Manage alerts autonomously agentic workflow

  • Release version: Zurich
  • Updated December 10, 2025
  • 2 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Manage alerts autonomously agentic workflow

    The Manage alerts autonomously agentic workflow is an AI-driven process in the Zurich release designed to enhance IT operations by automating alert management. It streamlines alert triage, impact analysis, root cause investigation, and reporting, significantly reducing resolution times and improving operational efficiency.

    Show full answer Show less

    Key Features

    • Automated Alert Triage: Evaluates, categorizes, and analyzes alert history to detect noise patterns and update alert group descriptions.
    • Impact Assessment: Determines the impact of alerts on services and users by analyzing related incidents, cases, and service health using observability skills.
    • Comprehensive Investigation: Retrieves and summarizes similar closed alerts, analyzes recent changes and knowledge base articles, identifies trends or anomalies in metrics, and investigates logs including proactive and reactive alerts.
    • Insight Generation and Reporting: Consolidates findings into summaries stored within alert records, including reasoning, evidence, confidence levels, and service health analysis.
    • AI Agent Utilization: Uses the Manage alerts AI agent to perform investigation, summarization, and structured insight storage.
    • Default Activation: This workflow is enabled by default, ensuring immediate AI-driven alert management capabilities out of the box.

    Practical Application for ServiceNow Customers

    By implementing this workflow, customers can expect automated and intelligent handling of IT alerts, reducing manual effort and accelerating response times. The workflow’s detailed analysis and reporting capabilities provide actionable insights that help prioritize work, identify root causes, and improve service reliability.

    Customers can review AI-generated alert insights conveniently through the Express List interface, which consolidates information and provides AI insights badges and filters for easy monitoring of alert statuses.

    For customization, customers must duplicate the agentic workflow and update AI agents, tools, and instructions accordingly to suit specific operational needs.

    Enhance IT operations with AI-driven, autonomous alert management using the manage alerts autonomously agentic workflow.

    Manage alerts autonomously agentic workflow overview

    The manage alerts autonomously workflow introduces a unified AI-driven process that significantly streamlines alert management and reduces resolution times. This workflow supports alert management in the following ways:
    • Automates the triage
    • Impact analysis
    • Root cause investigation of IT alerts
    • Generates reports, summarizes key insights and possible next steps

    For information on how to review key insights and data derived from the workflow in Express List, see Review AI-generated alert insights in Express List.

    For information about configuring this workflow, see Configure the manage alerts autonomously agentic workflow.

    Use the information on this page to learn about the actions related to the manage alerts autonomously agentic workflow. To modify the workflow, you must duplicate it and adjust the settings according to your requirements. For more information, see Duplicate an agentic workflow.

    Important:
    When you modify an agentic workflow, AI agent, or tool, make sure that you update all instructions accordingly.

    Manage alerts autonomously agentic workflow

    The manage alerts autonomously agentic workflow uses the manage alerts AI agent to perform alert management and resolution tasks.

    Table 1. AI agent used in the manage alerts autonomously agentic workflow
    AI agent AI agent role
    Manage alerts AI agent Investigates alerts, summarizes alert-related reports, and stores structured insights with key findings.

    The manage alerts autonomously agentic workflow performs several actions in the course of the workflow. These actions may include the following:

    • Triages alerts
      • Evaluates and categorizes alert
      • Analyzes alert history to identify noise patterns
      • Updates alert group description based on analysis
      • Performs related incidents analysis to detect focal points and common closure patterns
    • Determines alert impact
      • Evaluates impact on services
      • Determines user impact by finding recent incidents or cases
      • Uses observability skills for deeper service state validation
    • Investigates relevant information
      • Retrieves and summarizes similar closed alerts
      • Analyzes recent changes for causal relationships
      • Summarizes related KB articles for relevant information
      • Identifies trends or anomalies in related metrics
      • Uncovers errors, exceptions, or warnings in related logs
      • Analyzes non-primary log analytics alerts in an alert group to support investigation, including the following:
        • Classifies alerts as proactive or reactive, indicating emerging risk or an active issue
        • Assess if triage is required
        • Provides contextual insights, including potential failure scenarios and what may occur if the alert isn't addressed
    • Summarizes and stores information
      • Consolidates findings
      • Generates a final summary
      • Saves the summaries in the alert record, such as
        • reasoning, evidence, and confidence level behind AI-driven investigation of alert significance and automatic closure of insignificant alerts
        • summaries of Service Observability dashboards to provide health analysis of each service associated with an alert. For more information see, Analyze service health in Service Observability
      • Provides clear, actionable insights
    Important:
    This agentic workflow is turned on by default. For more information, see AI agents, skills, and agentic workflows on by default.