Install Trend
View Install Data
| Date | Install Count | Change |
|---|---|---|
| 2026-09-09 | 0 | - |
About
MI Core is an AI-assisted Major Incident analysis application for ServiceNow. It helps incident commanders quickly understand the scope, probable cause, business impact, and next steps for complex incidents. The application analyzes incident details, work notes, configuration items, changes, events, historical incidents, and resolver information, then produces a structured investigation summary with evidence, confidence levels, recommended actions, knowledge gaps, and retrospective follow-ups. MI Core supports on-demand analysis from an incident form and configurable automated triggers. Its modular architecture adapts to the capabilities available on each ServiceNow instance and continues to provide useful results when some data sources are unavailable.
Key Features
- AI-assisted Major Incident analysis
Converts complex incident information into a concise, actionable investigation summary.
- On-demand analysis
Allows authorized users to launch analysis directly from the incident form using Run MI Analysis.
- Configurable automated triggers
Automatically analyzes incidents based on administrator-defined conditions, such as priority, major incident status, or custom filters.
- Multi-source investigation
Correlates incident details with configuration items, recent changes, events, historical incidents, and resolver teams.
- Probable-cause analysis
Generates an initial hypothesis, evaluates alternative causes, and explains the reasoning behind the leading hypothesis.
- Evidence-based outcomes
Separates known evidence, assumptions, confidence levels, and unresolved investigation gaps.
- Business-impact assessment
Summarizes affected services, users, locations, applications, and potential downstream impact.
- Recommended next steps
Produces prioritized actions for incident commanders, service owners, engineering teams, and support groups.
- Resolver and escalation guidance
Identifies relevant teams and recommends who should be engaged based on available CI, change, incident, and ownership data.
- Graceful degradation
Continues to produce useful analysis when optional data sources such as CMDB, Event Management, Change Management, historical records, or on-call data are unavailable.
- Modular and extensible architecture
Enables administrators to enable, disable, reorder, or extend investigation modules using script, skill, flow, or agent providers.
- Incident write-back
Stores the investigation results and can write the synthesized analysis back to the source incident as a work note.
- Retrospective support
Identifies known unknowns, human follow-up tasks, documentation gaps, and process improvements.
- Controlled and auditable execution
Runs analysis asynchronously and records investigation progress, outcomes, and execution details.
- Human-in-the-loop design
Provides decision support without autonomously approving remediation or replacing incident commander judgment.