What ServiceNow Major Incident Management Actually Looks Like Inside a Real War Room
A retail CIO called me on a Sunday night. Their point-of-sale integration had been down for four hours across 380 stores. Their MIM process, on paper, was textbook. Dedicated channel in Teams. Incident commander named in the runbook. Bridge open. Status page updating every 15 minutes. Communications template pre-approved by comms and legal. None of it was working. The bridge had 34 people on it, most of them muted, most of them unclear on why they had been invited. The incident commander was a service desk manager who had been told two months earlier that this role was hers on paper. She had never actually run one. The status page updates were being drafted by a comms person who was pulling status from the bridge, which was pulling status from a screenshare of a Kibana dashboard that only one engineer could read. And the ServiceNow major incident record itself had been created 90 minutes into the outage, after someone remembered it should exist. This is what most ServiceNow major incident management looks like when the wheels come off. Not because the tooling is bad. The tooling is fine. Because the process was designed for the audit, not for the crisis.