Skip to content
IT Canvass
Service management deep-dive · Lesson

Incident management

Quick answer

Incident Management is the flagship ITSM process and where most people first meet ServiceNow. Its ITIL goal is precise: restore normal service operation as quickly as possible and minimise business impact, while keeping users informed. It is deliberately about speed of restoration, not root cause; that is Problem Management's job.

Key takeaways

  • What an incident is (and isn't)
  • Priority is derived, not typed
  • The lifecycle
  • Major incidents
  • How incident connects to everything else

Incident Management is the flagship ITSM process and where most people first meet ServiceNow. Its ITIL goal is precise: restore normal service operation as quickly as possible and minimise business impact, while keeping users informed. It is deliberately about speed of restoration, not root cause; that is Problem Management's job.

Incident lifecycle in ServiceNow: from logging through resolution and closure.
Incident lifecycle in ServiceNow: from logging through resolution and closure.

What an incident is (and isn't)

An incident is an unplanned interruption or degradation of a service. It lives on the incident table, which extends task, inheriting number, assignment group, state and priority, and adding caller, category, impact, urgency, resolution code/notes. Crucially, a request for something new is not an incident, it belongs in the Service Catalog.

Priority is derived, not typed

Agents don't pick priority directly, it is calculated from a Priority lookup of Impact x Urgency, keeping prioritisation consistent org-wide:

Impact (how widespread) x Urgency (how time-critical) = Priority High x High --> P1 Critical High x Med --> P2 High Med x Med --> P3 Moderate Low x Low --> P5 Planning

The mapping is a Priority Data Lookup table you can tune per organisation.

The lifecycle

New
Logged, not yet picked up.
In Progress
Assigned and being worked.
On Hold
Waiting, on caller, on a change, on a vendor (with a reason).
Resolved
Fix applied; resolution code + notes required.
Closed
Confirmed/auto-closed after a wait period.

State movement is governed by UI/data policies and business rules (e.g. resolution notes become mandatory at Resolved), and timers are tracked by SLAs.

Major incidents

Major Incident Management (MIM) is a dedicated overlay for P1/P2 outages: a promotion process, a Major Incident workbench, timelines, comms tasks and stakeholder updates, because a critical outage needs coordination the standard flow doesn't provide.

How incident connects to everything else

Common mistakes

  • Using incidents for service requests, those belong in the catalog.
  • Letting agents override priority instead of setting impact/urgency correctly.
  • Resolving without a resolution code, so trend reporting is useless.
  • No MIM process, so major outages are coordinated over ad-hoc chat.

Want to learn this properly?

Our live, instructor-led ServiceNow Training covers this hands-on, with real projects and a certification path.

Check your understanding

  1. Priority in ServiceNow is derived from which two fields?

    • A. Impact and urgency
    • B. Category and state
    • C. Caller and group
    Show answer

    A. Impact and urgency

    The priority matrix multiplies impact by urgency.

  2. Which state means work is paused waiting on the caller or a vendor?

    • A. Resolved
    • B. On Hold
    • C. New
    Show answer

    B. On Hold

    On Hold pauses the incident clock while you wait.

  3. An incident is best described as:

    • A. A request for new hardware
    • B. An unplanned service interruption
    • C. A scheduled change
    Show answer

    B. An unplanned service interruption

    Incidents are unplanned interruptions to service.

Frequently asked questions

What does the term Incident management refer to in ServiceNow?

Incident Management is the flagship ITSM process and where most people first meet ServiceNow. Its ITIL goal is precise: restore normal service operation as quickly as possible and minimise business impact, while keeping users informed.

Which tables and records are involved in Incident management?

An incident is an unplanned interruption or degradation of a service. It lives on the incident table, which extends task, inheriting number, assignment group, state and priority, and adding caller, category, impact, urgency, resolution code/notes.

What is the practical takeaway on Incident management?

Crucially, a request for something new is not an incident, it belongs in the Service Catalog.

What tends to go wrong with Incident management?

Using incidents for service requests, those belong in the catalog. Letting agents override priority instead of setting impact/urgency correctly. Resolving without a resolution code, so trend reporting is useless.
CallWhatsAppEnquire