---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Add the primary origin

# Add the primary origin {#ariaid-title1}

* Release version: Australia
* 
* Updated June 1, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Add a primary origin of an operational vulnerability in its record. Once the primary origin of the operational vulnerability is specified, its upstream dependencies are automatically included in the impacted areas. It enables
you to view the operational vulnerability from all affected perspectives. The source is automatically added as the primary origin on the Primary origin tab.

## Before you begin

Role required: Analyst assigned to the operational vulnerability

## About this task

Beginning with Release 20.1.x, the Operational Resilience application supports the latest Common Service Data Model (CSDM). The enhanced functionality supports the roll up of the dependencies.

Consider the following example where the relationships are configured between objects.

If you have a business process BP1 as shown in the relationship diagram, it has service offering SO1 and business service BS1 as upstream relationships. With the enhanced functionality, adding BP1 as an operational vulnerability automatically includes SO1 and BS1 in the impacted areas. The impacted areas are displayed in the Impacted Areas tab of the operational vulnerability record.

## Procedure

1. Navigate to WorkspacesOperational Resilience WorkspaceAll Operational Vulnerabilities.
2. Open the vulnerability for which you want to add the related area.
3. Update the source in the Source field.
4. Update the source record in the Source record field in the Primary origin section of the Details tab and select Save.  
   When you add the source and source record in the Primary origin section of the Details tab, the system automatically edits the primary origin. The primary origin displays on the Primary origin tab. In the following example, the Source Table is Business Service, the Source is Business service, and the selected source record is BS1000.  
   As shown in the example, the source record BS1000 is automatically updated as the primary origin on the Primary origin tab.

   Adding the primary origin automatically adds its upstream dependencies to the impacted areas as shown in the example. The operational vulnerability can be seen from all the impacted area.

   For example, you establish a relationship from a business service to a service offering, and from the service offering to a business process (BS - SO - BP). SO is the downstream entity of BS, and BP is the downstream entity of SO. In the Primary origin tab of the operational vulnerability, if you fetch the business process (BP), it automatically adds its upstream dependencies, as shown in the examples.  
   Note:  
   When the scheduled job is run, the operational vulnerabilities are gathered and shown in the red flags section of the Home page.
5. On the Primary origin tab, select Add.  
   You can add the primary origin of the operational vulnerability.  
   When you add the primary origin of the operational vulnerability, its impacted areas with upstream entities are updated on the Impacted areas tab.

   When the Calculate red flags for CSDM and dependencies scheduled job is executed, the updated impacted areas and the operational vulnerability count are updated on the dashboard.

   For example, when impacted areas in the operational vulnerability are updated, the operational vulnerability count on the overview page of SO1 is 0 before the scheduled job runs. After the scheduled job runs,
   the count is updated to 1.

   The updated data is promptly reflected on the Operational Resilience dashboard.
6. To update the impacted areas for a primary origin of the operational vulnerability, select Updated impacted area.  
   The application fetches the impacted areas for the primary origin.
7. To view the status of the uploaded upstream assets of the primary origin, select the View progress UI action.  
   The Operational Resilience administrator or manager can view the progress when adding the impacted assets to the operational vulnerabilities. The assets are listed in the Impacted areas tab as shown in the example.

*[\>]: and then


