---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Annotate security artifacts

# Annotate security artifacts {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

As you are analyzing a case, you can add annotations to any artifact.

## Before you begin

The Threat Intelligence plugin must be activated to use Security Case Management.  
Role required:

* sn_ti.case_user_write for adding annotations
* sn_ti.case_user_read to view annotations
{#annotate-artifacts__ul_nm1_2rh_c1b}

## Procedure

1. Open a case that contains artifacts that you want to annotate.
2. Click the Case Artifacts related list.
3. Click the tab associated with the artifacts you want to annotate.  
   For example, click Indicators of Compromise to add annotations to IoCs.
4. To add an annotation to one or more artifacts, perform the following steps:
   1. Select the artifacts to which you want to add an annotation.
   2. Click Annotate.  
   3. Type the annotation and click Annotate.  
      The annotation is added to the selected artifacts.
5. To view annotations for an artifact, click the View annotations (![View Annotations]()) icon.  
   The existing annotations appear in the Annotations dialog box.
6. You can also enter a new annotation for the artifact in the Security Annotation box, and click Annotate.
{#annotate-artifacts__steps_lr2_m11_2z}
**Related concepts**   

* [Related details for case artifacts](https://servicenow-prod.fluidtopics.net/ajcdrJhAoEjOoX3~sqLcKQ "As you add artifacts to a case, additional related details for each artifact may also be automatically added. For example, if you add a security incident, it may contain affected CIs and user records. You can quickly view the related details for a selected artifact without leaving the list of artifacts.")
* [Security artifact exclusion and inclusion](https://servicenow-prod.fluidtopics.net/jyccETG2tcFav3EhJ6r9Hw "The lists of supporting artifacts assigned to a case can sometimes get long and there may be instances where you want to remove particular artifacts from a list. Rather than permanently remove the artifacts, you can exclude them from the list and, as needed, return them to the list at a later time.")  
**Related tasks**   

* [Search for security artifacts](https://servicenow-prod.fluidtopics.net/cnsXnFihO7S_E65zHxedvg "You can perform a keyword search on any security artifact list.")

