An integration change went in.
Scoped, reviewed, approved. Promoted in the window it was supposed to go in. ServiceNow has the record; who asked for it, who signed off, what it touched, when it landed. Everything in that record is correct.
Four days later, tickets.
Not a flood. Five, six. Different accounts. A field that didn’t populate. A sync somebody said was running behind. A record that looked wrong to a person who couldn’t say why it looked wrong. Support worked them the way you work tickets. Somebody found a way to make it stop. They closed.
Nobody declared an incident. There wasn’t one to declare. There were tickets, and then there weren’t.
Six weeks later, same shape of thing. Different accounts. Different words for it. Worked. Closed.
Nobody in your building knows those were the same thing.
The usual story about repeats goes like this. Somebody figured it out, and the answer didn’t survive. It went into a ticket comment. Into a thread. Into one person’s head, and that person changed teams in March.
That happens, but that’s not this.
Nothing got figured out the first time. There was no answer to lose.
The tickets got handled. Nothing about handling them required knowing why they showed up. Somebody made the symptom stop for the accounts that called, which is what they were asked to do, and it worked. Getting to a statement about cause would have meant somebody crossing from five unrelated-looking tickets to a third-party change from the week before. Nobody did that. Nothing about those tickets pointed at a change. They pointed at five accounts having a bad week.
So there’s nothing to check the second one against. Not a document somebody forgot to write. There’s no version of this where somebody remembers harder and it comes out different.
Think about what that does to the second one.
It arrives the way the first one did. Same queue. Same handful of accounts describing something in words that don’t match each other. The one thing that would mark it as the second one is the cause, and the cause isn’t attached to either.
So your team works it as new.
Given what’s in front of them, that’s the right call. It is new, as far as anything in the environment can say.
Every system involved is right about its own part.
ServiceNow has the change, complete and approved. It has no reason to know about tickets. Salesforce has both sets of tickets, both accurate, and nothing in either set points at a change. Jira has whatever the third party filed, if the third party filed anything.
Ask any of them whether the thing in March and the thing in April were one thing. There’s no system in your environment where that question lives.
All of it reported correctly. None of it can tell you the two were connected.
Here’s the position that puts you in.
You own the platforms. You own the integrations between them. You don’t own the people who change things inside them, and you find out what they changed the way everybody else does. Downstream. In tickets.
You can account for what happened both times. It is all documented. They got worked, they got closed, both have records you could pull this afternoon.
What you can’t say is whether it was one thing or two.
Ask your team how many of last quarter’s tickets were the second time.
They’ll give you a number. It’ll be honest. It’ll be the number of times somebody happened to be around for both.
Teams who can tell you exactly what happened both times, and can’t tell you whether it was the same thing, are exactly who we’re thinking about.
If that’s your team, we offer a complimentary Investigation Cost Audit. Forty-five minutes. Structured diagnostic across five dimensions. You leave with a scorecard that puts numbers on what your team absorbed last quarter: in time, in recurrence, and in the answers only a person in the room can produce.