in the instance and you select the New Communication option from the More Actions (![More actions icon]()) icon of the Incident record page. For more information, see [Task Communications Management](https://www.servicenow.com/docs/access?context=tcm-landing-page&version=australia&pubname=australia-servicenow-platform&ft:locale=en-US) and [Incident Communications Management](https://www.servicenow.com/docs/eQEsw7fijrKwfn7cp1~KYw "The ServiceNow Incident Communications Management application enables organizations to create and manage communications related to major business issues or incidents.").

{#incident-sow__ul_ohz_lz4_1bc}For more information on the features of the Communicate tab, see [Communicating with stakeholders about incidents and major incidents in SOW](https://www.servicenow.com/docs/TLeTd6S4I2dgsfVgH05Y~A "Use the Communicate tab to create and manage all communications with stakeholders during the various phases of an incident or a major incident.").

## Post incident report tab {#incident-sow__section_ywz_kbp_1bc}

This tab enables you to generate, configure, publish, and export a post incident report for a major incident after it's resolved. The post incident report enables you to review the cause and resolution of the major incident and also identify potential process gaps. Based on this information, you can take preventive measures to avoid the issue in the future or to handle the major incident in a better way. This tab is available only if the following conditions are met:

* Major Incident Management is active and configured in Admin Center for Service Operations Workspace. For more information, see [Setting up Major Incident Management in Service Operations Workspace](https://www.servicenow.com/docs/4rpRmqsxj_4aD~jWKTy97A "Set up Major Incident Management (MIM) to manage major incidents from the incident record page in Service Operations Workspace. A major incident (MI) is an incident that results in significant disruption to the business and has a high business impact.").
* The major incident is in the Resolved state.

{#incident-sow__ul_lyb_sbp_1bc}For more information on the features of the Post incident report tab, see [Review and update a post incident report](https://www.servicenow.com/docs/B6JrdYw3TQSsxtDbecN19g "Review a post incident report (PIR) using the Post Incident Report tab. A PIR helps you review and understand the cause of the major incident and the actions taken by the teams to resolve the incident. This helps prevent the issue in the future.").

## Details tab {#incident-sow__section_gn3_xsq_5sb}

This tab displays detailed information about the incident. For example, the short description, assignment details, and related records. For more information on how you can configure fields in this tab, see [Configure a task record form in Service Operations Workspace](https://www.servicenow.com/docs/BM3w9bR5khLWAVK2PF5BYQ "Configure a task record form in Service Operations Workspace by modifying the form layout or related lists from the classic ServiceNow AI Platform user interface.").

## Related records tab {#incident-sow__section_hkf_ysq_5sb}

This tab provides a list view of the records associated with the incident. For example, task SLAs and affected CIs.

## Contextual side panel {#incident-sow__section_dhl_ctq_5sb}

From this section, you can view record information and recommendations, collaborate using Microsoft Teams, and reach out to experts on-call to resolve incidents quickly.

For more information about Incident Management, see [Incident Management](https://www.servicenow.com/docs/9c8177e7~u2qCzQBofO4uw "Incident Management restores normal service operation while minimizing impact to business operations and maintaining quality.").
* **[Create an incident in Service Operations Workspace](https://www.servicenow.com/docs/DX7Hz9WAFvHCv6apiiNpGg)**   
  Track the investigation, possible solutions, and resolution of a problem for a customer.
* **[View and update incident information on the Overview tab](https://www.servicenow.com/docs/6ZJ5lZc63TAqEOfGcrEQHg)**   
  View and update the incident information, such as summary, impact, cause, and resolution, from the Overview tab. This incident information helps you analyze the issue and resolve the incident quickly.
* **[Viewing incident record information using the Contextual side panel](https://www.servicenow.com/docs/Is~pVulzhychaejFJSbfIg)**   
  View the incident record information, such as caller details and assets, from the Contextual side panel. Use this information to help manage an incident more efficiently.
* **[Work on an incident list page in Service Operations Workspace](https://www.servicenow.com/docs/JEehtYaqJl5l8F9K1_u6YQ)**   
  Perform various actions on an incident from the incident list page in Service Operations Workspace (SOW).
* **[Work on an incident record in Service Operations Workspace](https://www.servicenow.com/docs/QurZTkwKnKIiMg5xEkZyDA)**   
  If resolving the incident involves creating a problem, change, service request, and so on, you can create them directly from the incident record.
* **[Remedial actions using Playbook](https://www.servicenow.com/docs/xJ66u1YJJn1tqsmwiBx5tQ)**   
  Resolve the CI-related issues using the remedial actions using Playbook in the Investigate tab.
* **[Close resolved incident](https://www.servicenow.com/docs/73gjz_3ufF~D~TSgW5EVIg)**   
  Close a resolved incident when the user is satisfied with the provided resolution.
* **[Reopen an incident in Service Operations Workspace](https://www.servicenow.com/docs/M~2KqqtKwJdbd~nJBMOiNw)**   
  Reopen a resolved incident from the incident record in Service Operations Workspace (SOW).
* **[Incident Management in Service Operations Workspace reference](https://www.servicenow.com/docs/EEy54zsTSXlJtO7t~l_vVg)**   
  Reference topics provide additional information about Incident Management in Service Operations Workspace.

**Related concepts**   

* [Live Agent chat in Service Operations Workspace](https://www.servicenow.com/docs/wbbQneFtW3PNhZijUMFBxg "Service Operations Workspace enables agents to work on any incident created using Live Agent chat.")
* [Interaction Management in Service Operations Workspace](https://www.servicenow.com/docs/IJjnY28l7xvLvNaKfyaWLQ "Interactions are a centralized location for all communication channels in Service Operations Workspace. You can respond to an incoming chat, phone, walk-up, or messaging interactions faster.")
* [Request Management in Service Operations Workspace](https://www.servicenow.com/docs/V3MWTflvoQBI5HmCic3jsg "Service Operations Workspace for Request Management integrates the platform functionality for tier 1 agents into a multi-tab interface that helps agents efficiently manage multiple incidents, catalog requests, and catalog tasks.")
* [Change Management in Service Operations Workspace](https://www.servicenow.com/docs/DJM5pmB5G3EPbTuWS2a9zA "When a change to your infrastructure or a business service is required, you can create a change request and track it in Service Operations Workspace.")  
**Related tasks**   

* [Play a guided tour in Service Operations Workspace](https://www.servicenow.com/docs/U9Od4ggCfU_t4WuEN_EdDg "Use the guided tours in Service Operations Workspace for ITSM through a sequence of interactive steps that guide you through a specific concept or process.")
* [Add a user-specific quick link on the ITSM landing page](https://www.servicenow.com/docs/IrsfwaMLB_kL4F~VQVCLsw "Refer to a URL quickly from the Service Operations Workspace landing page.")
* [Create a list in Service Operations Workspace](https://www.servicenow.com/docs/8fH3joA2AQqMevmR48HLnA "Create a list or use an existing list to create a list.")

