---
sourceDocument: Brazil IT Service Management
sourceDocumentLink: https://www.servicenow.com/docs/r/it-service-management

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil IT Service Management

ft:clusterId :

    - itsm

bundleId :

    - itsm

workflow :

    - Technology


---

# Managing incidents

# Managing incidents {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Managing incidents

Managing incidents in ServiceNow involves diagnosing, investigating, documenting, and escalating or promoting incidents as needed.
The process is primarily human-driven, where service desk agents interact with users and leverage the Configuration Management Database (CMDB) to understand hardware, software, and their relationships.
The CMDB is often populated through Discovery, a separate product.
Show full answer Show less  

## Incident Investigation

Investigation relies on continuous evaluation of incident details and CMDB information, with updates recorded as work notes to facilitate communication. Email notifications can be sent to keep stakeholders informed. To identify related incidents, ServiceNow provides tools such as:

* **Related Incidents Icon:** Appears beside the Caller field to show incidents associated with the same caller. Administrators can enable this feature on other reference fields through dictionary attributes and ensure the corresponding UI macro is active.
* **Incidents by Same Caller Related List:** Displays related incidents on the form; administrators may need to configure the form to show this list.
* **Dependency Views:** Visual maps showing related incidents based on configuration items (CIs). Users can expand CIs to view related tasks, aiding in comprehensive incident analysis.

## Incident Promotion

When an incident is identified as stemming from a broader error or problem, the incident management team can promote the incident to a problem record or initiate a change management process if infrastructure or service changes are required. The Incident form includes menu options to create and associate problem or change records, preventing duplicate records of the same type. Additionally, agents can create hardware or software requests directly from incidents when user resolution involves procurement, available in instances Jakarta release or later with the appropriate plugin activated.

## Incident Escalation

To ensure timely resolution, ServiceNow provides two escalation methods:

* **Service Level Agreements (SLAs):** SLAs define agreed service scope, quality, and response times. They monitor incident progress, automatically escalate priorities when thresholds are met, and serve as performance indicators for the service desk.
* **Inactivity Monitor:** Tracks incidents with no updates over a specified time and triggers email notifications or scripts to prevent incidents from being overlooked.  
Working on incidents involves diagnosing and investigating the incident, recording
results, and sometimes escalating or promoting the incident.

Initial diagnosis of incidents is largely a human process. The service desk agent looks at the
details of the incident and communicates with the user to diagnose the issue.

To aid in the diagnosis, the service desk agent can query the configuration management
database, or CMDB. The CMDB contains information about hardware and software within a network and
the relationships between them. The CMDB can be populated by:
[Discovery](https://www.servicenow.com/docs/access?context=r-discovery&version=brazil&pubname=brazil-it-operations-management&ft:locale=en-US)
. Discovery is available as a separate product.

## Incident investigation

Incident investigation is also a human process. The service desk continues to use the
information in the Incident form as well as the CMDB to solve the issue. Work notes are added to
the incident as the service desk evaluates the incident, facilitating communication between the
concerned parties. Work notes and other updates can be communicated to the concerned parties
through [email notifications](https://www.servicenow.com/docs/access?context=c_EmailNotifications&version=brazil&pubname=brazil-platform-administration&ft:locale=en-US).

One way to investigate incidents is to determine whether related records exist, using one of
the following features.

Related incidents icon
:   The show related incidents icon (![Show related incidents icon]()) appears beside the Caller field when it is populated. Click
    the icon to view the list of incidents for the same caller.  
    Note:  
    Administrators can add this icon to any reference field by modifying the dictionary entry and adding the ref_contributions=user_show_incidents dictionary attribute. The icon appears only for users who have read or write access to the field. A UI macro named user_show_incidents defines the behavior. The UI macro must be active to view the related incidents icon.

Incidents by Same Caller related list
:   Another way to research related incidents is to use the Incidents by Same Caller related list. The administrator may need to configure the form to display
    this related list.

Dependency views
:   Dependency views can help find related incidents based on configuration items (CI). If a
    configuration item is attached to an incident, click the map icon (![Dependency view icon]()) to display the dependency views map. In the dependency map, if you want to view the
    tasks that are attached to the CI, click the down arrow next to the CI and from the menu,
    select View Related Tasks.  
    Figure 1. CI options

## Incident promotion

When the incident management team has determined that the cause of an incident is an error or
widespread problem, the team initiates the problem management process. When the issue requires a
change to the infrastructure or a business service, the team initiates the change management
process.  
A menu item on the Incident form lets you create a problem or change record easily and associate the incident with the problem or change record. For more information, refer [Create a record from incident](https://www.servicenow.com/docs/yfDKT3F783BvhwWS5G1GVg "Create a problem, change, or request record from an incident.")  
Note:  
If the incident already has an associated problem or change record, you cannot create another record of the same task type.  
Sometimes, the resolution for the user is to request hardware or software for them. For example, a user may report a problem that requires a new mouse device or keyboard. The service desk agent can create a request from the incident. The incident is associated with the requested item.  
Note:  
This feature is available only in new instances starting with Jakarta or a later release. The Problem Management Best Practice -- Jakarta plugin (com.snc.best_practice.problem.jakarta) plugin must be activated.

## Incident escalation

There are two escalation methods the platform uses to track and report on incidents that are
not being resolved according to your organization standards.

[Service level agreements](https://www.servicenow.com/docs/EJAKZdvEHMa7ALGJLB6gHg "The ServiceNow Service Level Management (SLM) application facilitates you to oversee and control the services within the organization.") (SLAs)
:   SLAs monitor the progress of an incident according to a set of agreements between a service
    provider and customer that define the scope, quality, and speed of the services being
    provided. As time passes, the SLA escalates the priority of the incident and leaves a marker
    as to its progress. SLAs are also used as a performance indicator for the service desk.

[Inactivity monitor](https://www.servicenow.com/docs/access?context=t_SetAnInactivityMonitor&version=brazil&pubname=brazil-platform-administration&ft:locale=en-US)
:   The inactivity monitor generates an event to prevent incidents from going unnoticed. When a
    certain amount of time has passed without an update to the incident, the event creates an
    email notification or triggers a script.

