Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Incident Management in Service Operations Workspace

You can create and manage your incidents in Service Operations Workspace.

[Omitted video] Description: Introduction to incident management

Image omitted: sow-incident-tabs-header-new.gif
Tabs of an incident record

Overview tab

This tab displays the following information about an incident:

  • Summary
  • Impact
  • Cause
  • Resolution

From the Compose section, you can add comments and work notes for the incident.

The Overview tab displays the field information along with the field labels, including when you're in read mode.

For more information on the fields displayed on the Overview tab, see View and update incident information on the Overview tab.

You can customize the display of the information on the Overview tab. For more information, see Customize the Overview tab for an incident.

Investigation tab

This tab enables you to investigate any affected CIs with the ci_computer or ci_server class associated with the incidents. The tab displays the metrics information of the associated primary CI or any affected CI that is selected, which helps you to analyze and resolve the issue. You can use the various remedial actions on this tab to resolve the CI-related issues.

By default, the tab displays metrics information of the primary affected CI associated with the incident. But you can also select and view the information for any affected CI with the ci_computer or ci_server class that is associated with the incident. For information about how you can set up Investigation Framework, see Setting up Investigation Framework in Service Operations Workspace.

Note:

  • The tab is visible only if the Agent Client Collector (ACC) or Microsoft Endpoint Configuration Manager (MECM) adapters are installed and configured.
  • The tab displays the metrics information for the CI only in the following conditions:
    • Agent Client Collector or Microsoft Endpoint Configuration Manager (MECM) is installed for the associated CI. This helps to retrieve the metrics data for the CI.
    • The associated CI class is a CMDB CI computer.
  • This feature supports only the macOS, Windows, and Linux operating systems.

You can also customize the display of the metrics information on this tab. For more information, see Customize the Investigate tab.

For more information on the metrics displayed on this tab, see Features of the Investigation tab.

Communicate tab

This tab displays all the communication tasks and options that enable you to communicate with the stakeholders in the various phases of an incident. This tab is available only if any of the following conditions are met:

  • For a major incident - The Major Incident Management (sn-sow-mim) plugin is active and configured in Admin Center, for Service Operations Workspace. For more information, see Setting up Major Incident Management in Service Operations Workspace.
  • For Incident – The Task Communications Management and Incident Communications Management applications are installed, active, and configured in the instance and you select the New Communication option from the More Actions (
Image omitted: mim-more-actions-top-icon.png
More actions icon\) icon of the Incident record page. For more information, see [Task Communications Management](../../servicenow-platform/task-communications-management/tcm-landing-page.md) and [Incident Communications Management](../incident-communications-management/c_IncidentAlertManagement.md).

For more information on the features of the Communicate tab, see Communicating with stakeholders about incidents and major incidents in SOW.

Post incident report tab

This tab enables you to generate, configure, publish, and export a post incident report for a major incident after it's resolved. The post incident report enables you to review the cause and resolution of the major incident and also identify potential process gaps. Based on this information, you can take preventive measures to avoid the issue in the future or to handle the major incident in a better way. This tab is available only if the following conditions are met:

For more information on the features of the Post incident report tab, see Review and update a post incident report.

Details tab

This tab displays detailed information about the incident. For example, the short description, assignment details, and related records. For more information on how you can configure fields in this tab, see Configure a task record form in Service Operations Workspace.

This tab provides a list view of the records associated with the incident. For example, task SLAs and affected CIs.

Contextual side panel

From this section, you can view record information and recommendations, collaborate using Microsoft Teams, and reach out to experts on-call to resolve incidents quickly.

For more information about Incident Management, see Incident Management.

Parent Topic:Operating IT services in your organization

Related topics

Play a guided tour in Service Operations Workspace

Add a user-specific quick link on the ITSM landing page

Live Agent chat in Service Operations Workspace

Interaction Management in Service Operations Workspace

Request Management in Service Operations Workspace

Change Management in Service Operations Workspace