---
sourceDocument: Australia IT Service Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/it-service-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia IT Service Management

ft:clusterId :

    - itsm

bundleId :

    - itsm

workflow :

    - Technology


---

# Demote a major incident

# Demote a major incident {#ariaid-title1}

Release version: Australia  
Updated March 12, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read  
When an incident is incorrectly evaluated to be a major incident, you can demote the
major incident even after it is accepted so that the incident can be handled as a regular
incident.

## Before you begin

Role required: major_incident_manager

## Procedure

1. Navigate to AllMajor IncidentsOpen.  
   Note:  
   If the UI16 module link redirection feature is enabled in Service Operations Workspace (SOW) and the UI16 module supports the redirect configuration, navigating through UI16 paths automatically redirects you to the equivalent list or record pages in SOW instead of displaying the UI16 forms or lists. For more information, see [Redirect UI16 module links to Service Operations Workspace](https://servicenow-prod.fluidtopics.net/vL8HZs36~TCAlAHAiJ5i~w "Redirect classic UI16 module navigation links to the equivalent Service Operations Workspace (SOW) experience.").
2. Open the major incident that you want to demote.
3. Click the additional actions icon ![Additional actions icon]() and select Demote Major Incident.
4. Enter the reason for the demotion.  
   The major incident state is set to Canceled but the incident state remains the same.

*[\>]: and then


