IT CanvassTalk to an advisor
Service management deep-dive · LessonBy , ServiceNow Trainer, 8 yrs · Published · current release · beginner

Incident management

Restore service fast when something breaks, the most-used process in ServiceNow.

Quick answer

Incident Management is the flagship ITSM process and where most people first meet ServiceNow. Its ITIL goal is precise: restore normal service operation as quickly as possible and minimise business impact, while keeping users informed. It is deliberately about speed of restoration, not root cause; that is Problem Management's job.

Key takeaways
  • What an incident is (and isn't)
  • Priority is derived, not typed
  • The lifecycle
  • Major incidents
  • How incident connects to everything else

Incident Management is the flagship ITSM process and where most people first meet ServiceNow. Its ITIL goal is precise: restore normal service operation as quickly as possible and minimise business impact, while keeping users informed. It is deliberately about speed of restoration, not root cause; that is Problem Management's job.

Incident lifecycle in ServiceNow: from logging through resolution and closure.
Incident lifecycle in ServiceNow: from logging through resolution and closure.

What an incident is (and isn't)

An incident is an unplanned interruption or degradation of a service. It lives on the incident table, which extends task, inheriting number, assignment group, state and priority, and adding caller, category, impact, urgency, resolution code/notes. Crucially, a request for something new is not an incident, it belongs in the Service Catalog.

Priority is derived, not typed

Agents don't pick priority directly, it is calculated from a Priority lookup of Impact x Urgency, keeping prioritisation consistent org-wide:

Impact (how widespread) x Urgency (how time-critical) = Priority High x High --> P1 Critical High x Med --> P2 High Med x Med --> P3 Moderate Low x Low --> P5 Planning

The mapping is a Priority Data Lookup table you can tune per organisation.

The lifecycle

New
Logged, not yet picked up.
In Progress
Assigned and being worked.
On Hold
Waiting, on caller, on a change, on a vendor (with a reason).
Resolved
Fix applied; resolution code + notes required.
Closed
Confirmed/auto-closed after a wait period.

State movement is governed by UI/data policies and business rules (e.g. resolution notes become mandatory at Resolved), and timers are tracked by SLAs.

Major incidents

Major Incident Management (MIM) is a dedicated overlay for P1/P2 outages: a promotion process, a Major Incident workbench, timelines, comms tasks and stakeholder updates, because a critical outage needs coordination the standard flow doesn't provide.

How incident connects to everything else

Common mistakes

  • Using incidents for service requests, those belong in the catalog.
  • Letting agents override priority instead of setting impact/urgency correctly.
  • Resolving without a resolution code, so trend reporting is useless.
  • No MIM process, so major outages are coordinated over ad-hoc chat.

Authoritative sources

  • ServiceNow Incident Management docs - Incident application reference
  • ITIL 4 (Axelos) - Incident-management practice definition

Practice challenge

+0 XPStreak ×0
Question 1 of 3
Priority in ServiceNow is derived from which two fields?

FAQ

What is ITSM in ServiceNow?

ITSM (IT Service Management) is ServiceNow's original and best-known set of applications for running IT as a service: incident, problem, change, request and knowledge management, all on one workflow engine and data model.

Frequently asked questions

What does the term Incident management refer to in ServiceNow?
Incident Management is the flagship ITSM process and where most people first meet ServiceNow. Its ITIL goal is precise: restore normal service operation as quickly as possible and minimise business impact, while keeping users informed.
Which tables and records are involved in Incident management?
An incident is an unplanned interruption or degradation of a service. It lives on the incident table, which extends task, inheriting number, assignment group, state and priority, and adding caller, category, impact, urgency, resolution code/notes.
What is the practical takeaway on Incident management?
Crucially, a request for something new is not an incident, it belongs in the Service Catalog.
What tends to go wrong with Incident management?
Using incidents for service requests, those belong in the catalog. Letting agents override priority instead of setting impact/urgency correctly. Resolving without a resolution code, so trend reporting is useless.
Already working on ServiceNow and stuck on a live ticket?Get an expert ServiceNow developer on screen-share to finish your daily tasks with you. Deliver on time, protect your reputation and your job. Monthly support only, no task-wise plans.Task assigned · no idea where to startStill stuck · your job on the lineExpert joins your screenDelivered on timeExplore On Job Support