---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Resolve security incident agentic workflow

# Security Incident Response AI agent collection Resolve security incident agentic workflow {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 min. de leitura

Chat with an AI agent in the Now Assist panel to help you create a resolution plan for a security incident and to resolve it.

## Resolve security incident agentic workflow overview {#now-assist-sir-resolve-incident-ai-workflow__section_ocf_d2x_t2c}

Use the Resolve security incident agentic workflow to fetch the incident details, fetch the knowledge articles and similar closed security incidents, get a resolution plan, and resolve the security incident.

If you want to modify this agentic workflow, you can [duplicate](https://www.servicenow.com/docs/access?context=clone-aia-usecase&version=australia&pubname=australia-intelligent-experiences&ft:locale=en-US) it, adjust the settings to suit your specific needs, and activate the duplicated version of the agentic workflow instead.

## Agents used in the Resolve security incident agentic workflow {#now-assist-sir-resolve-incident-ai-workflow__section_tjt_sfx_t2c}

The Resolve security incident agentic workflow contains the following AI agents:

* Endpoint Detection and Response AI agent
* Exchange online integration handling AI agent
* Observable analysis AI agent
* Security incident resolution AI agent
* Security incident wrap up generator AI agent
* Security incident activities handling AI agent
{#now-assist-sir-resolve-incident-ai-workflow__ul_f2v_5zc_52c}

## Tools mapped to the Resolve security incident plan generator AI agent {#now-assist-sir-resolve-incident-ai-workflow__section_u2r_vjx_t2c}

All tools are of script type.
{#now-assist-sir-resolve-incident-ai-workflow__table_qsq_pkx_t2c__entry__3}

| Name | Execution mode | Description |
|-|-|-|
| Fetch security incident details | Autonomous | Fetches the security incident details from the security incident number. |
| Fetch knowledge and similar incidents | Autonomous | Fetches relevant knowledge articles and similar closed security incidents with a search query. |
[Tabela 1. Tools mapped to the Resolve security incident plan generator AI agent]

{#now-assist-sir-resolve-incident-ai-workflow__table_qsq_pkx_t2c}

## Tools mapped to the Security incident wrap-up generator AI agent {#now-assist-sir-resolve-incident-ai-workflow__section_ewb_bkx_t2c}

{#now-assist-sir-resolve-incident-ai-workflow__table_uzq_clx_t2c__entry__4}

| Tool type | Execution mode | Name | Description |
|-|-|-|-|
| Scripts | Autonomous | Fetches security incident details | Fetches the security incident details from the security incident number. |
| Scripts | Autonomous | Gets close code values | Tool to get available close code values for the security incident. |
| Scripts | Autonomous | Closes the security incident as false positive | Tool used when the incident is being closed as a false positive. |
| Scripts | Autonomous | Updates the security incident | Updates a field of the security incident. |
| Subflow | Autonomous | Generates close notes | Generates closure notes for the security incident. |
| Subflow | Autonomous | Generates post incident analysis | Generates post incident analysis for the security incident. |
[Tabela 2. Tools mapped to security incident wrap-up generator]

{#now-assist-sir-resolve-incident-ai-workflow__table_uzq_clx_t2c}

## Tools mapped to the Security incident observable analyzer AI agent {#now-assist-sir-resolve-incident-ai-workflow__section_ch5_dkx_t2c}

All tools are of script type.
{#now-assist-sir-resolve-incident-ai-workflow__table_vq4_nlx_t2c__entry__3}

| Name | Execution mode | Description |
|-|-|-|
| Retrieve capability execution results | Autonomous | Retrieves threat lookup and provides observable enrichment results. |
| Run Threat lookup | Autonomous | Performs threat lookup on observables. |
| Run Observable enrichment | Autonomous | Fetches additional context related to the observables. |
| Fetch Observable Associated to Security Incident | Autonomous | Retrieves observables associated to a security incident. |
[Tabela 3. Tools mapped to the security incident observable analyzer AI agent]

{#now-assist-sir-resolve-incident-ai-workflow__table_vq4_nlx_t2c}

## Tools mapped to the Security incident core activities handler AI agent {#now-assist-sir-resolve-incident-ai-workflow__section_pcr_fkx_t2c}

All tools are of script type.
{#now-assist-sir-resolve-incident-ai-workflow__table_fq5_fmx_t2c__entry__3}

| Name | Execution mode | Description |
|-|-|-|
| Update incident state | Autonomous | Updates the state field of a security incident. |
| Send email | Autonomous | Sends emails. |
| Create related record | Autonomous | Creates incidents, problems, change requests, or response tasks. short_description, description, security_incident_sys_id input parameters are mandatory to invoke this tool. |
[Tabela 4. Tools mapped to the security incident core activities handler AI agent]

{#now-assist-sir-resolve-incident-ai-workflow__table_fq5_fmx_t2c}

## Triggers for the Resolve security incident agentic workflow {#now-assist-sir-resolve-incident-ai-workflow__section_vb5_pmx_t2c}

There are no triggers for this use case. If required, you can add a trigger to invoke the use case automatically.

