---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Generate recommended actions in UI16

# Generate recommended actions in UI16 for a security incident with Now Assist for Security Incident Response {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 min. de leitura

Automatically generate the next steps your analysts can take to help them close a security incident in the UI16 (legacy) view. The recommended steps are based on existing security incidents and knowledge articles.

## Antes de Iniciar

Generating recommended actions works for active security incidents in any states other than Closed or Cancelled.

The AI Search application must be enabled so that the Recommended Actions skill works for security incidents. To verify AI Search is enabled on your instance, navigate to AllAI SearchAI Search Status. Contact support if the page indicates AI Search is not enabled.

The recommended actions skill must be activated before you can see the Recommended actions button on a security incident.

Roles required: sn_si.analyst, sn_si.manager or sn_si.basic

## Procedimento

1. In the legacy Core UI, navigate to AllSecurity IncidentIncidents and open a security incident that is assigned to you.
2. Locate and select Recommended actions under the Short description field.  
   The recommended actions are listed along with the reference links.

   The recommended actions remain cached for one hour. You can refresh them if you leave the page, log out, log back in, and return within one
   hour to the security incident.

