Combined Now Assist for Security Incident Response and Now Assist for Vulnerability Response release notes for upgrades from Vancouver to Yokohama

  • Release version: Yokohama
  • Updated January 30, 2026
  • 13 minutes to read
  • Consolidated page of all release notes for Now Assist for Security Incident Response and Now Assist for Vulnerability Response from Vancouver to Yokohama.

    How to use this page

    To help you prepare for your upgrade, we have combined the cross-family Now Assist for Security Incident Response and Now Assist for Vulnerability Response release notes onto one page. Read this summary of the new features, changes, and updated information for your product from Vancouver to Yokohama.

    Tip:
    If there were no updates for a release notes section in a certain family release, we included a short note for your reference. For example, if a product did not have any updates in Tokyo, the row says "No updates for this release."

    Important information for upgrading Now Assist for Security Incident Response and Now Assist for Vulnerability Response to Yokohama

    Before you upgrade to Yokohama, review these pre- and post-upgrade tasks and complete the tasks as needed.

    Release Release notes

    Vancouver

    No updates for this release.

    Washington DC

    No updates for this release.

    Xanadu

    No updates for this release.

    Yokohama

    For more information about required applications for Now Assist for Vulnerability Response, see Supporting information. For more information about required applications for Now Assist for Security Incident Response, see Supporting information.

    Note:

    Upgrading the Now Assist plugins activate any designated skills that were previously untouched by the customer.

    • If you have the plugins installed but never touched the configuration (never activated the skill nor adjusted associated roles) of a skill, any Default On skill will be activated on a per skill basis upon upgrading.
    • If you have previously toggled a skill from active and then back to inactive or have updated any roles for that skill, that skill remains inactive upon upgrading.
    • You maintain full control over deactivating individual skills at any time after activation.
    Starting with version 2.0.1, the name of the Now Assist for Security Operations application in ServiceNow® Store and in your ServiceNow AI Platform® instance has changed to Now Assist for Security Incident Response. You must upgrade to version 2.0.1 to access the following features:
    • Generate resolution notes in the Now Assist context menu.
    • Generate correlation insights for a security incident investigation from the Now Assist panel.

    The AI Search application must be enabled so that the recommended actions skill works for security incidents. To verify that AI Search is enabled on your instance, navigate to All > AI Search > AI Search Status. Contact support if the page indicates that AI Search is not enabled.

    New features

    Between your current release family and Yokohama, new features were introduced for Now Assist for Security Incident Response and Now Assist for Vulnerability Response.

    Release Release notes

    Vancouver

    No updates for this release.

    Washington DC

    No updates for this release.

    Xanadu

    No updates for this release.

    Yokohama

    Yokohama Patch 11
    Role configuration required for agentic workflows and AI agents
    Agentic workflows and AI agents included with Now Assist applications require additional security configuration. If you select Users with selected roles for your user access security controls for an agentic workflow or AI agent, you must add the installed roles, or they will not execute. Data access settings must also include these roles. See the documentation for the agentic workflow or AI agent for the specific roles you must add.
    Some Now Assist skills are now turned on by default
    The new default behavior works as follows:
    • New customers: When you install a Now Assist product, designated skills are turned on automatically.
    • Existing customers who are upgrading (starting with Yokohama Patch 11): Any previously unconfigured skill is turned on automatically (the skill was never configured and turned on, then turned off again). Previously configured skills that were turned on, then off, remain inactive.
    Generate a quality assessment report
    Use generative AI to create a quality assessment report of a security incident. The reports are generated using a predefined, natural language rule set. The report provides an overall assessment summary followed by the detailed assessment for all the rules.
    Use Now Assist for Vulnerability Response to help you create a service graph connector in Security Posture Control
    You have the option to use Now Assist to help you automatically complete some of the steps in the Connector builder in the Security Posture Control workspace.
    Generate insights to prioritize risks
    Use generative AI to provide contextual summaries, actionable recommendations, and quick links in the Security Exposure Management Workspace, helping you prioritize critical risks and accelerate remediation.
    Generate recommendation for approval impact analysis
    Use generative AI to provide on-demand recommendation to approve or reject a request directly from the Exception Change Approval record, enabling approvers to make fast, consistent decisions while reducing manual analysis effort.
    Yokohama Patch 8
    Granular roles
    The sn_vul_ai.write_rem_insights and sn_vul_ai.read_rem_insights granular roles have been added and are inherited by the sn_vul.vulnerability_admin and sn_vul.vulnerability_analyst roles automatically. These roles provide you with more control over read and write access for the records on the Remediation Compliance Insights [sn_vul_ai_remediation_insights] caching table. The VR.System role also inherits these granular roles so background job execution for the workflow can occur.
    Yokohama Patch 6
    Generate SIR Shift Handover Report
    The AI Agent helps add security incident details to a shift handover report. The agent populates the different sections of the shift handover with appropriate content by identifying the relevant details from the security incident. The AI agent can fetch details of the security incident and identify if the analyst has access to the shift handover record. The AI agent can generate content for each section of the shift handover record and asks for analysts feedback on the content. The AI agent refines the content based on the feedback and saves the content to the records on approval.
    Identify duplicate vulnerable items
    Use generative AI to identify duplicates for your active host vulnerable items that are imported by your vulnerability scanners. Use generative AI reasoning with Now Assist to help your analysts differentiate between primary vulnerability items (VITs) and those VITs that are duplicates. Close duplicate VITs and move their associated detections automatically to the primary VIT records.
    Suggest vulnerability solutions
    Use generative AI to analyze available remediation options pulled from integrated third-party products like Red Hat, Tenable for Vulnerability Response, or internal solution management systems. Evaluate each option against the specific configuration item context, for example, the OS version or software version, and get recommendations for the most viable fix for implementation.
    Yokohama Patch 3
    Use agentic workflows
    The Analyze security operations metrics agentic workflow enables security managers to analyze their teams' performance.
    • Generate metrics for Security Incident Response (SIR) records for case volume, mean time to assign (MTTA), and mean time to resolve (MTTR) for a date range of your choosing.
    • Request suggestions for how to improve MTTR, MTTA, and volume based on your metrics.
    Enhancements to correlation insights in Now Assist for Security Incident Response
    You can generate and view results for correlation insights in the Security Incident Response Workspace.
    • Correlation insights are not limited to the primary configuration item (CI) or affected users associated with a security incident. You can base your correlation insights on any CI or affected user for a security incident.
    • You can generate correlation insights from the Investigation tab for a security incident in any state in the Security Incident Response Workspace.
    • You can generate insights for multiple items simultaneously for Associated Observables, Configuration items, and Affected Users.
    • Results are displayed in a modeless dialog that you can size and move.
    Use agentic workflows

    The Assess vulnerability exposure agentic workflow enables vulnerability managers to determine your exposure to vulnerabilities.

    • Determine your exposure to the most current Cybersecurity and Infrastructure Security Agency (CISA) known vulnerabilities in your environment and assess their potential impact to your configuration items (CIs) and business services.
    • Identify assets with Common Vulnerabilities and Exposures (CVEs).
    • Determine the number of active vulnerability items (VITs) that correspond to CVEs. Create watch topics for VIT remediation.

    The Analyze vulnerability remediation status agentic workflow enables vulnerability managers to monitor and assess remediation target compliance.

    • Track Service Level Agreement (SLA) compliance - Understand how effectively your organization is meeting remediation goals for vulnerabilities based on your SLAs.
    • Analyze missed SLAs by severity, assignment group, and configuration item (CI) class - Pinpoint gaps in remediation by categorizing overdue VITs based on severity, assignment groups, and CI classes to enable targeted interventions and smarter resource allocation.
    Using Security incident resolution agentic workflow
    Use the Security incident resolution agentic workflow to close your security incidents. Analysts can chat with the AI agents in natural language to resolve the security incidents. The AI agent analyzes the incident details, existing runbooks, knowledge articles, and past similar security incidents as inputs, and provides a resolution plan. The AI agent also assists the analysts to resolve the security incident.
    Yokohama Patch 1
    Using Security Incident Response AI agents
    Yokohama Patch 1: Use the Close security incident use case to close your security incidents:
    • Analysts can chat with the AI agents in natural language to close the security incidents. The AI agent can cancel the associated response tasks, generate resolution notes, close code, or close notes and post incident analysis (PIA) during incident closure. Analysts can provide feedback on the content and the AI agent can refine the content​ based on the feedback.
    • Analysts can also close false positive security incidents with minimal user intervention.
    Yokohama Early Availability
    • Generate correlation insights

      Generate correlation insights to connect current security incidents to past events. You can identify the affected users, configuration items (CI)s, or observables (IP addresses and file hashes) from existing incidents and records to help you more quickly triage your new security incidents. Correlation insights are supported in Workspace, the Core UI, and from the Now Assist panel.

    • Enhancements to closure (resolution) notes and post incident analysis generation
      Generate resolution notes from the Close the security incident modal or the Now Assist context menu on a security incident record (SIR). You can also generate resolution notes from the Now Assist panel. If you choose the Now Assist context menu, you have the following options to help you refine the generated text:
      • Shorten: Select the text to remove details.
      • Elaborate: Generate more details about the context of a security incident.
      Note:
      Generating resolution notes is supported in Workspace and Core UI. Generating a post incident analysis is supported from the Close the security incident modal in Workspace.

    Changes

    Between your current release family and Yokohama, some changes were made to existing Now Assist for Security Incident Response and Now Assist for Vulnerability Response features.

    Release Release notes

    Vancouver

    No updates for this release.

    Washington DC

    No updates for this release.

    Xanadu

    No updates for this release.

    Yokohama

    Yokohama Patch 11
    Changes to Now Assist usage measurement
    Some Now Assist skills are now turned on by default
    The following Now Assist skills for Now Assist for Security Incident Response and Now Assist for Vulnerability Response are activated by default.
    • Security incident summarization (SIR)
    • Resolution notes generation (SIR)
    • Post incident analysis (SIR)
    • Security incident recommended actions (SIR)
    • Correlation insights generation (SIR)
    • Security incident quality assessment (SIR)
    • Recommend preferred solution for VIT (VR)
    • Vulnerable item de-duplication (VR)
    • Approval Recommendation (VR)(USEM)
    • Security Exposure Management (SEM) Insights (VR)(USEM)
    • SPC Setup Connector (Security Posture Control)
    The new default behavior works as follows:
    • New customers: When you install a Now Assist product, designated skills are turned on automatically.
    • Existing customers who are upgrading (starting with Yokohama Path 11): Any previously unconfigured skill is turned on automatically (the skill was never configured and turned on, then turned off again). Previously configured skills that were turned on, then off, remain inactive.

    Removed

    Between your current release family and Yokohama, some Now Assist for Security Incident Response and Now Assist for Vulnerability Response features or functionality were removed.

    Release Release notes

    Vancouver

    No updates for this release.

    Washington DC

    No updates for this release.

    Xanadu

    No updates for this release.

    Yokohama

    No updates for this release.

    Deprecations

    Between your current release family and Yokohama, some Now Assist for Security Incident Response and Now Assist for Vulnerability Response features or functionality were deprecated.

    Release Release notes

    Vancouver

    No updates for this release.

    Washington DC

    No updates for this release.

    Xanadu

    No updates for this release.

    Yokohama

    No updates for this release.

    Activation information

    Review information on how to activate Now Assist for Security Incident Response and Now Assist for Vulnerability Response.

    Release Release notes

    Vancouver

    No updates for this release.

    Washington DC

    No updates for this release.

    Xanadu

    No updates for this release.

    Yokohama

    Install Now Assist for Security Incident Response and Now Assist for Vulnerability Response by requesting them from the ServiceNow Store.

    Additional requirements

    If any additional requirements were introduced or changed for Now Assist for Security Incident Response and Now Assist for Vulnerability Response we have noted them here.

    Release Release notes

    Vancouver

    No updates for this release.

    Washington DC

    No updates for this release.

    Xanadu

    No updates for this release.

    Yokohama

    No updates for this release.

    Browser requirements

    If any specific browser requirements were introduced or changed for Now Assist for Security Incident Response and Now Assist for Vulnerability Response we have noted them here.

    Release Release notes

    Vancouver

    No updates for this release.

    Washington DC

    No updates for this release.

    Xanadu

    No updates for this release.

    Yokohama

    No updates for this release.

    Accessibility information

    Review details on accessibility information for Now Assist for Security Incident Response and Now Assist for Vulnerability Response, such as specific requirements or compliance levels.

    Release Release notes

    Vancouver

    No updates for this release.

    Washington DC

    No updates for this release.

    Xanadu

    No updates for this release.

    Yokohama

    No updates for this release.

    Localization information

    If there are specific localization considerations for Now Assist for Security Incident Response and Now Assist for Vulnerability Response we have noted them here.

    Release Release notes

    Vancouver

    No updates for this release.

    Washington DC

    No updates for this release.

    Xanadu

    No updates for this release.

    Yokohama

    No updates for this release.

    Highlight information

    If there are specific highlight considerations for Now Assist for Security Incident Response and Now Assist for Vulnerability Response we have noted them here.

    Release Release notes

    Vancouver

    No updates for this release.

    Washington DC

    No updates for this release.

    Xanadu

    No updates for this release.

    Yokohama

    Yokohama Patch 11
    • Review changes to Now Assist usage measurement.
    • Some Now Assist skills, agents, and agentic workflows are on by default.
    • Additional role configuration is required for agentic workflows and AI agents included with Now Assist applications.
    • Use Now Assist for Vulnerability Response with Security Posture Control to help you with Creating an API connector in the Security Posture Control workspace.
    • Use generative AI to create a quality assessment report of a security incident.
    • Yokohama Patch 6

      Help your analysts identify duplicate host vulnerable items and analyze available remediation options with generative AI skills with Now Assist for Vulnerability Response.

      Help analysts to add security incidents details to the Shift Handover report by chatting with AI agents in the Now Assist panel.

      • Use Google Gemini and Anthropic Claude on AWS as AI model providers for Now Assist skills and AI agents in addition to Now LLM Service and Azure OpenAI.
    • Yokohama Patch 3

      Help your analysts to gain insight into security incident record metrics with an agentic workflow. Chat with AI agents in natural language from the Now Assist panel.

      Help your vulnerability managers and analysts to assess your exposure to vulnerabilities and analyze metrics for remediation targets. Chat with AI agents in natural language from the Now Assist panel.

      Help your analysts to resolve security incidents by chatting with AI agents in the Now Assist panel where the AI agent provides a resolution plan.

    • Yokohama Patch 1

      Help your analysts to close security incidents more efficiently by chatting with AI agents in natural language from the Now Assist panel.

    • Yokohama early availability
      • Triage security incidents with long activity streams by reviewing work notes and contextual information quickly in a concise, easy-to-read format.
      • Automatically generate resolution notes for security incidents by using generative AI.
      • Generate recommended actions to resolve security incidents.
      • Generate a post-incident analysis.
      • Generate correlation insights to help you connect current incidents to past events. By identifying the affected users, configuration items (CIs), or observables (IP addresses and file hashes) from existing incidents, you can help to triage new security incidents.
      For more information, see Now Assist for Security Incident Response and Now Assist for Vulnerability Response.