---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Use the AI guardrails helper agentic workflow

# Use the AI guardrails helper agentic workflow {#ariaid-title1}

* Release version: Australia
* 
* Updated August 3, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Use the AI agent to ask about guardrails identified by the AI skill component in the AI Guardrails Helper. Automatically defer findings with existing mitigations in the form of guardrails and create exception rules to
automatically defer future findings.

## Before you begin

The ServiceNow Otto® panel must be activated. For more information, see [Activate the ServiceNow Otto panel standard chat](https://www.servicenow.com/docs/access?context=activate-now-assist-panel&version=australia&pubname=australia-intelligent-experiences&ft:locale=en-US).

Roles required: sn_vul.vulnerability_admin or sn_vul.vulnerability_analyst admin

## About this task

Because the agentic workflow uses AI to generate responses, review all output before acting on it and apply human judgment to any remediation decisions.{#ai-security-exposure-use-agent__ai-security-exposure-use-agent-context-1}

Before providing the agent with instructions, use the AI guardrails helper skill to collect guardrail suggestions for findings that have associated vulnerabilities.

## Procedure

1. Navigate to WorkspacesSecurity Exposure Management Workspace.
2. If the AI validation findings tab is not displayed, select it.
3. Select Ask ServiceNow Otto to invoke the agent.  
   A new panel opens. The agent displays the following options:

   Find mitigated validation findings
   :   Locate mitigated findings by threat categories to help you see more about the AI behavioral threats identified by automated red teaming or validation.

   Defer validation findings
   :   Defer findings returned by the Guardrail Detector skill, or a subset of the returned results, using AI-generated justifications for deferral.

   Create exception rule
   :   Create exception rules to automatically defer future AI validation findings that have guardrails as mitigations already present in the AI security platform. See [Configure Exception Management for Security Exposure Management](https://servicenow-prod.fluidtopics.net/JZ0xXrugG35YGdIcnEdkUg "When your organization can't comply with a vulnerability management or security policy, standard, or guideline, you can request an exception. Exception management entails requesting, reviewing, approving, or rejecting exceptions to a finding or remediation task (RT) that can't be remediated according to the policy.") for more information about exception management.

   Learn about guardrails
   :   View how active mitigations in your environment help defer findings and reduce risk.  
       Note:  
       For deferred findings, associated threats are imported and stored for potential reconsideration.
4. Select a prompt in the panel.  
   For example, if you select Defer validation findings, you can defer all findings for a specific criterion: risk rating, assignment group, and so on.

   The system displays a justification for the deferral for your review. You can approve or reject the justification. If you approve it, a calendar is displayed. Choose an end date for the deferral. After you select
   Submit, the finding state transitions from Open to Deferred.

   The system displays the number of findings associated with your deferral request and prompts you to create an exception rule.

   If you select Yes, a rule is created. Select the link to view your new rule. The system displays the record for review. You can modify the conditions of the rule and select
   Save to preserve your changes. Select Submit to send your new rule for approval based on your approval hierarchy and approval rules described in the Exception
   Management documentation.

   Select the Approvals tab on the approval rule record to view the status of your requests.
{#ai-security-exposure-use-agent__steps_qr4_kbs_x3c}

*[\>]: and then


