Service management deep-dive · LessonBy Sneha I, ServiceNow Trainer, 8 yrs · Published · ServiceNow · all levels
Major incident management
Promote, communicate and review major incidents with the shipped MIM process.
Quick answer
Promote, communicate and review major incidents with the shipped MIM process.
Key takeaways
- Promotion is a controlled step, not a checkbox anyone ticks
- The workbench centralises updates, tasks and child incidents
- Root cause belongs in a problem record
- Review actions need owners and dates or they evaporate
Promotion
A candidate is proposed by an ITIL user or triggered by criteria, then a major incident manager promotes or rejects it. Promotion sets the major incident flag, opens the communication tooling and starts the timeline that the post incident review depends on.
Communication
The workbench gives one place for status updates, tasks and the child incident list. Communication plans define who receives updates and how often, which stops the ad hoc mail storm that usually accompanies an outage.
After the event
Post incident review is where the value is.
- Link child incidents so impact is measurable
- Record the timeline as it happens, not from memory afterwards
- Create a problem record for root cause, keep it separate from the incident
- Track the actions from the review as change or problem tasks so they actually land
Practice challenge
+0 XPStreak ×0
Question 1 of 2
What links user impact to a major incident?
Frequently asked questions
Who should be able to promote?
A small named group, usually service desk leads and major incident managers. Uncontrolled promotion devalues the process.
Do we need a separate table?
No. Major incidents are incidents with a flag and extra process, which keeps reporting and history in one place.