---
sourceDocument: Brazil IT Service Management
sourceDocumentLink: https://www.servicenow.com/docs/r/it-service-management

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil IT Service Management

ft:clusterId :

    - itsm

bundleId :

    - itsm

workflow :

    - Technology


---

# Post Incident Report tab

# Post Incident Report tab {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Post Incident Report tab

The Post Incident Report tab in ServiceNow Brazil release enables major incident managers to document and analyze major incidents comprehensively.
It supports understanding the incident's root cause, documenting the resolution process, and capturing lessons learned.
This tab becomes editable when the incident is in the Resolved state, allowing managers to provide detailed post-incident insights.
Show full answer Show less  

## Key Features

* **Structured Sections for Reporting:** Includes Overview (incident summary), Findings (root cause and lessons learned), Resolution (steps taken to resolve), and Timeline (detailed activity feeds covering the incident, communication plans, and tasks).
* **Integration with Problem and Change Management:** Managers can directly add or manage related Problem or Change records from the report.
* **Timeline Updates:** Users can refresh the incident activity timeline to include the latest updates using the "Regenerate Timeline" function.
* **Continual Improvement Management (CIM) Integration:** When the CIM plugin is activated, related improvement records appear within the report, linking continuous improvement efforts to the incident.
* **Report Generation and Access:** Major incident managers can compile all entered information into a comprehensive report, downloadable as a PDF via "Download Report PDF."
* **Role-Based Access Links:**
  * "Regenerate PIR Timeline" link is available to majorincidentmanager role users when the incident is Resolved.
  * "Preview PIR" link is available to itil role users when the incident is Resolved or Closed.
* **Time to Identify Metric:** The report calculates the time to identify the incident based on alert creation or incident creation timestamps, depending on whether the incident was proposed as major or created directly, providing precise incident response timing.

## Practical Benefits for ServiceNow Customers

* Enables thorough documentation of major incidents, facilitating post-incident reviews and continuous improvement.
* Improves collaboration by linking incident, problem, and change records directly within the report.
* Supports compliance and accountability by requiring detailed records of actions and findings.
* Enhances reporting accuracy and transparency with automated timelines and precise incident identification metrics.
* Provides easy access to comprehensive post-incident reports in PDF format for sharing and auditing.  
The Post Incident Report tab helps you to understand the cause of
the major incident, and the actions taken by the teams to resolve the incident.  
The teams can assess the incident response and resolution process and determine follow-up action items. The post incident report is required to record the actions performed, the reasons for doing them, and findings.  
Note:  
The major incident manager can edit a report when the incident is in the Resolved state.  
Figure 1. View of the Post Incident Report tab  
The post incident report includes the following sections where a major incident manager can provide required information:

* Overview: Summary of the incident.
* Findings: Information on what caused the major incident and any lessons learned in the process.
* Resolution: Information on the resolution steps taken to resolve the issue. The major incident manager can also add or edit any related Problem or Change information by clicking Add or Manage respectively.
* Timeline: Information of all the activity feeds, not only of the incident but also of the incident communication plan and incident communication tasks related to the incident. You can update the timeline with the latest activity by clicking Regenerate Timeline.  
  Note:  
  The information that you provide for Overview, Findings, and Timeline gets updated in the Post Incident Report section on the Incident form.
{#mi-workbench-pir-tab__ul_pfs_41g_hdb}

If you activate the Continual Improvement Management (CIM) plugin (com.sn_cim), the
Related Improvement Records section is displayed in the report. This section displays the
Inbound CIM Integrations records.

When you click View Complete Report, all the information entered by the
major incident manager is compiled together and you can download the report in the .PDF format
by clicking Download Report PDF.  
The following links appear in the Incident form under the Related Links section:

* Regenerate PIR Timeline: This link appears when incident is in the Resolved state and the user has the major_incident_manager role.
* Preview PIR: This link appears when incident is in the Resolved or Closed state and the user has the itil role.
{#mi-workbench-pir-tab__ul_h1k_kn4_vgb}  
Note:  
On the downloaded report, under Incident Response Timeline, the time displayed in the timing type Time to Identify is calculated in the following ways:

* If you propose the incident as a major incident: The time indicates the time from creation of the first related alert for this incident or creation of the incident (in case there is no alert or the Event Management plugin is inactive), whichever occurs first, until the time the incident is first proposed as a major incident.
* If you create a major incident directly: The time indicates the time from creation of the first related alert for this incident or creation of the incident (in case there is no alert or the Event Management plugin is inactive), whichever occurs first, until the time the incident is promoted as a major incident.
{#mi-workbench-pir-tab__ul_cqg_qwd_5gb}
**Related concepts**   

* [Major Incident workbench --- Summary tab](https://www.servicenow.com/docs/bmYzWmqNTHwVyFQGrhOeAA "The Summary tab provides a unified view of information in the form of a card layout. The information on impacted services, affected CIs, active outages, locations that are impacted, and child incidents helps to keep you informed about related records associated with an incident.")
* [The Communicate tab in the Major Incident workbench](https://www.servicenow.com/docs/9hTR8jshR~xQaVrx0Q9aAg "The Communicate tab helps you understand the progress of a communication plan and its related tasks.")
* [Major Incident workbench --- the Collaborate tab](https://www.servicenow.com/docs/51inMqYEQzNx80b8P5kMqg "The Collaborate tab helps you to view and manage communication tasks that use conference as their communication channel.")  
**Related tasks**   

* [Associate a new post incident report](https://www.servicenow.com/docs/HT06V9Dx~ca2zurE47jddQ "Create your own post incident report and associate the UI page with the View Complete Report button under the Post Incident Report tab. Using the customized report, you can add information that is specific to your organization.")

