Semantius Logo

Incident Management

1. Overview

Capture, triage, route, and resolve service-disrupting incidents. Includes major-incident command, AI-assisted classification, and skill-based assignment.

2. Entity summary

Namedata_objectDescription
Incidentsservice_incidentsUnplanned service interruptions or quality reductions, with severity, priority, category, assignee, and affected components.
Service Outagesservice_outagesCustomer-facing outage records, with the affected service, public status, start and end times, and the customer message.
Asset Lifecycle Eventsasset_lifecycle_eventsCross-cutting lifecycle log for hardware, software, and SaaS assets: procurement, deployment, transfer, retirement, and disposal.
Configuration Itemsconfiguration_itemsCanonical records of IT things under management: servers, containers, applications, services, network devices, databases, and cloud resources.
LocationslocationsPhysical or organizational locations referenced across the system, used to place and group other records.
Org Unitsorg_unitsNodes in the organizational hierarchy such as divisions, departments, and teams, with manager, cost center alignment, geographic scope, and parent-child links.
Alertsmonitoring_alertsFiltered, human-relevant events that crossed a threshold or matched a pattern, enriched with priority and routing, ready to be paged or ticketed.
Error Groupserror_groupsAggregated exception records grouped by fingerprint, with first and last seen, occurrence count, affected releases, owners, and status.
SLOsservice_level_objectivesService-level objective definitions and their breach state, with targets, remaining error budget, burn rate, and last breach.
flowchart TD
  classDef master fill:#d4f4dd,stroke:#27ae60,color:#0b3d20;
  classDef embedded_master fill:#fff4cc,stroke:#c79100,color:#5b4500;
  classDef consumer fill:#e8def8,stroke:#7b1fa2,color:#3a155d;
  classDef platform_builtin fill:#e0e0e0,stroke:#424242,color:#1a1a1a;
  service_incidents["Incidents"]
  error_groups["Error Groups"]
  service_level_objectives["SLOs"]
  configuration_items["Configuration Items"]
  monitoring_alerts["Alerts"]
  locations["Locations"]
  org_units["Org Units"]
  asset_lifecycle_events["Asset Lifecycle Events"]
  service_outages["Service Outages"]
  users["Users"]
  configuration_items -->|"triggers"| service_incidents
  service_incidents -->|"references"| configuration_items
  service_incidents -->|"correlates_to"| monitoring_alerts
  service_incidents -->|"correlates_to"| error_groups
  org_units -->|"rolls_up_to"| org_units
  locations -->|"rolls_up_to"| locations
  users -->|"logged events"| asset_lifecycle_events
  users -->|"owned CIs"| configuration_items
  users -->|"assigned_monitoring_alerts"| monitoring_alerts
  users -->|"leads"| org_units
  users -->|"assigned"| asset_lifecycle_events
  users -->|"assigned incidents"| service_incidents
  users -->|"reported incidents"| service_incidents
  org_units -->|"has members"| users
  locations -->|"houses"| users
  class service_incidents master;
  class error_groups consumer;
  class service_level_objectives consumer;
  class configuration_items embedded_master;
  class monitoring_alerts consumer;
  class locations embedded_master;
  class org_units embedded_master;
  class asset_lifecycle_events embedded_master;
  class service_outages master;
  class users platform_builtin;
  style error_groups stroke-dasharray:5 5;
  style service_level_objectives stroke-dasharray:5 5;
  style monitoring_alerts stroke-dasharray:5 5;
  style locations stroke-dasharray:5 5;
  style org_units stroke-dasharray:5 5;
  style asset_lifecycle_events stroke-dasharray:5 5;

3. Entities catalog

#data_objectcanonical codesingularpluralrolemastered inmastered labelnecessitypersonal_contententity_typewrite tiernotes
1service_incidentsservice_incidentsIncidentIncidentsmaster--requiredyesoperational_workflow:manage-
2service_outagesservice_outagesService OutageService Outagesmaster--required-operational_workflow:manage-
3asset_lifecycle_eventsasset_lifecycle_eventsAsset Lifecycle EventAsset Lifecycle Eventsembedded_masteritam-lifecycleUnified Asset Lifecycle Logoptional-operational_record:manage-
4configuration_itemsconfiguration_itemsConfiguration ItemConfiguration Itemsembedded_mastercmdb-coreCMDB Core Repositoryrequired-operational_workflow:manage-
5locationslocationsLocationLocationsembedded_masteriwms-location-masterLocation and Property Masteroptional-catalog:admin-
6org_unitsorg_unitsOrg UnitOrg Unitsembedded_masterhcm-org-positionsOrganization and Position Managementoptional-operational_workflow:manage-
7monitoring_alertsmonitoring_alertsAlertAlertsconsumeritom-infra-monInfrastructure Monitoring and Event Managementoptional-operational_workflow:manage-
8error_groupserror_groupsError GroupError Groupsconsumer--optional-operational_workflow:manage-
9service_level_objectivesservice_level_objectivesSLOSLOsconsumer--optional-operational_workflow:manage-

4. Aliases and industry synonyms

(none: no industry-scoped aliases for this scope)

5. Relationships

5.1 Intra-scope edges

fromverbtocardinalitykindnecessityowner_sidedelete_modefk_formatnotes
configuration_itemstriggersservice_incidentsone_to_manyreferenceoptionaltargetclearreference-
service_incidentsreferencesconfiguration_itemsmany_to_manyreferenceoptionaltargetclearreference-
service_incidentscorrelates_tomonitoring_alertsmany_to_manyreferenceoptionaltargetclearreference-
service_incidentscorrelates_toerror_groupsmany_to_manyreferenceoptionaltargetclearreference-
org_unitsrolls_up_toorg_unitsone_to_manyreferenceoptionalsourceclearreference-
locationsrolls_up_tolocationsone_to_manyreferenceoptionalsourceclearreference-

5.2 Built-in edges (users and other platform built-ins)

fromverbtocardinalitynecessityowner_sidedelete_modefk_formatnotes
userslogged eventsasset_lifecycle_eventsone_to_manyoptionalsourceclearreference-
usersowned CIsconfiguration_itemsone_to_manyoptionalsourceclearreference-
usersassigned_monitoring_alertsmonitoring_alertsone_to_manyoptionalsourceclearreference-
usersleadsorg_unitsone_to_manyoptionalsourceclearreference-
usersassignedasset_lifecycle_eventsone_to_manyoptionalsourceclearreference-
usersassigned incidentsservice_incidentsone_to_manyoptionalsourceclearreference-
usersreported incidentsservice_incidentsone_to_manyrequiredsourcerestrictreference-
org_unitshas membersusersone_to_manyoptionaltargetclearreference-
locationshousesusersone_to_manyoptionaltargetclearreference-

5.3 Cross-scope edges

5.3a Outbound from this scope’s masters and contributors

Edges this scope drives: the in-scope endpoint has role of master or contributor.

fromverbtocardinalitynecessitydelete_modefk_formatnotes
service_incidentstriggersremediation_plansone_to_manyoptionalnonen/a-
application_interfacesraisesservice_incidentsone_to_manyoptionalnonen/a-
service_mapsrefreshesservice_incidentsmany_to_manyoptionalnonen/a-
ci_baselinestriggersservice_incidentsone_to_manyoptionalnonen/a-
chat_threadsescalates_toservice_incidentsone_to_manyoptionalnonen/a-
control_testsescalates_toservice_incidentsone_to_manyoptionalnonen/a-
test_defectsescalates_toservice_incidentsone_to_manyoptionalnonen/a-
lcap_appsopensservice_incidentsmany_to_manyoptionalnonen/a-
dlp_incidentsinforms_security_incidentservice_incidentsone_to_manyoptionalnonen/a-
onboarding_tasksemitsservice_incidentsone_to_manyoptionalnonen/a-
service_requestsroutes_toservice_incidentsone_to_manyoptionalnonen/a-
service_requeststriggersservice_incidentsone_to_manyoptionalnonen/a-
service_problemsis investigated byservice_incidentsone_to_manyoptionalnonen/a-
service_slasgoverns incidentservice_incidentsone_to_manyrequirednone (required-if-present)n/a-
service_incidentsresolved_withknowledge_articlesmany_to_manyoptionalnonen/a-
eam_work_ordersescalates_toservice_incidentsone_to_manyoptionalnonen/a-
event_correlationstriggersservice_incidentsone_to_manyoptionalnonen/a-
root_cause_analysesannotatesservice_incidentsone_to_manyoptionalnonen/a-
incident_predictionsforecastsservice_incidentsone_to_manyoptionalnonen/a-
dc_cabinetsraisesservice_incidentsone_to_manyoptionalnonen/a-
dc_power_distribution_unitsraisesservice_incidentsone_to_manyoptionalnonen/a-
dc_uninterruptible_power_suppliesraisesservice_incidentsone_to_manyoptionalnonen/a-
dc_cooling_unitsraisesservice_incidentsone_to_manyoptionalnonen/a-
endpoint_experience_scorestriggersservice_incidentsone_to_manyoptionalnonen/a-
saas_applicationsraises_incidentservice_incidentsone_to_manyoptionalnonen/a-

5.3b Context edges on embedded shells and consumed entities

Edges the canonical owner drives, shown for context: the in-scope endpoint has role of embedded_master, consumer, or derived.

fromverbtocardinalitynecessitydelete_modefk_formatnotes
fixed_assetsimpacted by lifecycleasset_lifecycle_eventsone_to_manyoptionalnonen/a-
service_changesupdatesconfiguration_itemsmany_to_manyoptionalnonen/a-
enterprise_applicationsmapped_toconfiguration_itemsmany_to_manyoptionalnonen/a-
technology_platformsregisters_asasset_lifecycle_eventsone_to_manyoptionalnonen/a-
enterprise_applicationsonboards_intoconfiguration_itemsone_to_oneoptionalnonen/a-
ci_classesclassifiesconfiguration_itemsone_to_manyrequirednone (required-if-present)n/a-
configuration_itemsrelated_viaci_relationshipsone_to_manyoptionalnonen/a-
configuration_itemsbaselined_inci_baselinesmany_to_manyoptionalnonen/a-
configuration_itemscomposesservice_mapsmany_to_manyoptionalnonen/a-
configuration_itemsbacked_byhardware_assetsone_to_oneoptionalnonen/a-
configuration_itemschanged_byservice_changesmany_to_manyoptionalnonen/a-
asset_contractsgovernsasset_lifecycle_eventsone_to_manyoptionalnonen/a-
saas_applicationslifecycle events forasset_lifecycle_eventsone_to_manyoptionalnonen/a-
asset_lifecycle_eventshands_off_tohardware_disposal_recordsone_to_oneoptionalnonen/a-
fixed_assetsupdated by lifecycleasset_lifecycle_eventsone_to_manyoptionalnonen/a-
hardware_assetsrepresented_asconfiguration_itemsone_to_oneoptionalnonen/a-
locationshosts_desk_bookingsdesk_bookingsone_to_manyrequirednone (required-if-present)n/a-
locationshosts_room_reservationsroom_reservationsone_to_manyrequirednone (required-if-present)n/a-
locationssite_of_service_requestsworkplace_service_requestsone_to_manyrequirednone (required-if-present)n/a-
locationsmeasured_by_reportsspace_utilization_reportsone_to_manyrequirednone (required-if-present)n/a-
locationssubject_of_feedbackworkplace_experience_feedbackone_to_manyoptionalnonen/a-
org_unitsgroupsemployeesone_to_manyrequirednone (required-if-present)n/a-
org_unitscontainshcm_positionsone_to_manyrequirednone (required-if-present)n/a-
cost_centersfundsorg_unitsone_to_manyrequirednone (required-if-present)n/a-
employeestriggersasset_lifecycle_eventsone_to_manyoptionalnonen/a-
org_unitsengagescontingent_workersone_to_manyoptionalnonen/a-
org_unitsis_scored_byengagement_driversone_to_manyoptionalnonen/a-
org_unitsis_measured_bypeople_kpisone_to_manyoptionalnonen/a-
org_unitstriggersiga_entitlement_definitionsone_to_manyoptionalnonen/a-
org_unitsmaps_tocost_centersone_to_oneoptionalnonen/a-
onboarding_taskstriggersasset_lifecycle_eventsone_to_manyoptionalnonen/a-
hardware_assetsdelivered byasset_lifecycle_eventsone_to_manyoptionalnonen/a-
org_unitssponsorscompliance_assignmentsone_to_manyoptionalnonen/a-
org_unitssponsorsbenefit_plansmany_to_manyoptionalnonen/a-
survey_campaignstargetsorg_unitsmany_to_manyoptionalnonen/a-
org_unitsownsaction_plansone_to_manyoptionalnonen/a-
service_changesgeneratesasset_lifecycle_eventsone_to_manyoptionalnonen/a-
service_changesimpactsconfiguration_itemsmany_to_manyrequirednone (required-if-present)n/a-
service_slasaligns_withservice_level_objectivesmany_to_manyoptionalnonen/a-
dc_port_connectionsupdatesconfiguration_itemsone_to_manyoptionalnonen/a-
vulnerabilitiesaffectsconfiguration_itemsone_to_manyoptionalnonen/a-

6. Cross-domain context

6.1 Master consumers (other modules / domains that embed this scope’s masters)

data_objectother module / domainrolenecessitynotes
service_incidentsIT-OPS-STARTER (IT Operations Starter) - IT-OPS-STARTERembedded_masteroptional-
service_incidentsITOM-INFRA-MON (Infrastructure Monitoring and Event Management) - ITOMcontributorrequired-
service_incidentsITSM-STARTER (IT Service Desk Starter) - ITSMembedded_masterrequired-
service_incidentsMSP-PSA-SVC-DESK (MSP Multi-Tenant Service Desk) - MSP-PSAcontributoroptional-
service_incidentsREMOTE-ACCESS-SESSION (Remote Session Control) - REMOTE-ACCESSconsumerrequired-
service_incidentsRMM-MONITORING (Monitoring and Alerting) - RMMconsumerrequired-
service_incidentsWSC-CHANNELS-CONVERSATIONS (Channels and Conversations) - WSCconsumeroptional-

6.2 Outbound handoffs (events this scope publishes)

source moduletarget domaintarget moduletrigger_eventtransitionpayloadintegrationfrictiondescription
ITSM-INCIDENT-MGMTITAMITAM-LIFECYCLEservice_incident.asset_failure(state_change)asset_lifecycle_eventsapi_callmediumIncident resolved by replacing or retiring an asset generates a lifecycle event in ITAM. Friction sits in the asset-id resolution (incidents are filed against users or symptoms, asset IDs come later).
ITAM-LIFECYCLEITAMITAM-PORTFOLIO-REPORTINGasset_lifecycle_event.recorded(state_change)asset_lifecycle_eventslifecycle_progressionlow-
HCM-ORG-POSITIONSIGAIGA-ACCESS-REQUESTorg_unit.created(state_change)org_unitsevent_streammediumNew org unit drives IGA group/role provisioning. Group-name conventions and ownership must be encoded; otherwise orphan groups proliferate.
HCM-ORG-POSITIONSIGAIGA-ACCESS-REQUESTorg_unit.disbanded(state_change)org_unitsevent_streamhighOrg-unit disbandment requires IGA group cleanup; orphan-group risk if employees re-assigned slowly.
HCM-ORG-POSITIONSIGAIGA-ACCESS-REQUESTorg_unit.merged(state_change)org_unitsevent_streamhighOrg-unit merge consolidates IGA groups: members migrate, entitlements deduplicated, SoD revalidated. Often runs as a batch project rather than event.
ITAM-LIFECYCLEHAM(domain-level)asset.retired_for_disposal(state_change)asset_lifecycle_eventsevent_streamlowRetired assets hand off to HAM disposal workflow.
HCM-ORG-POSITIONSHCMHCM-CORE-WORKERorg_unit.disbanded(state_change)org_unitslifecycle_progressionhighDisbanded org unit requires every incumbent employee to be re-placed before close; worker-record module blocks the close until reassignment completes.
HCM-ORG-POSITIONSHCMHCM-CORE-WORKERorg_unit.merged(state_change)org_unitslifecycle_progressionmediumOrg-unit consolidation cascades employee re-assignment, manager and dotted-line reassignment, and reporting-line recompute on the worker record.
HCM-ORG-POSITIONSATSATS-RECRUITMENT-PIPELINEorg_unit.activated(state_change)org_unitsapi_calllow-
HCM-ORG-POSITIONSATSATS-RECRUITMENT-PIPELINEorg_unit.closed(state_change)org_unitsapi_callhigh-
HCM-ORG-POSITIONSATSATS-RECRUITMENT-PIPELINEorg_unit.created(state_change)org_unitsapi_callmedium-
HCM-ORG-POSITIONSATSATS-RECRUITMENT-PIPELINEorg_unit.disbanded(state_change)org_unitsapi_callhigh-
HCM-ORG-POSITIONSATSATS-RECRUITMENT-PIPELINEorg_unit.merged(state_change)org_unitsapi_callhigh-
HCM-ORG-POSITIONSATSATS-RECRUITMENT-PIPELINEorg_unit.reorganized(state_change)org_unitsapi_callhigh-
ITAM-LIFECYCLEFIN(domain-level)asset_lifecycle_event.recorded(state_change)asset_lifecycle_eventsevent_streammediumAsset lifecycle events update the ERP-FIN fixed-asset register and depreciation.
HCM-ORG-POSITIONSFIN(domain-level)org_unit.created(state_change)org_unitsapi_callmediumNew org unit usually maps to cost-center; ERP-FIN must reflect the structure for budgeting and labor allocation.

6.3 Inbound handoffs (events this scope reacts to)

target modulesource domainsource moduletrigger_eventtransitionpayloadintegrationfrictiondescription
ITSM-INCIDENT-MGMTITOMITOM-INFRA-MONmonitoring_event.alert_triggered(signal)service_incidentsevent_streamhighMonitoring/alerting events from ITOM auto-create incidents in ITSM when severity and correlation rules match. High friction in practice - alert storms create incident floods, correlation rules drift, and dedupe logic between systems is rarely good enough. The classic ‘NOC-floods-the-helpdesk’ problem.
ITSM-INCIDENT-MGMTCMDBCMDB-COREci.unauthorized_change_detected(state_change)configuration_itemsapi_callmediumConfiguration drift against a CI baseline (or change without a CAB-approved change record) creates a compliance / security incident in ITSM. Friction is medium - false positives from legitimate-but-unrecorded operational tweaks are common.
ITSM-INCIDENT-MGMTDISCOVERY(domain-level)discovery_scan.failed(state_change)service_incidentsapi_callmediumFailed DISCOVERY scans open ITSM tickets for the discovery owner.
ITSM-INCIDENT-MGMTDISCOVERY(domain-level)discovery_source.disconnected(state_change)service_incidentsapi_callmediumDISCOVERY source outages auto-ticket ITSM to restore visibility.
ITSM-INCIDENT-MGMTAIOPSAIOPS-EVENT-CORRELATIONcorrelation.identifiedidentified (signal)service_incidentsevent_streamhighA correlated alert cluster surfaces as ONE incident in ITSM instead of N. The defining noise-reduction promise of AIOps - and the hardest integration to land cleanly, because suppressing the underlying alerts requires bidirectional state with ITOM, and ITSM needs to expose the correlated-events bundle as evidence on the incident.
ITSM-INCIDENT-MGMTAIOPSAIOPS-PREDICTIVE-INTELLIGENCEincident_prediction.high_confidence(signal)service_incidentsevent_streamlowPredicted incidents auto-open proactive ITSM tickets ahead of impact.
ITSM-INCIDENT-MGMTAIOPSAIOPS-PREDICTIVE-INTELLIGENCEroot_cause_analysis.published(state_change)service_incidentsevent_streamlowAIOPS RCA conclusion lands on the linked ITSM incident/problem as resolution context.
ITSM-INCIDENT-MGMTOBS(domain-level)error_group.regression_detected(signal)error_groupsapi_callmediumOBS regression on resolved error reopens ITSM problem record.
ITSM-INCIDENT-MGMTOBS(domain-level)log_entry.error_pattern_matched(signal)service_incidentsapi_callmediumCritical log patterns auto-open ITSM tickets for technician triage.
ITSM-INCIDENT-MGMTOBS(domain-level)service_level_objective.budget_exhausted(state_change)service_level_objectivesapi_callmediumExhausted SLO error budget escalates to ITSM and triggers change/release controls.
ITSM-INCIDENT-MGMTOBS(domain-level)service_level_objective.burn_rate_high(threshold)service_level_objectivesapi_callmediumOBS SLO burn-rate alerts trigger ITSM major-incident workflow.
ITSM-INCIDENT-MGMTOBS(domain-level)slo.breachedbreached (state_change)service_incidentsevent_streamhighSLO breach (error budget exhausted, burn-rate spike) creates an incident in ITSM. High friction in practice, the routing from an OBS-side SLO-breach event to a correctly assigned ITSM incident is rarely turnkey, especially when the SLO-owning team and the incident-handling team differ.
ITSM-INCIDENT-MGMTTEST-MGMT(domain-level)test_defect.created(lifecycle)service_incidentsapi_callmediumCustomer-impacting defects in production-pathing tests escalate to ITSM tickets.
ITSM-INCIDENT-MGMTAPMAPM-PORTFOLIO-REGISTRYapplication_interface.brokenactivebroken (state_change)service_incidentsevent_streamhighIntegration failure escalates to incident; detection lag; true-positive rate varies.
ITSM-INCIDENT-MGMTGRC(domain-level)control.faileduntestedfail (state_change)service_incidentsapi_callhighFailed IT control → ITSM ticket; no feedback when ITSM closes ticket on GRC SLA.
ITSM-INCIDENT-MGMTGRC(domain-level)remediation_plan.created(lifecycle)service_incidentsevent_streammediumRemediation ticket created in ITSM.
ITSM-INCIDENT-MGMTAUDIT(domain-level)audit_engagement.completedin_progresscompleted (lifecycle)service_incidentsmanual_handoffhighIT audit outcomes trigger ITSM actions; requires human interpretation of scope/findings.
ITSM-INCIDENT-MGMTIGAIGA-ACCESS-REQUESTiga_access_request.approved(state_change)service_incidentsapi_callmediumApproved access requests with manual-fulfillment steps route to ITSM.
ITSM-INCIDENT-MGMTIGAIGA-AUTO-PROVISIONINGiga_provisioning_event.completed(state_change)service_incidentsevent_streammediumProvisioning event drives ITSM fulfillment-task closure where access tickets exist.
ITSM-INCIDENT-MGMTIGAIGA-AUTO-PROVISIONINGiga_provisioning_event.failed(state_change)service_incidentsapi_callhighFailed provisioning becomes ITSM incident/request for manual completion. Alert-without-feedback-loop friction shape.
ITSM-INCIDENT-MGMTIPAAS(domain-level)integration_run.failed(lifecycle)service_incidentsapi_callhighiPaaS run failures often surface as ITSM tickets - the failed integration usually has business impact (missed orders, stalled provisioning).
ITSM-INCIDENT-MGMTLCAPLCAP-VISUAL-COMPOSITIONlcap_app.deployment_failed(signal)service_incidentsapi_callmediumDeployment failure opens incident for platform team.
ITSM-INCIDENT-MGMTRPA(domain-level)rpa_bot_credentials.expiring(threshold)service_incidentsapi_callmediumExpiring bot credentials open a service request for IT rotation.
ITSM-INCIDENT-MGMTRPA(domain-level)rpa_execution.failed(state_change)service_incidentsapi_callhighBot execution failure opens incident for bot owner; target system change often the root cause.
ITSM-INCIDENT-MGMTTELCO-BSS(domain-level)network_inventory.updated(state_change)service_incidentsbatch_synclowNetwork inventory updates sync to ITSM CMDB-adjacent inventory.
ITSM-INCIDENT-MGMTTELCO-BSS(domain-level)service_provisioning.failed(state_change)service_incidentsevent_streamhighProvisioning failures escalate to ITSM for network/IT diagnosis.
ITSM-INCIDENT-MGMTTELCO-BSS(domain-level)service_trouble_ticket.opened(state_change)service_incidentsevent_streammediumTelco trouble ticket routes to ITSM for network ops resolution.
ITSM-INCIDENT-MGMTHC-PATIENT(domain-level)clinical_order.placed(lifecycle)service_incidentsapi_calllowOrder routing relies on ITSM-managed integration with lab/imaging systems.
ITSM-INCIDENT-MGMTMFG-OPS(domain-level)shop_floor_case.opened(lifecycle)service_incidentsapi_callmediumShop-floor case with IT/MES root cause is routed to ITSM for incident management.
ITSM-INCIDENT-MGMTUTIL-OPS(domain-level)utility_asset.failed(state_change)service_incidentsapi_callmediumFailure of IT-dependent grid/SCADA asset raises an ITSM incident for dependent technology stack.
ITSM-INCIDENT-MGMTCLIN-DEV(domain-level)clinical_engineering_work_order.opened(lifecycle)service_incidentsapi_callmediumClinical engineering work order surfaces in ITSM when shared with IT for connected-device support.
ITSM-INCIDENT-MGMTCLIN-DEV(domain-level)device_calibration.due(threshold)service_incidentsbatch_synclowCalibration scheduling visible to ITSM when biomed device is shared infrastructure.
ITSM-INCIDENT-MGMTEAM(domain-level)eam_work_order.created-service_incidentsevent_streammediumCritical equipment failures escalated to IT incidents.
ITSM-INCIDENT-MGMTBI(domain-level)bi_report.failed(state_change)service_incidentsapi_callmediumScheduled report failure files an ITSM ticket for the BI platform team to investigate.
ITSM-INCIDENT-MGMTWSCWSC-CHANNELS-CONVERSATIONSchat_thread.escalated_to_ticket(state_change)service_incidentsapi_calllowWSC IT-support threads are converted into ITSM tickets so the SLA clock starts and the transcript becomes incident context.
ITSM-INCIDENT-MGMTAPP-PAAS(domain-level)paas_deployment.failed(state_change)service_incidentsapi_callmediumFailed deployments raise incidents in ITSM for triage.
ITSM-INCIDENT-MGMTVSDP(domain-level)software_deployment.failed(state_change)service_incidentsapi_callmediumFailed deployments raise incidents for change-management and operations triage.
ITSM-INCIDENT-MGMTKUBE-PLAT(domain-level)container_workload.degraded(state_change)service_incidentsapi_callmediumPersistent workload degradation creates ITSM incidents for platform-team triage.
ITSM-INCIDENT-MGMTNPMD(domain-level)network_interface.down(state_change)service_incidentsapi_calllowInterface-down events auto-create ITSM tickets for the responsible team.
ITSM-INCIDENT-MGMTNPMD(domain-level)network_performance_alert.raised(lifecycle)service_incidentsapi_callmediumNPMD performance alerts auto-open ITSM network tickets.
ITSM-INCIDENT-MGMTDEM(domain-level)endpoint_experience_score.degraded(state_change)service_incidentsevent_streammediumDegraded DEM endpoint experience opens proactive ITSM tickets for the user.
ITSM-INCIDENT-MGMTDCIMDCIM-ASSET-SPACEdc_cabinet.environmental_alert(threshold)service_incidentsapi_callmediumDCIM cabinet environmental alerts auto-create facility ITSM tickets.
ITSM-INCIDENT-MGMTDCIMDCIM-POWER-ENVdc_cooling_unit.failure(state_change)service_incidentsevent_streamhighDCIM cooling failures trigger emergency ITSM workflow.
ITSM-INCIDENT-MGMTDCIMDCIM-POWER-ENVdc_power_distribution_unit.failure(state_change)service_incidentsevent_streamhighDCIM PDU failures trigger ITSM major-incident workflow.
ITSM-INCIDENT-MGMTDCIMDCIM-POWER-ENVdc_uninterruptible_power_supply.failover(state_change)service_incidentsevent_streamhighDCIM UPS failovers escalate to ITSM major-incident workflow.
ITSM-INCIDENT-MGMTSMPSMP-DISCOVERYsaas_application.deprovisioned(lifecycle)service_incidentsevent_streammediumSaaS app deprovisioning closes related ITSM tickets and access requests.
ITSM-INCIDENT-MGMTUEMUEM-DEVICE-LIFECYCLEenrolled_device.enrolled(state_change)service_incidentsevent_streamlowNewly enrolled UEM devices auto-link to onboarding ITSM tickets.
ITSM-INCIDENT-MGMTUEMUEM-CONFIG-APPSdevice_configuration_profile.drift_detected(state_change)service_incidentsapi_callmediumUEM configuration drift opens ITSM remediation tickets.
ITSM-INCIDENT-MGMTUEMUEM-COMPLIANCE-POSTUREdevice_compliance_result.non_compliant(state_change)service_incidentsapi_callmediumNon-compliant UEM devices auto-ticket ITSM for remediation.
ITSM-INCIDENT-MGMTDI(domain-level)pipeline_run.failed(state_change)service_incidentsapi_callhighPipeline failure opens incident for the data-platform on-call.
ITSM-INCIDENT-MGMTDQ(domain-level)dq_scorecard.breachedcompliantnon_compliant (threshold)service_incidentsapi_callmediumScorecard SLA breach → ITSM escalation ticket.
ITSM-INCIDENT-MGMTDQ(domain-level)dq_sla_definition.breached(threshold)service_incidentsapi_callhighData SLA breach creates incident for the producing pipeline’s owning team.
ITSM-INCIDENT-MGMTDQ(domain-level)quality_rule.breachactivebreached (state_change)service_incidentsevent_streammediumSeverity ≥ HIGH or breach > SLA threshold → ITSM incident. Dedup on (asset_id, rule_id).
ITSM-INCIDENT-MGMTDATA-AI-PLATDATA-AI-PLAT-MLml_model.drift_detected(signal)service_incidentsevent_streamhighDrift detected on production model; ITSM incident created for MLOps team to triage retraining.
ITSM-INCIDENT-MGMTDATA-AI-PLATDATA-AI-PLAT-MLml_model.evaluation_failed(state_change)service_incidentsapi_callmediumFailed evaluation creates an incident for MLOps; deployment blocked until remediated.
ITSM-INCIDENT-MGMTRMMRMM-MONITORINGmonitoring_alert.threshold_breached(threshold)service_incidentsapi_callhighRMM agent telemetry breaches a monitoring policy threshold and the alert is forwarded to ITSM to auto-create an incident with affected endpoint, telemetry snapshot, and severity. Failure modes: alert-to-ticket bridges across different vendors break on auth/throttling/schema drift; threshold rules drift between systems; duplicate-alert suppression in one tool doesn’t propagate to the other; closing the incident rarely closes the originating alert.
ITSM-INCIDENT-MGMTRMMRMM-AUTOMATIONautomation_script.failed(state_change)service_incidentsapi_calllowFailed RMM script executions auto-create ITSM tickets.
ITSM-INCIDENT-MGMTREMOTE-ACCESSREMOTE-ACCESS-SESSIONremote_session.ended(state_change)service_incidentsevent_streamlowCompleted remote sessions append worklog and timer to the linked ITSM ticket.
ITSM-INCIDENT-MGMTREMOTE-ACCESSREMOTE-ACCESS-SESSIONsupport_session.completedcompleted (state_change)service_incidentsapi_callmediumCompleted remote session writes a session summary (duration, technician, actions taken, recording link) back to the originating ITSM incident as a work-note. Failure modes: ticket-id correlation is brittle when session was launched outside the ticket flow; recording links break when retention policy expires before the ticket closes.
ITSM-INCIDENT-MGMTNCDB(domain-level)nocode_automation.failed(signal)service_incidentsapi_callmediumAutomation failure that the citizen owner cannot resolve escalates to IT support.
ITSM-INCIDENT-MGMTWORK-MGMTWORK-MGMT-TASK-EXECwork_automation.triggered(signal)service_incidentsevent_streamlowWork-item automations linked to IT tickets propagate status changes to ITSM.
ITSM-INCIDENT-MGMTWORK-MGMTWORK-MGMT-TASK-EXECwork_item.status_changedanyany (lifecycle)service_incidentsapi_callhighCross-functional WORK-MGMT items intersect with IT support requests: a marketing project task (‘IT-provision new SaaS’) needs to be linked to an ITSM request, with status mirrored both ways. Bidirectional sync is bespoke; off-the-shelf WORK-MGMT-to-ITSM connectors exist but require careful per-team configuration.
ITSM-INCIDENT-MGMTDLPDLP-ENFORCEMENT-RUNTIMEdlp_incident.blockedconfirmedblocked (state_change)service_incidentsevent_streammediumDLP block creates security incident in ITSM.
ITSM-INCIDENT-MGMTFLEET-MAINT(domain-level)maintenance_defect.reported-service_incidentsevent_streammediumIn-vehicle IT defects escalated to IT tickets.
ITAM-LIFECYCLEHCMHCM-CORE-WORKERemployee.terminatedterminated (lifecycle)asset_lifecycle_eventsapi_callhighEmployee termination triggers asset-recall events: assigned laptops, mobile devices, badges, software licenses must be reclaimed. High friction - recall rates rarely hit 100%, and the cost of unrecovered SaaS seats / laptops shows up in financial leakage reports.
CMDB-COREDISCOVERY(domain-level)ci.discovereddiscovered (signal)configuration_itemsevent_streamlowDiscovered devices reconcile against the existing CMDB and either match (update existing CI), promote (create new CI), or queue for manual review (ambiguous match). Low friction when DISCOVERY and CMDB are same-vendor; medium otherwise.
CMDB-CORERMMRMM-AGENT-MGMTci_endpoint.discovereddiscovered (signal)configuration_itemsapi_callhighRMM contributes CI attributes (OS, installed services, network config) to the CMDB. Failure modes: CMDB receives the same logical CI from multiple discovery sources (RMM, AD, agent-less scans, cloud APIs) with conflicting attribute values; reconciliation rules are CMDB-vendor-specific and rarely fully cover RMM’s payload shape.

6.4 Master providers (modules / domains that own masters this scope embeds)

data_objectrole herenecessitycanonical owner(s)slice notes
asset_lifecycle_eventsembedded_masteroptionalITAM-LIFECYCLE (ITAM)-
configuration_itemsembedded_masterrequiredCMDB-CORE (CMDB)-
locationsembedded_masteroptionalIWMS-LOCATION-MASTER (IWMS)-
org_unitsembedded_masteroptionalHCM-ORG-POSITIONS (HCM)-
error_groupsconsumeroptional(no canonical owner recorded)-
monitoring_alertsconsumeroptionalITOM-INFRA-MON (ITOM)-
service_level_objectivesconsumeroptional(no canonical owner recorded)-

7. Lifecycle states

configuration_items (Configuration Item)

This scope holds configuration_items as embedded_master; the canonical state machine is owned by CMDB-CORE.

orderstate_nameinitial?terminal?requires_permission?derived gatedescription
1discovered---CI auto-detected by discovery feed; not yet curated.
2registered--itsm-incident-mgmt:register_ciCI record curated and accepted into the CMDB of record.
3in_use----CI is actively in operational use.
4retired--itsm-incident-mgmt:retire_ciCI taken out of service but record retained.
5archived-itsm-incident-mgmt:archive_ciCI record archived after retirement; read-only for audit.

org_units (Org Unit)

This scope holds org_units as embedded_master; the canonical state machine is owned by HCM-ORG-POSITIONS.

orderstate_nameinitial?terminal?requires_permission?derived gatedescription
1draft---Org unit defined as part of a future structure; not yet operational.
2active--itsm-incident-mgmt:active_org_unitOperational unit; carries headcount, cost-center linkage, and reporting lines.
3reorganized-itsm-incident-mgmt:reorganized_org_unitUnit folded into or replaced by a new structure; references remain for history.
4closed-itsm-incident-mgmt:closed_org_unitUnit dissolved; no employees or positions reside in it.

service_incidents (Incident)

orderstate_nameinitial?terminal?requires_permission?derived gatedescription
1new---Incident has been logged; not yet triaged or routed.
2assigned----Triaged and assigned to a support group or agent.
3in_progress----Assignee is actively diagnosing or working the incident.
4resolved--itsm-incident-mgmt:resolved_incidentWorkaround or fix delivered; awaiting reporter confirmation.
5closed-itsm-incident-mgmt:closed_incidentResolution confirmed; incident archived and SLA clock stopped.
6canceled---Incident withdrawn (duplicate, invalid, raised in error).

8. Permissions and business rules (derived)

8.1 Permissions

permissiontierdescriptionincluded in :admin?
itsm-incident-mgmt:readbaseline-readRead access to every entity in the module
itsm-incident-mgmt:managebaseline-manageEdit operational records
itsm-incident-mgmt:adminbaseline-adminEdit reference data and inherit every workflow gate below-
itsm-incident-mgmt:active_org_unitworkflow-gate (lifecycle)Transition org_units into state active
itsm-incident-mgmt:reorganized_org_unitworkflow-gate (lifecycle)Transition org_units into state reorganized
itsm-incident-mgmt:closed_org_unitworkflow-gate (lifecycle)Transition org_units into state closed
itsm-incident-mgmt:resolved_incidentworkflow-gate (lifecycle)Transition service_incidents into state resolved
itsm-incident-mgmt:closed_incidentworkflow-gate (lifecycle)Transition service_incidents into state closed
itsm-incident-mgmt:register_ciworkflow-gate (lifecycle)Transition configuration_items into state registered
itsm-incident-mgmt:retire_ciworkflow-gate (lifecycle)Transition configuration_items into state retired
itsm-incident-mgmt:archive_ciworkflow-gate (lifecycle)Transition configuration_items into state archived
itsm-incident-mgmt:view_all_incidentsoverride (personal_content)View all service_incidents rows beyond row-scope
itsm-incident-mgmt:manage_all_incidentsoverride (personal_content)Manage all service_incidents rows beyond row-scope

8.2 Business rules

rule_namedata_objectsource flagintent
incident_edit_scopeservice_incidentshas_personal_contentRow-scope by default; override via itsm-incident-mgmt:view_all_incidents / itsm-incident-mgmt:manage_all_incidents

9. Roles, RACI, and responsibilities (derived)

Baseline roles, the permission hierarchy, and RACI realization are DERIVED from this scope’s entity-type write tiers + process_raci; none of it is stored in the catalog (the deployer provisions it from this blueprint).

9.1 ITSM-INCIDENT-MGMT

Baseline roles:

rolebaseline grant
itsm-incident-mgmt_vieweritsm-incident-mgmt:read
itsm-incident-mgmt_manageritsm-incident-mgmt:manage

Permission hierarchy:

permissionincludes
itsm-incident-mgmt:adminitsm-incident-mgmt:manage
itsm-incident-mgmt:manageitsm-incident-mgmt:read
itsm-incident-mgmt:adminitsm-incident-mgmt:active_org_unit
itsm-incident-mgmt:adminitsm-incident-mgmt:reorganized_org_unit
itsm-incident-mgmt:adminitsm-incident-mgmt:closed_org_unit
itsm-incident-mgmt:adminitsm-incident-mgmt:resolved_incident
itsm-incident-mgmt:adminitsm-incident-mgmt:closed_incident
itsm-incident-mgmt:adminitsm-incident-mgmt:register_ci
itsm-incident-mgmt:adminitsm-incident-mgmt:retire_ci
itsm-incident-mgmt:adminitsm-incident-mgmt:archive_ci
itsm-incident-mgmt:adminitsm-incident-mgmt:view_all_incidents
itsm-incident-mgmt:adminitsm-incident-mgmt:manage_all_incidents

Processes wired:

process_keyprocess_namePCF codePCF IDleveldescription
create_organizational_designCreate organizational design1.2.5100413Formulating a design for the organization’s resources that allow it to meet its objectives. Develop a new framework for molding the organization’s various processes into a coherent and seamless whole.
conduct_organizationConduct organization restructuring opportunities1.1.5167923Examining the scope and contingencies for restructuring based on market situation and internal realities. Map the market forces over which any and all probabilities can be probed for utility and viability. Once the restructuring options have been analyzed and the due-diligence performed, execute the deal. Consider seeking professional services for assistance in formalizing these opportunities.

RACI realization:

actorkindraciprocess_keyrealization
HR-ORG-DESIGN-ANALYSTpersonaresponsiblecreate_organizational_designgrant gates [itsm-incident-mgmt:active_org_unit] + the gated entities’ write tier
HR-BUSINESS-PARTNERpersonaaccountablecreate_organizational_designapproval gate
PEOPLE-MANAGERpersonaconsultedcreate_organizational_designadvisory read grant
HR-HRIS-ADMINpersonainformedcreate_organizational_designnotification side effect (trigger_event / webhook_receiver)
HR-ORG-DESIGN-ANALYSTpersonaresponsibleconduct_organizationgrant gates [itsm-incident-mgmt:reorganized_org_unit] + the gated entities’ write tier
HR-BUSINESS-PARTNERpersonaaccountableconduct_organizationapproval gate
PEOPLE-MANAGERpersonaconsultedconduct_organizationadvisory read grant

9.2 Functional ownership and default grants

responsibilitybusiness functiondefault roledefault tier
ownerIT Service Deskadmin:admin
contributorIT Operationsmanage:manage
contributorSecuritymanage:manage
consumerFinanceread:read
consumerHuman Resourcesread:read