Before reporting a bug
What to check first, what to send, and what never to send.
Check these three first
Is it on a ServiceNow host? The extension only runs on *.service-now.com. On any other domain
nothing loads, and that is the permission the browser granted rather than a fault.
Does it survive a reload? The widget is injected on request, so a page that loaded while the worker was asleep can miss it once.
Is it your ServiceNow account? A 401 or 403 comes from the instance. Everything here asks
with your own session and reports what it is told. If you are impersonating, the message says so,
and /unimp stops it.
Then look at when something does not work: most reports turn out to be one of the situations on that page, and each one has a different fix.
What makes a report useful
The extension's version, from the settings page, and your browser's version.
Which ServiceNow interface: the current shell, the classic UI, a workspace, or the Service Portal. They are three different rendering paths, and a fault in one often does not exist in the others.
What you typed or clicked, and what happened instead. For a command, the exact line, switches included.
Whether the browser console shows anything at the moment it happens. The assistant can record page errors for you, but only if you have turned that permission on.
For a dark-mode gap, the address of the page and which part stayed the wrong colour. For a command that returned the wrong rows, the line and roughly how many rows you expected.
What never to send
No instance credentials. Nothing in a report needs them, and we have no way to hold them safely.
No record data. A screenshot of an incident carries every name, address and number on it. If a screenshot is the clearest way to show the fault, cover the fields that are not part of it.
No session cookie and no CSRF token. They are enough to act as you.
If a fault can only be explained with real data, say so and describe its shape instead: the table, the field, the kind of value.
Something that looks like a security problem
Tell us before you tell anyone else, and give us time to fix it. The address for that is on the security page, alongside what the extension can reach and what leaves your browser.
