AI triage for fresh ServiceNow P1 and P2 incidents in Slack

By General Input

Every 15 minutes during business hours, new high-priority ServiceNow incidents land in Slack pre-classified with a plain English summary and a suggested assignment group.

Integrations

  • ServiceNow
  • Slack Bot

Type

Agentic Task

Categories

  • Engineering
  • Operations

Build an agent workflow that triages fresh high-priority ServiceNow incidents and posts a pre-classified summary into Slack so responders can act without manually skimming the queue.

Trigger: a cron schedule that fires every 15 minutes during business hours (default to weekdays 8am to 6pm in the workspace's local time, but make this easy to change). ServiceNow does not have a first-class poll trigger here, so use cron and filter on the server side.

On each run, call the ServiceNow List Incidents action with a sysparm_query that filters to: state = 1 (New), priority IN 1,2, and sys_created_on greater than 15 minutes ago. Ask ServiceNow for display values so caller_id and cmdb_ci come back as human-readable names, and include at minimum: number, sys_id, short_description, description, priority, state, caller_id, cmdb_ci, assignment_group, category, subcategory, sys_created_on.

For each incident returned, reason over the short_description, description, caller, and affected configuration item to produce:

1) A best-guess category and subcategory drawn from common ITSM taxonomies (network, hardware, software, database, access, email, etc.) or from any taxonomy the user has shared with the agent.

2) A suggested assignment group name. If the user has shared a list of real group names, pick from that list; otherwise propose a sensible generic name and flag that it is a guess.

3) A one-paragraph plain English summary (three to five sentences) covering the observed symptom, the likely user or business impact, and a recommended first action for the responder.

Then call the ServiceNow Update or Resolve Incident action to append the classification and assignment suggestion to the incident's work_notes field. Format the work note clearly as an AI suggestion, for example: "AI triage suggestion — Category: Network / WAN. Suggested assignment group: Network Operations. Summary: ..." Do not change state, priority, assigned_to, or assignment_group; humans make the final call.

Finally, post one Slack message per incident to a dedicated channel (default #incident-triage, configurable) using the Slack Bot Send a Message action. Use Slack mrkdwn formatting with a structure like:

• A header line with a priority badge (🔴 for P1, 🟠 for P2), the incident number, and the short description. • Caller and affected configuration item. • AI summary paragraph. • Suggested category / subcategory and suggested assignment group, clearly labeled as AI suggestions. • A deep link back to the ServiceNow record using the instance URL plus /nav_to.do?uri=incident.do?sys_id={sys_id}.

Behavior rules: never escalate, reassign, resolve, or close incidents automatically — the agent only reads, writes work_notes, and posts to Slack. If the List Incidents call returns zero new incidents, do nothing (no "all clear" message). If a Slack post fails, retry once; if a ServiceNow update fails, still post to Slack so responders are not blind. Keep the schedule window aligned with the cron cadence so an incident is posted exactly once.

Inputs to ask the user during setup: ServiceNow connection, Slack Bot connection, target Slack channel, business hours window, list of real assignment group names (optional but improves suggestions), and any taxonomy hints for category/subcategory.

Related prompts

Explore more prompts
A brand asset library your marketing team actually searchesTurn Mailjet email clicks into ranked HubSpot follow-upsClean out the Looker dashboards and Looks nobody opensLiveKit live operations console for room moderationWake up dormant Keap leads with a researched reasonLiveChat coverage board for planning next week's shiftsPhone routing control panel for LiveKit voice agentsLinkedIn Ads budget pacing dashboard for every client accountGive your team Looker numbers without buying more seatsPause marketing emails to escalated customers, then restore them