Remedial actions using Playbook

  • Release version: Australia
  • Updated March 12, 2026
  • 4 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Remedial actions using Playbook

    The Remedial Actions using Playbook feature in Service Operations Workspace enables you to resolve Configuration Item (CI)-related issues efficiently through guided remediation steps accessible from the Investigate tab on incident records. This functionality requires the Investigation Framework and Remedial Action Framework applications to be installed and properly configured.

    Show full answer Show less

    Playbooks provide an interactive side panel UI that guides you through executing remedial actions such as End process and Restart service, helping you control and track each step of the remediation process. These actions can be applied to both affected CIs and caller CIs associated with an incident.

    Key Features

    • Playbook Interface: Accessible from the contextual side panel on incident pages, the playbook displays tabs for Current (new and in-progress) and History (completed, canceled, failed) remediation processes.
    • Remedial Actions: Two primary actions are supported:
      • End process: Available via Top processes metric cards for memory and CPU. For devices, user approval is required before directly stopping a process; for servers, a standard change request must be created first.
      • Restart service: Available through the Services metric card. Device actions require user approval; server actions require a change request similar to the End process action.
    • Action Management: You can cancel ongoing remedial actions via the playbook, with cancellation status and reasons available in the History tab unless certain conditions prevent viewing.
    • Concurrent Execution Control: By default, concurrent or duplicate remedial actions on the same CI or process are prevented until the current action completes. This behavior can be modified via configuration to allow concurrent executions.
    • CI Support: Different playbooks are displayed depending on whether the CI supports DEX or the Service Operations Workspace default view.
    • Visibility of Actions: The Investigate tab shows remedial actions for the primary CI by default with an option to view actions performed on all CIs associated with the incident.

    Practical Application for ServiceNow Customers

    This capability allows ServiceNow users managing incidents in Service Operations Workspace to systematically remediate CI issues through a structured and auditable process. By leveraging playbooks:

    • You gain step-by-step guidance and control over remediation actions, minimizing errors and improving resolution speed.
    • Change management integration ensures that server-related actions comply with organizational policies via required change requests.
    • The ability to track remediation history and cancel ongoing actions provides transparency and flexibility during incident resolution.

    To implement these remedial actions effectively, ensure the Investigation Framework and Remedial Actions Framework are installed and configured according to your environment’s needs. Customize the Investigate tab as necessary to display relevant remedial actions and metrics.

    Resolve the CI-related issues using the remedial actions using Playbook in the Investigate tab.

    The Investigate tab includes the following types of remedial action to resolve CI-related issues:
    • End process
    • Restart service
    These remedial actions are available on the Investigate tab only if the following conditions are met:
    Remedial actions use playbooks to resolve CI issues. Playbook provides you with an interactive UI to guide and execute the remedial actions step by step. With a playbook, you can control every execution step of the remediation process. Playbook is available on the contextual side panel of the Incident record page. When any remedial action is performed, that remediation process is added to a playbook. You can then select the playbook (Playbook icon) icon on the contextual side panel to open the playbook on a separate panel and execute the process. The playbook panel displays the following tabs:
    • Current: Displays the current list of playbooks that trigger the remedial action, including both processes and services that have the status New and In Progress.
    • History: Displays the historical list of playbooks, including both processes and services that have the status Completed, Canceled, or Failed.
    You can perform remedial actions on both the affected CIs and the caller CIs associated with the incident record. The caller CIs are the CIs that are assigned to the caller.
    Note:
    If the CI is DEX supported, the remedial actions playbook for the DEX actions are displayed. If the CI is SOW or default view supported, the remedial actions playbook for SOW actions are displayed.
    You can cancel an ongoing End process or Restart service remedial action playbook. To cancel a remedial action playbook, select the remedial action playbook and select the menu (Menu icon) icon and then select Cancel action option. After the remedial action playbook is canceled, the corresponding action is also canceled. Then, the status of the remedial action is displayed as Canceled in the History tab of the playbook panel. To view the reason for cancellation, select the View reason option on the playbook. This option isn’t available if any of the following are true:
    • The remedial action is already in Canceled status.
    • The corresponding CI action record of the remedial action is already in progress.
    • The change request has already moved to implement state for actions associated to CIs of type server.

    The Remedial actions section on the Investigate tab also contains the Current and History tab to display the list of remedial actions performed. By default, this section displays the list of remedial actions for the primary CI or current CI. You can switch the Show actions performed on all CIs in this incident toggle to display the list of remedial actions for all the CIs associated with the Incident.

    Playbook is available only if both the Remedial Action Framework [com.snc.sn_reacf] application and the Investigation Framework [sn_invest_fwk] application are installed and configured, as well as if the remedial actions are triggered.

    Note:
    You can't execute concurrent or duplicate remedial actions when a remedial action is in progress on a process or service for a CI type device or server. You also can't execute concurrent or duplicate remedial actions on the same CI until the previous remedial action execution is completed. You can change this behavior and allow concurrent execution of the remedial action by selecting the Allow concurrent execution option for Remedial Action Type. For more information, see Configure the Remedial Actions Framework.

    End process

    The End process remedial action is available with the following metric information cards:
    • Top processes By Memory
    • Top processes By CPU
    Select the CI and then select End process to stop the process running on the CI. The remediation process then is added to the playbook. Select the Playbook (Playbook icon) icon from the contextual side panel to open the playbook on a separate panel and execute the process. You can execute the End process remedial action for the following CI classes:
    • Device: For this CI class, a two-step process is executed where you must get the user approval before the End process remediation process can be executed. After it’s approved, you can directly stop the process on the device, which is also known as the endpoint.
    • Server: For this CI class, you must create a change request before the End process remedial action can be executed using a standard change request. You must also provide additional information to create a change request.

    Restart service

    The Restart service remedial action is available with the Services metric information card.

    Select the CI and then select Restart service to restart the services running on the CI. The remediation process then is added to the playbook. Select the Playbook (Playbook icon) icon on the contextual side panel to open the playbook on a separate panel and execute the process. You can execute the Restart service remedial action for the following CI classes:
    • Device: For this CI class, a two-step process is executed where you must get the user approval before the Restart service remediation process is executed. After it's approved, you can directly restart the services on the device, which is also known as the endpoint.
    • Server: For this CI class, you must create a change request before you can execute the remedial action using a standard change request. You must also provide additional information to create a change request.