You are here:
Managing an Incident from Intake to Resolution for IT Services
This example illustrates the lifecycle of an incident at Cumulus Bank, from Omni-Channel intake to resolution with SLAs and problem management.
Julian, an IT fulfiller at Cumulus Bank, manages incidents reported through multiple channels, such as chat, email, portal, or Slack. With Omni-Channel and assignment rules, these incidents are automatically routed by the system into queues.
The system then assigns incidents to available fulfillers such as Julian.
Intake and Routing
| Source | Action |
|---|---|
| Chat, email, portal, Slack | Fulfillers such as Julian pick them up |
Recently, an employee reported a VPN connectivity issue through email. Because the issue is of high priority, the system automatically applies SLA milestones. Julian moves the incident to In Progress, which satisfies the Acknowledge within 1 hour milestone.
SLA Tracking
| Milestone | Target Time |
|---|---|
| Acknowledge | Within 1 hour |
| Resolve | Within 4 hours |
States and Milestones
| State Change | Milestone Effect |
|---|---|
| New to In Progress | Meets Acknowledge within 1 hour milestone |
| Work underway | Resolve within 4 hours timer continues |
| Promote to Major Incident | SLA targets reevaluated according to policy (if configured) |
| Resolved to Closed | Resolution met and post-incident actions continue for the problem. |
Julian uses Agentforce to automatically associate similar incidents reported within the last one day with this incident. Normally, fulfillers can only propose such incidents for further approval. Because Julian has elevated privileges, he directly promotes the record to a major incident without requiring approval. When promoted, the SLA policy can reapply or adjust milestone times, for example, setting stricter goals for major incidents.
Major Incident Escalation
| Trigger | User Action |
|---|---|
| Similar incidents detected | Julian promotes the incident to a major incident. |
To get immediate help on the issue, Julian starts a swarm in Slack directly from the incident record. Julian also uses Agentforce to generate a summary of the Slack conversation, and Agentforce posts the summary as a feed update on the incident record in the console, after the swarm session ends. This keeps both Slack and console users aligned.
Because this was a major incident, the system automatically creates a problem record.
Problem Creation
| Action | Outcome |
|---|---|
| Promote to major incident | The system automatically creates a problem record. |
After investigation, the team discovers a workaround. Julian uses Einstein to draft a knowledge article of the type Troubleshooting Guide and associates this knowledge article to the incident. Because a problem associated with the incident already exists, the knowledge article is also automatically associated with the problem. After Julian finds out the root cause of the problem, he also creates a knowledge article of the type Known Error for the problem.
Knowledge Reuse
| Action | Outcome |
|---|---|
| Identify a workaround | Einstein drafts a knowledge article as a troubleshooting guide, linked to the incident for reuse. |
| Identify the root cause | Einstein drafts a knowledge article as a known error, linked to the problem for reuse. |
By combining smart routing, SLA tracking, associations, automated problem creation, and knowledge reuse, Julian resolves incidents faster.

