You are here:
AI Actions for Incident Management
Accelerate incident resolution and improve accuracy by using incident actions. Fulfillers and managers can use incident actions to track and resolve issues efficiently throughout the incident lifecycle.
Required Editions
| Available in: Lightning Experience |
| Available in: Enterprise, and Unlimited Editions with Agentforce IT Service. |
Update an Issue
When a VPN connection failure is reported, an incident fulfiller takes ownership and starts investigating the issue.
Here’s how an incident fulfiller finds and updates an incident record using Agentforce.
| Instructions | Example Utterance or User Input | Agent response | Standard Action Engaged |
|---|---|---|---|
| Verify the key fields and priority of the incident. |
|
The agent displays the key attributes of the incident (for example, category: Network (VPN), priority: high, status: new, SLA: 2 hours remaining). | Check Incident Attributes |
| Instruct the agent to update one or more fields with new values. |
|
The agent updates the record status to In Progress and confirms the change. | Update Record Fields |
Investigate and Resolve an Issue
To manage incidents related to VPN connection failures, incident fulfillers use Agentforce to capture key findings, such as summaries, root causes, resolutions, and post-incident reviews.
Here’s how an incident fulfiller investigates and resolves issues using Agentforce.
| Instructions | Example Utterance or User | Agent response | Standard Action Engaged |
|---|---|---|---|
| Generate an overview of an incident where an employee’s laptop has a corporate VPN connection issue. |
|
The agent generates an incident summary (for example, reported by: Sarah, issue: high-priority VPN connection failure (Error 720), impact: user unable to work, status: new, awaiting investigation). | Summarize Incident |
| Find and link to other incidents or records related to this issue to understand its scope. |
|
The agent finds 22 related incidents with error 720 from the last 48 hours and suggests linking them to track a wider issue. | Associate Related Records For Incident |
| After investigating an incident, draft a summary of the root cause. |
|
The agent finds a linked incident and uses it to draft a root cause summary. The summary identifies an incompatibility issue between the latest OS security patch and the corporate VPN client. | Create Incident Root Cause Summary |
| Generate a potential resolution for the VPN issue based on historical data. |
|
The agent finds a relevant knowledge article (KA-0001) from a past incident. It then proposes a fix, which is to uninstall the incompatible VPN client and install the updated version from the Software Center. | Propose Resolution Summary For Incident |
| Evaluate if VPN connections that keep failing after company OS updates are worth creating a problem record to fix the problem and prevent future problems. |
|
The agent analyzes recent incidents and recommends creating a problem record based on the findings (for example, 22 related VPN incidents in the last 48 hours, all linked to a recent OS update). It then suggest to create a problem record and associate it with the relevant incidents. | Evaluate Problem Creation Requirement |
After resolving an incident, draft a summary of the steps taken to fix the VPN connectivity issue. Note Incident fulfillers copy the resolution summary generated by
Agentforce and paste it into the resolution summary field before marking the
incident as resolved or closed. This step updates the incident record with a
clear summary of the resolution. |
|
The agent generates a resolution summary. The summary states that updating the VPN client resolved the issue. | Create Incident Resolution Summary |
| At any point in the incident life cycle fulfillers or managers can summarizes multiple incident records based on a certain time and status criteria. This gives a consolidated view for trend analysis and finding common problems. |
|
The agent summarizes incident trends for the specified period (for example, time frame: September 1–11, 2025, total incidents: 84 (65 closed, 10 in progress, 9 new), top trend: 15 incidents related to VPN connection failures). | Summarize Multiple Incidents |
| Generate a post-incident review (PIR) for stakeholders after an incident is resolved. Include timeline, root cause analysis, and preventive measures. |
|
The agent generates a structured post-incident review (PIR) for VPN Error 720 using data from the incident feed, resolution notes, swarm data, and SLAs. The report documents the timeline from the initial report, the user impact, the OS patch conflict root cause, and preventive testing measures. After populating the PIR field, the agent prompts you to review or edit the draft. | Generate a Post-incident Review |
Collaborate and Communicate on an Issue
Agentforce helps incident fulfillers or managers handle major incidents by enabling swarms in Slack, summarizing record channels, and drafting professional updates via email, keeping stakeholders informed throughout the incident lifecycle.
Here’s how incident fulfillers or managers can use Agentforce to swarm and communicate about the ongoing VPN connectivity issue.
| Instructions | Example Utterance or User Input | Agent response | Standard Action Engaged |
|---|---|---|---|
| Create a summary of the troubleshooting discussion happening in the Slack record channel. This is directly from the Incident record related to the VPN outage. |
|
The agent summarizes the linked record channel on Slack to identify the problem, key contributors, troubleshooting steps, action items, and decisions. | Summarize a Slack Channel |
| Post the final swarming summary to the problem record to document the investigation and resolution plan. |
|
The agent posts the generated swarming summary and incident resolution as a new Feed Item on the current record for visibility and historical tracking. | Post To Feed |
| Draft an initial notice acknowledging the VPN outage. After a fix is identified, provide technical details to generate clear resolution communication for employees. |
|
The agent manages VPN outage communications. It first drafts a broadcast email to acknowledge the issue, followed by a final resolution message detailing the root cause, required client updates, and a link to a knowledge article. |

