Datasheet
Eviworx ITSM Core
Tickets • Incidents • Problems • Changes
Overview
Eviworx ITSM Core comprises the four core modules for IT service management: Tickets (general requests), Incidents (disruptions with SLA), Problems (root cause analysis) and Changes (changes with multi-approver). All modules share a common architecture with state machines, cross-entity linking, activity logging and SHA-256 audit chain.
Tickets
General Requests & Service Requests
- • Categories (freely configurable)
- • Saved views — personal, for groups or the whole organisation
- • Global search across nine object kinds
- • Assignment to agent/team
- • Cross-entity linking (Assets, Changes, Problems) & sub-tickets (one level)
- • Bulk operations (status, assign, link)
- • Activity log with audit chain
- • Attachments with virus scan
- • Multi-mailbox (IMAP/SMTP + Graph API) with signatures & visibility
- • Reopen governance (window/reason/limit) + auto-close & waiting-customer auto-resolve
Incidents
Disruptions with SLA & Escalation
- • Impact/Urgency → Priority matrix (P1-P4)
- • SLA with business hours & escalation
- • Closure approval via configurable approver groups
- • PIR mandatory for P1/P2 (Post-Incident Review)
- • Major incident flag — deliberately set by hand, with its own permission (triggers NOC alarm and stakeholder information)
- • Workaround tracking & mitigation
- • Duplicate marking on resolution & linking
- • GDPR data breach flow & evidence checklists
- • Category management & follower/CC
- • Reopen with mandatory approval (governance: window/reason/limit)
Problems
Root Cause Analysis & Prevention
- • Root cause analysis documentation
- • Known error with workaround as dedicated states
- • Linking to causing incidents
- • Change suggestions for resolution
- • Prevention through linked changes
- • Activity log with audit chain
- • Reopen governance (window/reason/limit)
Changes
Changes with Multi-Approver
- • Unified Approval (ALL/ANY/MAJORITY/QUORUM)
- • Change types: STANDARD, NORMAL, EMERGENCY, MAJOR
- • Categories with individual approval logic
- • Rollback plan & testing documentation
- • Four-eyes principle: the requester does not approve their own change
- • Activity log with audit chain
- • Scheduled changes (start/end timestamps)
- • BACKED_OUT status & versioning
Shared Architecture
Each entity has a clearly defined state machine with valid transitions. Unauthorized transitions are blocked. Automatic timestamps on status changes.
Tickets, Incidents, Problems, Changes can be linked to each other. Once a parent record is done, closing the linked records appears as a task in the approval inbox — the decision is deliberately made in the record itself, because that is where deadline, resolution code and feedback to the reporter come together. Tickets can additionally be placed under a parent ticket (sub-tickets, one level): the parent ticket pauses its SLA while a sub-ticket is open and can only be resolved once all sub-tickets are completed.
Access and erasure are built in, not bolted on: every person can request their data as a machine-readable export, and administration can irreversibly anonymize an account — the business record history is retained while the personal reference falls away. Active involvements block the erasure until they are reassigned, and a backlog report shows open cases with their deadlines.
Every change is logged in the audit chain. Blockchain-like hash chaining with prevHash. Automatic redaction of sensitive fields (secrets/tokens). A nightly system job automatically verifies the entire chain and alerts on deviations.
Complete history of all changes per entity. Who changed what when. API-key support for automated changes. Filterable by actor/type/period.
Technical Specifications
- • 29 permission modules, 85 critical actions
- • 175 notification events in 14 categories
- • 29 automation actions, 24 shipped schedules
- • Attachments on 12 object kinds, virus scan included
- • REST API (CRUD + Actions)
- • Bulk-Operations
- • Search & Filtering
- • Activity & History
- • Trash & restore (its own permission)
- • Reports as CSV, XLSX and PDF through the report builder
- • Granulare Permissions pro Modul
- • Dynamische Rollen (RBAC)
- • MFA/TOTP • FIPS 140-2 compatible algorithms (no FIPS certification)
- • Field locks per change status, 8 permissions per asset type
- • Sign-in via Microsoft Entra ID with a daily sync
- • In the application (bell, live)
- • Email (SMTP or Microsoft Graph)
- • Microsoft Teams (Bot Framework)
- • Cisco Webex
- • Web-Push (Browser)
- • User-based quiet periods
- • Digest (bundled delivery: hourly/daily/weekly)
Key Differentiators
Integration & Deployment
ITSM Core is part of the Eviworx Enterprise platform with 50+ modules (Assets, Workflows, Contracts, Knowledge Base, Analytics, etc.).
12 specialized containers (incl. Traefik API-GW + report generator). Backend with Node.js. Frontend with React 19+. PostgreSQL + Redis. Multi-instance ready.
Start a Pilot
Test Eviworx ITSM Core in your environment. Pilot phase: 30 days free.
Get in Touch Now