ServiceNow Integration FAQ
Answers to common questions about the ServiceNow integration, including configuration, ticket operations, limitations, and troubleshooting.
General
What is the ServiceNow integration?
The ServiceNow integration lets Qualytics create and link ServiceNow Incidents directly from data anomalies detected in the platform. This streamlines the issue resolution workflow by eliminating the need to manually create incidents in ServiceNow and then reference them back in Qualytics.
Is the synchronization one-way or two-way?
Both ways for state, one way for notes. Qualytics posts comments and status notes to the incident when the integration is set to Two-way sync, and reads the incident's state and short description back on every sync. With Anomaly status sync on, the anomaly and its incidents follow the status mapping in both directions. Work notes written in ServiceNow are not imported. See the How It Works page for the full sync matrix.
Who can manage the ServiceNow integration?
- Users with the Manager or Admin role can connect, edit, and disconnect the integration.
- Users with the Member role cannot access the integration configuration in Settings, but can view linked tickets on anomalies they have permission to access.
For ticket operations on anomalies (create, link, remove), team-level permissions on the anomaly's datastore also apply. See the Permissions page for details.
Connection and Credentials
How are credentials stored?
The ServiceNow service account username and password are stored encrypted at rest in Qualytics. They are never shown in plain text in the UI or in API responses.
How do I rotate the service account password?
Change the password in ServiceNow, under User Administration > Users, then update the integration with the new credentials from the edit modal. See Edit ServiceNow Connection.
Do not disconnect and reconnect to do this. Disconnecting removes every link between an anomaly and an incident, and reconnecting does not bring them back.
Why is "Web service access only" recommended for the service account?
Enabling Web service access only in ServiceNow restricts the account to API-only usage, so the credentials cannot be used to log in through the standard UI. This reduces the attack surface and is a common security best practice for integration accounts that don't need a human-facing login.
Can I change the ServiceNow instance URL?
Yes, with Edit on the existing integration. Qualytics tests the new URL against the instance before saving it. Do not disconnect and reconnect to change it, because disconnecting permanently removes every link between an anomaly and an incident. See Edit ServiceNow Connection.
The integration type itself cannot be changed. A ServiceNow integration stays a ServiceNow integration.
One caution when you point it at a different instance: the links already stored keep the addresses they were created with, so their View button still opens the old instance. Move the integration only when the incidents you have linked live on the new instance too.
Can I use OAuth 2.0 instead of Basic Authentication?
Not currently. The integration uses Basic Authentication with a service account username and password in the username:password format. OAuth 2.0 is not supported yet.
Can I connect multiple ServiceNow instances at the same time?
No. Only one ticketing integration (Jira or ServiceNow) can be active at a time. Connecting a new integration requires disconnecting the existing one first.
Can I switch from ServiceNow to Jira later?
Yes. Disconnect the ServiceNow integration and connect a new Jira integration. Be aware of what that costs: disconnecting permanently removes every link between an anomaly and a ServiceNow incident, and reconnecting later does not bring them back. The incidents themselves stay in ServiceNow, with everything Qualytics wrote to them. See Disconnect ServiceNow.
Creating Incidents
Should I create a new incident or link to an existing one?
| Situation | Recommendation |
|---|---|
| The anomaly is a new, unique issue not yet tracked anywhere | Create a new incident |
| There's already a ServiceNow incident covering this issue | Link the existing incident |
| The existing incident must remain unchanged | Don't link, because the description is appended and a work note is added on link |
When in doubt, create a new incident. It's the safer default, since linking modifies the existing one.
Does linking an existing ServiceNow ticket modify the incident?
Yes, unlike the Jira integration. When you link an existing ServiceNow incident:
- The anomaly details are appended to the existing description (the original content is preserved)
- A work note is added to the incident with the linkage information (anomaly ID, status, timestamp)
If you need the incident to remain completely untouched, do not link it from Qualytics.
What fields can I set when creating a ServiceNow ticket from Qualytics?
The Create Ticket form has ten fields:
- Short Description (required): brief one-line summary.
- Description: detailed description. Anomaly context is added automatically.
- Status: the state the incident starts in. Defaults to
New. - Priority: Critical, High, Moderate, Low, or Planning. Defaults to Moderate.
- Urgency: High, Medium, or Low. Defaults to Low.
- Impact: High, Medium, or Low. Defaults to Low.
- Category: must match a category configured in your ServiceNow instance (case-sensitive).
- Subcategory: must match a subcategory configured in your ServiceNow instance (case-sensitive).
- Assignment Group:
sys_idof the assignment group, not the display name. - Assigned To:
sys_idof the user, not the username.
Every record is created on the Incident table by the integration's service account, and the caller cannot be set from Qualytics. Neither the table nor the caller is part of the form.
See Create a ServiceNow Ticket for the full field reference, and Sync Behavior for what Qualytics appends to a new incident.
Where do I find Category, Subcategory, Assignment Group, and Assigned To values?
These values must match what's configured in your ServiceNow instance. Category and Subcategory are case-sensitive. Assignment Group and Assigned To both require a sys_id, not the display name or the username. See Find ServiceNow Values for step-by-step lookup instructions.
Why is my incident unassigned even though I filled in Assigned To?
Assigned To takes the user's sys_id, not a username or a display name. A value ServiceNow cannot resolve to a user is ignored, and the incident is created with no assignee. The same applies to Assignment Group. See Find ServiceNow Values for how to look up a sys_id.
Can I link multiple ServiceNow incidents to the same anomaly?
Yes. Multiple incidents can be linked to a single anomaly. Each link is tracked independently.
Can I link the same ServiceNow incident to multiple anomalies?
Yes. A single ServiceNow incident can be linked to multiple anomalies.
Status and Comments
What happens when I acknowledge an anomaly?
A timestamped work note is added to each two-way linked ServiceNow incident (e.g., [2024-01-15 10:30:00 UTC] Qualytics Anomaly Status: Acknowledged). The incident state itself is not changed unless Anomaly status sync is on, in which case the incident also moves to the state mapped to Acknowledged. Read only incidents receive neither.
What happens when I archive (resolve) an anomaly?
A timestamped work note with the resolution status is added to each two-way linked ServiceNow incident. The incident state is not changed unless Anomaly status sync is on, in which case the incident also moves to the state mapped to that anomaly status.
How do I interpret ServiceNow state codes (1, 2, 3, 6, ...)?
ServiceNow uses numeric codes for incident states. The Status field in Qualytics accepts the code, and it also accepts the readable name for the six states Qualytics recognizes: New, In Progress, On Hold, Resolved, Closed, and Canceled. Any other state has to be given as its numeric code. See the full state mapping in State Mappings.
What's the difference between work notes and comments in ServiceNow, and which does Qualytics use?
In ServiceNow:
- Work notes are internal, visible only to fulfillers (users with the
itilrole). - Comments ("Additional comments" in some forms) are customer-facing, visible to the requester or caller via the Service Portal or email notifications.
Qualytics writes to work notes for all syncs (status changes, anomaly comments, link events). End users (callers) won't see Qualytics activity unless they have ITIL access. If you need that information visible to a customer, copy it manually into the comments field.
How does a comment look once it reaches ServiceNow?
The work note carries the comment as plain text. Two things do not survive the trip:
- A mention arrives as a raw text code rather than as the formatted name you saw when typing it, and the mentioned user is notified in Qualytics only, not in ServiceNow.
- A reply arrives as its own work note with no indication of which comment it answers, because work notes are a flat list.
For the full thread with its structure intact, open the anomaly's Timeline in Qualytics.
Do replies and comments on a specific change sync to ServiceNow?
Yes. Every comment posted on the anomaly's Timeline is pushed to the linked incident as a work note, whether it stands alone, is anchored to a specific change, or replies to another comment. The sync only ever adds, so edits to an existing comment are not re-synced, and deleting a comment in Qualytics leaves the work note already on the incident in place. Comments on containers, quality checks, and check templates are not pushed to tickets, because those assets have no linked ticket.
Limitations
Why doesn't a ServiceNow state change update the anomaly's status?
Because status sync is off by default. The incident state is read back and shown on the linked ticket card, but each system keeps its own state. Turn on Anomaly status sync in the ServiceNow integration settings and map each anomaly status to an incident state. From then on an anomaly status change moves its two-way incidents, and the anomaly follows its incidents once every linked incident sits at a state mapped to the same anomaly status.
What happens if the ServiceNow incident is deleted?
The link in Qualytics remains but will show broken references. Future sync attempts (work notes, status changes) will fail. You can manually remove the link from the anomaly's Tickets section.
Can Qualytics create tickets automatically (without user action)?
Yes. Add a Create Ticket action to a flow with an Anomaly or Anomaly Status Change trigger. The action's summary and description are templates: ,, ,, ` and