---
sourceDocument: Australia IT Service Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/it-service-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia IT Service Management

ft:clusterId :

    - itsm

bundleId :

    - itsm

workflow :

    - Technology


---

# Remedial actions using Playbook

# Remedial actions using Playbook {#ariaid-title1}

Release version: Australia  
Updated March 12, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 minutes to read  
Resolve the CI-related issues using the remedial actions using Playbook in the Investigate tab.
The Investigate tab includes the following types of remedial action to resolve CI-related issues:

* End process
* Restart service
{#remedial-actions-playbook__ul_eyv_2my_cxb}  
These remedial actions are available on the Investigate tab only if the following conditions are met:

* The Investigation Framework \[sn_invest_fwk\] application is installed and configured. For more information, see [Setting up Investigation Framework in Service Operations Workspace](https://servicenow-prod.fluidtopics.net/wRwSWi27I0unm9kxKoAGYg "Set up the Investigation Framework in Service Operations Workspace to enable the display of the CI metrics information on the Investigation tab of the Incident records.") and [Configure the Remedial Actions Framework](https://servicenow-prod.fluidtopics.net/mOq5HZyJcV4PtQORZwkazw "Configure the Remedial Actions Framework to add a new remedial action or modify an existing one.").
* The remedial actions are configured to display on the UI. For more information, see [Customize the Investigate tab](https://servicenow-prod.fluidtopics.net/NxOtbf6LUBNU84sL3lR~nA#customize-investigate "Customize on how the CI related metrics information is displayed on the Investigate tab of the Incident record.").
{#remedial-actions-playbook__ul_x2r_jmy_cxb}  
Remedial actions use playbooks to resolve CI issues. Playbook provides you with an interactive UI to guide and execute the remedial actions step by step. With a playbook, you can control every execution step of the remediation process. Playbook is available on the contextual side panel of the Incident record page. When any remedial action is performed, that remediation process is added to a playbook. You can then select the playbook (![Playbook icon]()) icon on the contextual side panel to open the playbook on a separate panel and execute the process. The playbook panel displays the following tabs:

* Current: Displays the current list of playbooks that trigger the remedial action, including both processes and services that have the status New and In Progress.
* History: Displays the historical list of playbooks, including both processes and services that have the status Completed, Canceled, or Failed.
{#remedial-actions-playbook__ul_c1y_zwy_cxb}  
You can perform remedial actions on both the affected CIs and the caller CIs associated with the incident record. The caller CIs are the CIs that are assigned to the caller.  
Note:  
If the CI is DEX supported, the remedial actions playbook for the DEX actions are displayed. If the CI is SOW or default view supported, the remedial actions playbook for SOW actions are displayed.  
You can cancel an ongoing End process or Restart service remedial action playbook. To cancel a remedial action playbook, select the remedial action playbook and select the menu (![Menu icon]()) icon and then select Cancel action option. After the remedial action playbook is canceled, the corresponding action is also canceled. Then, the status of the remedial action is displayed as Canceled in the History tab of the playbook panel. To view the reason for cancellation, select the View reason option on the playbook. This option isn't available if any of the following are true:

* The remedial action is already in Canceled status.
* The corresponding CI action record of the remedial action is already in progress.
* The change request has already moved to implement state for actions associated to CIs of type server.
{#remedial-actions-playbook__ul_anq_p3t_1yb}

The Remedial actions section on the Investigate tab also contains the Current and History tab to display the list of remedial actions performed. By default, this section displays the
list of remedial actions for the primary CI or current CI. You can switch the Show actions performed on all CIs in this incident toggle to display the list of remedial actions for all the CIs associated with
the Incident.

Playbook is available only if both the Remedial Action Framework \[com.snc.sn_reacf\] application and the Investigation Framework \[sn_invest_fwk\] application are installed and configured, as well as if the remedial actions are
triggered.  
Note:  
You can't execute concurrent or duplicate remedial actions when a remedial action is in progress on a process or service for a CI type device or server. You also can't execute concurrent or duplicate remedial actions on the same CI until the previous remedial action execution is completed. You can change this behavior and allow concurrent execution of the remedial action by selecting the Allow concurrent execution option for Remedial Action Type. For more information, see [Configure the Remedial Actions Framework](https://servicenow-prod.fluidtopics.net/mOq5HZyJcV4PtQORZwkazw "Configure the Remedial Actions Framework to add a new remedial action or modify an existing one.").

## End process {#remedial-actions-playbook__section_btd_rsy_cxb}

The End process remedial action is available with the following metric information cards:

* Top processes By Memory
* Top processes By CPU
{#remedial-actions-playbook__ul_ubv_5sy_cxb}  
Select the CI and then select End process to stop the process running on the CI. The remediation process then is added to the playbook. Select the Playbook (![Playbook icon]()) icon from the contextual side panel to open the playbook on a separate panel and execute the process. You can execute the End process remedial action for the following CI classes:

* Device: For this CI class, a two-step process is executed where you must get the user approval before the End process remediation process can be executed. After it's approved, you can directly stop the process on the device, which is also known as the endpoint.
* Server: For this CI class, you must create a change request before the End process remedial action can be executed using a standard change request. You must also provide additional information to create a change request.
{#remedial-actions-playbook__ul_wjp_4ty_cxb}

## Restart service {#remedial-actions-playbook__section_p1g_xxy_cxb}

The Restart service remedial action is available with the Services metric information card.  
Select the CI and then select Restart service to restart the services running on the CI. The remediation process then is added to the playbook. Select the Playbook (![Playbook icon]()) icon on the contextual side panel to open the playbook on a separate panel and execute the process. You can execute the Restart service remedial action for the following CI classes:

* Device: For this CI class, a two-step process is executed where you must get the user approval before the Restart service remediation process is executed. After it's approved, you can directly restart the services on the device, which is also known as the endpoint.
* Server: For this CI class, you must create a change request before you can execute the remedial action using a standard change request. You must also provide additional information to create a change request.
{#remedial-actions-playbook__ul_ezc_1yy_cxb}
**Related concepts**   

* [Viewing incident record information using the Contextual side panel](https://servicenow-prod.fluidtopics.net/Is~pVulzhychaejFJSbfIg "View the incident record information, such as caller details and assets, from the Contextual side panel. Use this information to help manage an incident more efficiently.")
* [Incident Management in Service Operations Workspace reference](https://servicenow-prod.fluidtopics.net/EEy54zsTSXlJtO7t~l_vVg "Reference topics provide additional information about Incident Management in Service Operations Workspace.")  
**Related tasks**   

* [Create an incident in Service Operations Workspace](https://servicenow-prod.fluidtopics.net/DX7Hz9WAFvHCv6apiiNpGg "Track the investigation, possible solutions, and resolution of a problem for a customer.")
* [View and update incident information on the Overview tab](https://servicenow-prod.fluidtopics.net/6ZJ5lZc63TAqEOfGcrEQHg "View and update the incident information, such as summary, impact, cause, and resolution, from the Overview tab. This incident information helps you analyze the issue and resolve the incident quickly.")
* [Work on an incident list page in Service Operations Workspace](https://servicenow-prod.fluidtopics.net/JEehtYaqJl5l8F9K1_u6YQ "Perform various actions on an incident from the incident list page in Service Operations Workspace (SOW).")
* [Work on an incident record in Service Operations Workspace](https://servicenow-prod.fluidtopics.net/QurZTkwKnKIiMg5xEkZyDA "If resolving the incident involves creating a problem, change, service request, and so on, you can create them directly from the incident record.")
* [Close resolved incident](https://servicenow-prod.fluidtopics.net/73gjz_3ufF~D~TSgW5EVIg "Close a resolved incident when the user is satisfied with the provided resolution.")
* [Reopen an incident in Service Operations Workspace](https://servicenow-prod.fluidtopics.net/M~2KqqtKwJdbd~nJBMOiNw "Reopen a resolved incident from the incident record in Service Operations Workspace (SOW).")

