---
sourceDocument: Australia IT Service Management
sourceDocumentLink: https://www.servicenow.com/docs/r/it-service-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia IT Service Management

ft:clusterId :

    - itsm

bundleId :

    - itsm

workflow :

    - Technology


---

# Triage and categorize ITSM incidents

# IT Service Management AI agent collection Triage and categorize ITSM incidents agentic workflow {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 5 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of IT Service Management AI agent collection Triage and categorize ITSM incidents agentic workflow

TheTriage and categorize ITSM incidents agentic workflowautomates the classification and enrichment of IT Service Management (ITSM) incidents within ServiceNow.
It assigns appropriate categories and subcategories based on the incident's short description, then links the incident to relevant services, service offerings, and configuration items (CIs).
Additionally, it autonomously associates incidents with related major incidents or known problems to streamline incident resolution.
Show full answer Show less  

## Key Features

* **Autonomous Incident Categorization:** Uses AI to assign categories and subcategories to new or in-progress incidents based on incident descriptions.
* **Service and CI Assignment:** Automatically identifies and assigns the relevant service, service offering, and configuration item associated with the incident.
* **Linking to Major Incidents and Problems:** Searches for related major incidents (requires activation of the Major Incident Management plugin) or known problems and links them to the incident to provide context and expedite handling.
* **Flexible Triggering:** Supports both automatic triggers based on incident state, assignment, and priority, and manual triggers when incidents are in progress and assigned.
* **AI Agent Team:** Utilizes a sequence of AI agents---Categorize ITSM Incident AI agent, Classify Service and CI AI agent, and Link Major Incident or Problem AI agent---to perform the workflow steps.
* **Configuration and Customization:** Allows duplication and modification of the workflow to tailor it to specific organizational needs. Semantic indexing must be enabled for the Problem table when modifying the workflow.
* **Run as AI User:** The workflow runs under a designated AI agent user with appropriate roles to execute automated tasks securely.
* **User Interaction via Otto Panel:** Human agents receive category recommendations and can monitor the autonomous updates to incident records, ensuring transparency and control.

## Practical Considerations for ServiceNow Customers

* Ensure the **Incident Management - Major Incident Management plugin** is activated to enable automatic linking to major incidents.
* Activate AI agents by enabling their status in the Define availability screen to ensure the workflow operates correctly.
* Set the **Run as user** to an AI agent user with the itil role to enable autonomous workflow execution.
* Review and update all instructions and triggers when customizing the agentic workflow to maintain consistency and accuracy.
* Use the AI Agent Studio interface to monitor workflow execution and receive notifications for category recommendations, enabling seamless collaboration between AI and human agents.

## Expected Outcomes

By implementing this agentic workflow, ServiceNow customers can expect:

* Improved incident triage speed through automated categorization and service assignment.
* Enhanced incident context by linking to relevant major incidents or known problems, aiding faster resolution.
* Reduced manual effort for ITSM teams in incident classification and record enrichment.
* Consistent and accurate incident data, improving reporting and analytics.
* Seamless integration of AI-driven automation with human workflows via the Otto panel for transparency and control.  
Use the Triage and categorize ITSM incidents AI agent team to assign incident categories and subcategories. Then, assign the service, service offering, and the configuration items (CI), and also link major incidents, and known problems
autonomously.

## Triage and categorize ITSM incidents agentic workflow overview {#now-assist-itsm-aiagents-catincidents-usecase__section_b25_wzj_h2c}

Using the Triage and categorize ITSM incidents agentic workflow, autonomously assign incident categories by assigning a category and a subcategory to incidents based on the incident short description. After categorizing the incident, assign
the service, service offering, and configuration item (CI) related to the incident. Then, automatically link incidents to major incidents or known problems.  
To modify the Triage and categorize ITSM incidents agentic workflow, [duplicate it](https://www.servicenow.com/docs/access?context=clone-aia-usecase&version=australia&pubname=australia-intelligent-experiences&ft:locale=en-US), and adjust the settings according to your requirements.  
Note:  
You must enable the semantic indexing for the Problem table when you duplicate the agentic workflow. For more information, see [Semantic Index Field form](https://www.servicenow.com/docs/access?context=semantic-index-field-form&version=australia&pubname=australia-platform-administration&ft:locale=en-US).  
Important:  
When you modify an agentic workflow, AI agent, or a tool, make sure that you update all instructions accordingly.  
Important:  
To search for related major incidents, you must activate the Incident Management - Major Incident Management plugin (com.snc.incident.mim). For more information, see [Activate Major Incident Management](https://www.servicenow.com/docs/N6Ae_uGIHaMRyVn~fuQjZA "You can activate the Incident Management - Major Incident Management plugin (com.snc.incident.mim) if you have the admin role. This plugin includes demo data and activates related plugins if they are not already active.").

## Triage and categorize ITSM incidents agentic workflow {#now-assist-itsm-aiagents-catincidents-usecase__section_yjy_lhk_h2c}

This workflow does the following:

1. Automatically categorizes the incidents.
2. Then, assigns the related service, service offering, and configuration item (CI).
3. Then, searches for related major incidents and if found, links them to the incident.
4. If no major incidents are found, then it searches for related problems, and if found, links them to the incident.
{#now-assist-itsm-aiagents-catincidents-usecase__ol_bff_bh1_x2c}  
To access the agentic workflow:

1. Navigate to AllAI Agent StudioCreate and manage.
2. Select Triage and categorize ITSM incidents.
{#now-assist-itsm-aiagents-catincidents-usecase__ol_qsk_tjc_j2c}  
Important:  
In the Edit trigger form, make sure that the Active button is turned on to enable the AI agent to trigger autonomously. You must enter the sys_id of the user with the itil role when the trigger is activated.

## Setting automatic or manual triggers for the agentic workflow {#now-assist-itsm-aiagents-catincidents-usecase__section_knp_ltt_1fc}

Based on the incident assignment, state, and priority, the Triage and categorize ITSM incidents agentic workflow is triggered either automatically or manually. {#now-assist-itsm-aiagents-catincidents-usecase__table_w5k_4tt_1fc__entry__2}

| Type of trigger | Field values |
|-|-|
| Automatic | * State is New * Assigned to is empty * Priority is 3, 4, or 5 {#now-assist-itsm-aiagents-catincidents-usecase__ul_hpr_q5t_1fc} |
| Automatic | * State is updated to In progress * Assigned to is empty * Priority is 3, 4 and 5 {#now-assist-itsm-aiagents-catincidents-usecase__ul_l15_z5t_1fc} |
| Manual | * State is In progress * Assigned to isn't empty {#now-assist-itsm-aiagents-catincidents-usecase__ul_gvb_yvt_1fc} |
[ ]

{#now-assist-itsm-aiagents-catincidents-usecase__table_w5k_4tt_1fc}

## Setting the AI user as the Run as user {#now-assist-itsm-aiagents-catincidents-usecase__section_iqc_lpl_hgc}

The ITSM Worker AI Agent user record is of identity type AI agent and is available by default. You can create users of this type and assign roles to the users based on your needs.  
Add the AI agent user as the Run as user:

1. Navigate to the Define key requirements screen.
2. Go to the Select the entity this agentic workflow will run as section.
3. In the Run as field, select AI user.
4. In the AI user field, select the desired AI agent user.
{#now-assist-itsm-aiagents-catincidents-usecase__ol_xdl_vsl_hgc}

## AI agents used in the Triage and categorize ITSM incidents agentic workflow {#now-assist-itsm-aiagents-catincidents-usecase__section_mjj_rlk_j2c}

The Triage and categorize ITSM incidents agentic workflow uses a team of AI agents to automatically categorize incidents, then assign the service, service offering, and configuration item (CI) related to the incident and then links
associated major incidents or known problems.  
Important:  
In the Define availability screen for the AI agent, make sure that the Status field is enabled to activate the AI agent.  
{#now-assist-itsm-aiagents-catincidents-usecase__table_abj_5lk_j2c__entry__2}

| AI agent | AI agent role |
|-|-|
| Categorize ITSM incident AI agent | Automatically assigns incidents to categories, and subcategories, based on the incident's short description. |
| Classify service and CI AI agent | Automatically assigns service, service offerings, and configuration items (CI) to the incidents. |
| Link major incident or problem AI agent | Important: To search for related major incidents, you must activate the Incident Management - Major Incident Management plugin (com.snc.incident.mim). For more information, see [Activate Major Incident Management](https://www.servicenow.com/docs/N6Ae_uGIHaMRyVn~fuQjZA "You can activate the Incident Management - Major Incident Management plugin (com.snc.incident.mim) if you have the admin role. This plugin includes demo data and activates related plugins if they are not already active."). * If this AI agent identifies a related, most similar major incident, it automatically links it to the current incident and ends the workflow. * If the Major incident linker AI agent doesn't find a related major incident, then the Incident problem linker AI agent takes over. If it identifies any ongoing problem that best matches the incident, then it automatically links it to the incident. {#now-assist-itsm-aiagents-catincidents-usecase__ul_f1f_ybf_chc} |
[Table 1. AI agents and their roles listed in the order of execution in the Triage and categorize ITSM incidents agentic workflow]

{#now-assist-itsm-aiagents-catincidents-usecase__table_abj_5lk_j2c}

## Assigning incident categories {#now-assist-itsm-aiagents-catincidents-usecase__section_jy3_grc_j2c}

In the agentic workflow record:

1. Review the information in the Describe and connect screen and in the Define trigger screen. Make the necessary updates, and then select Save and Continue.
2. In the Select display screen:
   1. Choose where you want the agentic workflow output to be displayed.
   2. Use the arrow next to the display option to add roles that can access the agentic workflow.  
      Note:  
      The itil role is added by default.
   3. Select Save and test.

      The agent executes the request for the agentic workflow.
   {#now-assist-itsm-aiagents-catincidents-usecase__ol_oth_1sc_j2c}
{#now-assist-itsm-aiagents-catincidents-usecase__ol_xtj_trc_j2c}
Example of Triage and categorize ITSM incidents agentic workflow output in the ServiceNow AI Agent Studio

In the AI Agent Studio, the human agent gets notified as soon as the category recommendation is generated so that they can follow the on-screen instructions and complete the task. For more information, see [Request the generative AI capabilities in ITSM by using the ServiceNow Otto panel](https://www.servicenow.com/docs/AnJIDfOoTCaVTN3DW2Cxdg "Use the ServiceNow Otto panel to request the contextual generative AI capabilities in IT Service Management (ITSM) such as a chat summary, incident summary, or incident resolution notes in a conversational manner. You can also add comments and work notes. These capabilities provide you with a quick resolution to issues.").

## Automate the categorizing an incident, then automatically link them to major incidents or known problems in the Otto panel {#now-assist-itsm-aiagents-catincidents-usecase__section_rwr_bch_m3c}

When an incident is updated and the trigger conditions are met, an execution plan is created. The incident fields are updated based the execution by each AI agent.  
As a user, do the following in the Otto panel:

1. Enter a message in the Otto panel, such as, "triage incident INC0010010".

   All executions are autonomous and the AI agent does need user inputs in any of the steps during the execution.
2. The first AI agent, which is the Categorize ITSM incident AI agent does the following:
   1. Updates the following fields in the incident record after the execution:
      * Category
      * Sub-category
      {#now-assist-itsm-aiagents-catincidents-usecase__ul_xt2_4dh_m3c}
   2. Updates any changes in the Work notes field.

      The orchestrator then moves to the next available agent.
   {#now-assist-itsm-aiagents-catincidents-usecase__ol_ewj_kdh_m3c}
3. The second agent, which is the Classify Service and CI AI agent updates the following fields in the incident record after the execution:
   * Service
   * Service offering
   * Configuration item

   {#now-assist-itsm-aiagents-catincidents-usecase__ul_mxc_1gh_m3c}It also updates the Additional comments and Work notes fields.

4. The third agent, which is the Link major incident or problem AI agent updates the parent incident or problem field in the incident's related record. The AI agent updates the changes in the Additional comments field.

{#now-assist-itsm-aiagents-catincidents-usecase__ol_ysl_ych_m3c}  
The image below shows the following:

* The Categorize ITSM incident AI agent populates the Category and Subcategory fields.
* The Classify service and CI AI agent populates the Service, Service offering, and Configuration items fields.
* The Link major incident or problem AI agent populates the Parent incident or the Problem field.
{#now-assist-itsm-aiagents-catincidents-usecase__ul_dj2_z3m_m3c}

*[\>]: and then


