Ch. 17 · ServiceNow

ServiceNow Incident, Problem and Change Roles

ServiceNow Incident, Problem and Change Roles. Learn the reasoning, a practical example, common mistakes and an interview exercise.

~2 min readbeginnerupdated Oct 3, 2026

Incident management restores service; problem management investigates causes; change management governs modifications. Related records represent different goals.

Before you start

You should understand tables, records and the difference between client-side and server-side scripts. Work in a development instance with representative permissions. Identify execution scope, transaction timing and the current user before attributing behavior to a platform script or business rule.

The practical goal is to reason through this situation: Restore a failing service through an incident, investigate recurrence through a problem and govern the permanent fix as a change. Read the walkthrough first, then try the interview exercise before opening its answer. The important part is explaining the decision and its consequences, rather than remembering a definition alone.

Step-by-step walkthrough

Step 1: Restore the service

An incident tracks immediate disruption and restoration.

Step 2: Investigate recurring cause

A problem record owns deeper evidence and prevention work.

Step 3: Govern the corrective change

A change controls implementation risk and approval where required.

Worked scenario

Restore a failing service through an incident, investigate recurrence through a problem and govern the permanent fix as a change.

An outage is mitigated by restarting a component, restoring users while the underlying defect remains. Repeated occurrences justify a linked problem investigation. The permanent configuration fix proceeds through the applicable change process; closing the incident does not prove the cause has been removed.

Common mistake

Converting every incident into a problem adds overhead without establishing investigation value.

Verify the behavior

Trace restoration, investigation and implementation outcomes as distinct linked records.

Interview exercise

Describe a recurring outage workflow.

Answer and reasoning

Explain restoration first, evidence gathering second and controlled corrective change, retaining links between the records.

Continue learning

Compare the scenario with the ServiceNow interview questions and test your understanding with the ServiceNow MCQs. For terminology and implementation details, consult the reference material.

More in ServiceNow

read ✓ServiceNow · hard

ServiceNow ACL Scripting and Access

Enforce access with ACLs, use scripted conditions carefully, and test as the actual user to verify.

~2 min readread →
read ✓ServiceNow · hard

ServiceNow Caching and Invalidation

Understand what the platform caches, when a change takes effect, and how to flush caches consistently across nodes.

~2 min readread →
read ✓ServiceNow · mid

ServiceNow Dictionary and Field Audit

Define fields in the dictionary, use per-table overrides, and enable audit on the fields that need a history.

~2 min readread →
esc