When to Use an Incident Ticket
Use an Incident ticket when normal service is not working and your goal is restoration rather than fulfillment. Common examples include VPN outages, SSO failures, email sync issues, and critical integrations timing out.When to Use a Major Incident
Use a Major Incident when one issue is affecting many people at once and needs a coordinated response, so their individual tickets can be tracked and updated together. Common examples include a company-wide VPN outage, an identity provider (SSO) going down, or a core application being unavailable for everyone on the team.How Incident Management Works in Serval
1
Incident is created and typed
A ticket comes in from Slack, Teams, email, web, or external sync. Serval can classify it as an Incident.
2
Team triages and routes
Your team sets status, priority, assignee, labels, and due date to establish ownership and urgency.
3
A major incident is created for a widespread issue
When one issue is affecting many people, a team manager creates a Major Incident to coordinate the response. This is a manual step out of the box; you can also build a workflow to create one automatically when automation detects a widespread issue.
4
Serval links related tickets to the major incident
Once a major incident exists, Serval automatically links new related tickets on the same team to it and notifies those requesters that a major incident is underway.
5
Incident is resolved and updates propagate
Your team runs remediation actions (including workflows), resolves the incident, and syncs updates across connected systems when configured. Updates on a major incident flow out to every linked ticket.
Related tickets link to a major incident, not to one another. The major incident is the one ticket that every related report connects to; those reports are not linked to each other.

