---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Security Operations Integration - CI Enrichment flow

# Security Operations Integration - CI Enrichment flow {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 min. de leitura

The Security Operations Integration - CI Enrichment flow allows you to enrich data in configuration items (CI) associated with a security incident.

## Antes de Iniciar

Role required: sn_si.analyst

## Por Que e Quando Desempenhar Esta Tarefa

This flow is triggered from Security Incident Response in two ways.

* by selecting one or more CIs from the Configuration Items tab (under the Affected Items related link) and selecting Run CI enrichment from the Actions on selected rows choice list.
* by opening a CI record and clicking the Run CI enrichment related link.

{#secops-integ-enrich-ci-wf__ul_oqw_mvx_v1b}  
Either method then allows you to specify which implementations to be used to enrich the selected CIs. The associated implementation flows are executed to perform the enrichment.  
Nota:  
The base system does not include an implementation flow for this capability. To enrich CIs, you must create your own implementation [flow](https://www.servicenow.com/docs/access?context=c_WorkflowOverview&version=australia&pubname=australia-build-workflows&ft:locale=en-US).
Figura 1. CI Enrichment

Actions specific to this flow are described here. For more information on other actions, see [Common Security Operations integration flows and orchestration activities](https://servicenow-prod.fluidtopics.net/KMDauzEgIIpChAc9WGx3Sg "Many of the flows associated with third-party integrations include the same activities. For example, activities for beginning and completing processing.").  
The flow process actions include:

* [Execution Tracking - Begin Flow Action](https://servicenow-prod.fluidtopics.net/pdKU5_E7bFtNiW1dsL~Aeg "The Execution Tracking - Begin flow action starts the auditing process for a Security Operations Integration flow that operates on observables.")
* [Security Operations Integration - CI Enrichment flow](https://servicenow-prod.fluidtopics.net/Wf2ULpR9dCr2eWdgxYaWug "The Security Operations Integration - CI Enrichment flow allows you to enrich data in configuration items (CI) associated with a security incident.")
* [Capability Execution Tracking- No Impls action](https://servicenow-prod.fluidtopics.net/hx_sFr0ICLcP65acYf4ccQ "The Capability Execution Tracking - No Impls flow action creates an error record when no integration capability implementation is found.")
* [Get Supported Security Capabilities action](https://servicenow-prod.fluidtopics.net/R~gbdTjl6fwVseBb52iYoQ "The Get Supported Capabilities flow action retrieves the name and number of integrations that are active and support the requested capability.")
{#secops-integ-enrich-ci-wf__ul_bc3_n4y_hcc}

