Incident Management in Service Operations Workspace
Summarize
Summary of Incident Management in Service Operations Workspace
Incident Management in Service Operations Workspace (SOW) enables ServiceNow customers to efficiently create, manage, investigate, communicate, and resolve incidents within a unified interface. The workspace provides multiple tabs and tools designed to streamline incident handling, enhance collaboration, and facilitate thorough investigation and reporting, especially for major incidents.
Show less
Incident Record Tabs and Their Functions
- Overview tab: Displays key incident details such as summary, impact, cause, and resolution, along with options to add comments and work notes. It can be customized to suit your workflow.
- Investigation tab: Allows analysis of affected Configuration Items (CIs) with cicomputer or ciserver classes by showing relevant metrics. It supports remedial actions via Playbook and requires Agent Client Collector or MECM adapters installed and configured. This tab supports macOS, Windows, and Linux CIs and can be customized.
- Communicate tab: Facilitates communication with stakeholders during incident phases. It is available when Major Incident Management or Task/Incident Communications Management plugins are active and configured.
- Post incident report tab: Enables generation and management of post-incident reports for major incidents to review causes, resolutions, and identify process improvements. Available only when Major Incident Management is active and the incident is resolved.
- Details tab: Shows detailed incident information such as short description, assignments, and related records, which can be configured as needed.
- Related records tab: Provides a list view of records related to the incident like task SLAs and affected CIs.
Contextual Side Panel
The side panel offers quick access to incident details, recommendations, collaboration via Microsoft Teams, and expert on-call support to expedite incident resolution.
Practical Usage for ServiceNow Customers
- Create and manage incidents: Easily create incidents and update critical information on the Overview tab to track progress and resolution efforts.
- Investigate issues: Use the Investigation tab to analyze CI metrics and execute remedial actions, helping to resolve root causes efficiently.
- Communicate effectively: Leverage the Communicate tab to keep stakeholders informed throughout incident lifecycle phases.
- Post incident analysis: Generate detailed reports for major incidents to learn from incidents and improve processes.
- Integrate related processes: Create related problems, changes, or service requests directly from an incident record to streamline workflows.
- Manage incident lifecycle: Close incidents once resolved and reopen them if necessary, supporting flexible incident handling.
Important Considerations
- Installation and configuration of specific plugins (e.g., Major Incident Management, Task Communications) and adapters (Agent Client Collector or MECM) are required for full functionality of certain tabs.
- Customization options are available for multiple tabs to tailor the workspace experience to organizational needs.
You can create and manage your incidents in Service Operations Workspace.
Overview tab
- Summary
- Impact
- Cause
- Resolution
From the Compose section, you can add comments and work notes for the incident.
The Overview tab displays the field information along with the field labels, including when you're in read mode.
For more information on the fields displayed on the Overview tab, see View and update incident information on the Overview tab.
You can customize the display of the information on the Overview tab. For more information, see Customize the Overview tab for an incident.
Investigation tab
This tab enables you to investigate any affected CIs with the ci_computer or ci_server class associated with the incidents. The tab displays the metrics information of the associated primary CI or any affected CI that is selected, which helps you to analyze and resolve the issue. You can use the various remedial actions on this tab to resolve the CI-related issues.
By default, the tab displays metrics information of the primary affected CI associated with the incident. But you can also select and view the information for any affected CI with the ci_computer or ci_server class that is associated with the incident. For information about how you can set up Investigation Framework, see Setting up Investigation Framework in Service Operations Workspace.
- The tab is visible only if the Agent Client Collector (ACC) or Microsoft Endpoint Configuration Manager (MECM) adapters are installed and configured.
- The tab displays the metrics information for the CI only in the following conditions:
- Agent Client Collector or Microsoft Endpoint Configuration Manager (MECM) is installed for the associated CI. This helps to retrieve the metrics data for the CI.
- The associated CI class is a CMDB CI computer.
- This feature supports only the macOS, Windows, and Linux operating systems.
You can also customize the display of the metrics information on this tab. For more information, see Customize the Investigate tab.
For more information on the metrics displayed on this tab, see Features of the Investigation tab.
Communicate tab
- For a major incident - The Major Incident Management (sn-sow-mim) plugin is active and configured in Admin Center, for Service Operations Workspace. For more information, see Setting up Major Incident Management in Service Operations Workspace.
- For Incident – The Task Communications Management and Incident Communications Management applications are installed, active, and configured in the instance and you select the New Communication option from the More Actions (
) icon of the Incident record page. For more information, see Task Communications Management and Incident Communications Management.
Post incident report tab
- Major Incident Management is active and configured in Admin Center for Service Operations Workspace. For more information, see Setting up Major Incident Management in Service Operations Workspace.
- The major incident is in the Resolved state.
Details tab
This tab displays detailed information about the incident. For example, the short description, assignment details, and related records. For more information on how you can configure fields in this tab, see Configure a task record form in Service Operations Workspace.
Related records tab
This tab provides a list view of the records associated with the incident. For example, task SLAs and affected CIs.
Contextual side panel
From this section, you can view record information and recommendations, collaborate using Microsoft Teams, and reach out to experts on-call to resolve incidents quickly.
For more information about Incident Management, see Incident Management.