Incident creation agent
11 min
minimum version 2026 1 the incident creation agent enables users to report issues using natural language and automatically creates incidents with the relevant details, ensuring faster and more accurate incident logging to enable and configure the incident creation agent, do the following log in to as an open the configuration console and select ai configuration hub > agentic ai > agent settings enable the incident creation agent using the toggle button an additional toggle button with the same function is available in the upper right corner of the agent page click configure to further set up the agent under knowledge base settings > suggest articles before ticket creation , enable the toggle button if you want the agent to suggest knowledge articles before creating an incident under knowledge base settings > user can skip viewing knowledge base , enable the toggle button to provide users an option to skip the knowledge article search and go directly to incident creation in skip button name , enter a custom name for the skip button according to your preference under messaging > successful creation , enter a success message that the agent shows after the successful incident creation you can add and in the message, which displays the incident id and link to the incident record under incident handling , configure the following settings a default incident template set any incident template as default from the dropdown when the agent cannot find the right incident template for a user's query, it will use the default incident template for the incident creation to view the available templates, go to incident business object > quick actions > edit actions > graphical action designer / classic action designer > your actions > templates you can also create new templates using the create new actions option for more information, refer to action templates docid\ mvmlsewqvf6rgde9i amp for a user query, if there is no matching template available in the given list, the agent will choose the default template for the incident creation configure the templates for every saved template, you must provide values for all mandatory fields based on the form selected in the default published incident form dropdown the selected form contains several mandatory fields that the agent needs to prefill during incident creation while the agent can predict and prefill some fields based on the user’s query, it cannot reliably predict values for all mandatory fields for example, the following image shows an incident form and its mandatory fields the agent can predict and prefill summary and description from the user’s query, but it cannot predict fields such as team and owner the agent cannot predict team and owner details because these values are organization specific therefore, administrators must provide values for such mandatory fields in the template when creating an incident, the agent captures the mandatory field values from the template and uses them to prefill the incident form automatically if you don’t fill a mandatory field for the incident form in the template and the agent cannot predict the value, the agent will prompt the user for the information this is not advisable because the field may not be adequately populated to select the field value, or the user may not have access to the information requested by the agent ensure the fields added in the template are available in the default published incident form , otherwise the field will not appear in the incident record b default published incident form select the appropriate incident form from the dropdown the form helps understand the fields required for incident creation when a user opts for incident creation therefore, ensure that all the required fields are present in the form for incident creation if any required fields are missing in the form, you can create them from the incident business object > fields tab and then update the form to update the form, go to incident business object > forms tab > open the relevant form for more information, refer to using forms docid 5dd6rlsb123v5tlqc9wfn c ci mining question depth enter the maximum number of questions the incident agent can ask to identify a specific user device d incident description question depth enter the maximum number of questions the incident agent can ask to better understand the user’s problem e device mining enable this toggle to allow the incident agent to search for possible devices that users might be experiencing issues with if disabled, the agent does not ask about the device and creates the incident without device information if the agent cannot find the device through device mining, it prompts the user to manually provide the device name to ensure successful device mining, configure the following maintain device records in the ci define the employee ci relationships agentic configuration for employee ci relationships enable the full text indexed option for relevant ci fields maintain device records in the ci for agents to identify devices managed within your organization, ensure that device information is configured in configuration items (ci) the ci business object helps maintain a reliable record of the devices, enabling easy tracking agents for more information, refer to working with configuration items docid\ a1imnpws7axa7x4ko5lxr define the employee – ci relationships to configure an employee – ci relationship, open the employee business object > relationships tab for the agent to identify the devices linked to a user/employee, you should configure the relationships between devices managed in ci records and associated users in your organization the relationships configured here are used by the agent for device mining for more information, refer to using relationships docid\ szcp qyw98hbg7iwleeu2 agent configuration for employee – ci relationships for the agents to understand the relationship between an employee and ci, you must configure the relationship information in the agentic configuration workspace as well to configure a relationship log in to as an administrator from the top header bar, select more to open the workspace selector using the search objects field, open the agentic configuration workspace click new ivnt agenticconfiguration enter the following details created by the name of the admin who created the record created on the date and time when the record was created use the calendar icon to select the value modified by the name of the user who last modified the record modified on the date and time of the most recent modification use the calendar icon to select the value configuration configure the required relationship names by referring to employee record > relationship tab enable the full text indexed option for relevant ci fields to enable full text search on relevant fields, go to ci business object > fields tab, and enable full‑text indexed option the ci business object contains multiple device‑related fields, such as model number, model name, and serial number for effective device identification, it is important to anticipate the type of device information users are likely to provide when prompted by an agent to allow agents to search devices using this information, enable the full‑text indexed option for corresponding fields by default, some fields are already enabled for full‑text indexing for more information, refer to about the different search types docid 9m an q i w5g n07a13 f allow transfer to live agent enable the toggle button to transfer the interaction to your service desk human agent in case the agentic ai bot cannot solve the user's request along with this toggle, you must also enable the allow transfer to live agent toggle in global settings > escalation handling under advanced settings > incident description , define the scope of the incident agent by detailing the types of incident queries the agent can handle you can also provide some example queries related to incidents to help the agent better understand the context when users ask queries other than those defined here, the agent considers them out of context and replies to users accordingly modifying the intent description might result in unpredictable agent behavior we recommend that only users with experience in llm prompt engineering make these changes fields marked with an asterisk ( ) are mandatory analytics to view the performance metrics and usage statistics for your incident creation agent, open the configuration console and select ai configuration hub > agentic ai > agent settings > incident creation agent > configure > analytics the analytics page provides the performance of the incident creation agent it helps you monitor the following metrics number of incident agent interactions the total number of interactions initiated with the incident creation agent each interaction represents an incident related conversation tracked by the agent number of incidents deflected through ks the number of incident related interactions that were resolved through knowledge article without creating an incident percentage of incidents deflected through ks the percentage of incident related interactions that were resolved through knowledge article without creating an incident number of incidents created by ia the total number of incidents created through the incident creation agent number of transfers to live agents the number of incident related interactions that were successfully transferred to a live agent percentage of incident transferred to live agents the percentage of incident related interactions that resulted in a successful transfer to a live agent incident creation rate the percentage of incident related interactions that resulted in successful incident creation the time range filter allows users to specify the period for which analytics data is displayed metrics on the analytics page are updated based on the selected time range limitations while interacting with the incident creation agent, certain query types prompt the agent to ask the user to upload a screenshot or image of the error however, uploading screenshots, attachments, or supporting documents is currently not supported by agentic ai when creating an incident, after the incident draft is presented to the user, the user cannot modify the incident priority by simply stating, for example, this is a high priority issue the agentic ai determines the incident priority based on the incident description when creating a new incident, the agentic ai does not search for previously created similar incidents and their resolutions as a result, multiple identical or similar incidents can be created during live agent transfer, a conversation summary should be sent to the live agent at the beginning of the session this functionality is currently not working at the end of a live agent transfer session, users are not informed about what to do next however, when the session ends, the agentic ai is reset and users should initiate a new prompt, even if no live agent was available the agentic ai handles only it‑related issues other line of business (lob) queries, such as hr, facilities, and other non‑it requests are not supported to create incident tickets for user queries, the incident agent uses the appropriate template from the saved templates list in some cases, the agent might have limited ability to predict certain required fields in the templates, except fields such as profile link, status, summary, description, urgency, and impact for example, fields such as team, owner, category etc therefore, we recommend that administrators prefill the required fields in all saved templates leaving these fields empty might cause the agent to ask end users for the field values or might even prevent incident creation if you add employeeassociatedci to the configuration fields on the agent configuration page, only the devices associated with the employee through employeeassociatedci are considered for device mining by default
