Change Impact Analysis

Last Updated: September 28, 2026
Estimated Reading Time: 6 minutes

Overview

A change request often touches more than one CI. Running a separate blast radius for each CI and adding the lists together hides the most important answers: which services every changed CI reaches, where a second path exists, and which single CI everything depends on.

Change Impact Analysis analyzes the full affected-CI scope of a ServiceNow change request as one graph. CMDBx uses deterministic, versioned relationship rules. AI does not decide the traversal.

What the Analysis Shows

ResultMeaning
Deduplicated impactEach impacted CI or service appears one time, even when more than one changed CI reaches it.
Origin CIsFor each impacted CI, the changed CI or CIs that reach it.
Shared impactImpacted CIs that more than one changed CI reaches.
Impact pathsUp to five retained paths for each impacted CI: the primary path and up to four alternate routes.
Redundancy evidenceWhether independent modeled routes exist. Duplicate relationship records on the same route do not count as redundancy.
Single points of failureModeled bottleneck CIs that every path to an impacted CI must pass through.
RiskA model-based priority for each impacted CI.
Evidence confidenceHow much you can trust the evidence. Stale topology, missing CI details, or an early stop lower confidence.
CompletenessWhether a depth, node, relationship, or time limit stopped the analysis before the topology ended.

Risk and confidence are separate on purpose. A high risk score on stale or partial evidence shows Low confidence. Neither value is a calibrated probability of an outage. A modeled alternate route does not prove that failover was tested.

How the Analysis Works

  1. CMDBx receives the affected CIs of the change request. You can send up to 500 CIs.
  2. CMDBx follows outage-propagating relationships from each changed CI to the CIs and services that depend on it. The maximum depth is 9 relationship levels.
  3. CMDBx merges the results into one set and records the origin CIs for each impacted CI.
  4. CMDBx evaluates alternate routes, redundancy, and single points of failure.
  5. CMDBx records the freshness of the topology: the last completed sync and the age of the relationship data.
  6. CMDBx saves the result as an immutable run. Later exports read the saved run. They do not run the analysis again.

The analysis reads the CMDBx mirror of your CMDB. It does not change the change request or any other ServiceNow record.

Run the Analysis From ServiceNow

A ServiceNow Flow, UI action, or script calls the CMDBx report API. Your ServiceNow administrator configures this one time.

Before You Begin

  • Make sure that CMDBx completed at least one full sync for the environment.
  • Ask your CMDBx administrator or CMDBx support for a ServiceNow credential. The recommended method is private-key OAuth. CMDBx also accepts integration tokens.
  • Make sure that the ServiceNow credential is bound to the correct CMDBx environment.

Start a Merged Analysis

  1. Send a POST request to /api/servicenow/tenant/{tenant}/blast-radius-report?env={environment}.
  2. Set analysisMode to merged.
  3. Send the change request number and sys_id.
  4. Send the affected CI sys_id values in affectedCIs.
  5. Send an idempotency key. Use the same key when you retry the same Flow execution.

If you do not send affectedCIs, CMDBx uses the affected CIs that it synced from the ServiceNow task_ci table. Send affectedCIs when you can. The change form can change between syncs.

Get the Result

  1. CMDBx returns 202 with a job ID and a status URL.
  2. Poll the status URL with the same credential.
  3. Obey the Retry-After response header.
  4. When the job completes, read summary.
  5. Post summary.work_note to the change request work notes.

The summary contains the deduplicated count, impact levels, shared impact, redundancy and single-point-of-failure counts, completeness, and the top-ranked CIs. Add include_result=false to the status URL when you need only the summary.

Single-CI Reports and Change Tasks

The same API also supports one CI at a time:

  • PDF mode returns a PDF impact report that ServiceNow can attach to a record.
  • JSON task-plan mode returns the affected CIs, ranked change-task candidates, and a work-note summary. ServiceNow creates the child change tasks. CMDBx returns 10 task candidates by default and never more than 25.

Call PDF mode and JSON mode as separate REST methods. If ServiceNow saves a PDF response directly as an attachment, do not read the body of the same response again.

Analyze a Single CI in CMDBx

You can also run the same outage analysis for one CI in the Dependency Map. See Blast Radius Simulator.

Related Articles