---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Create security annotations for observables

# Create security annotations for observables {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

You can select a single or multiple observables and apply security annotations to
them using the Actions on selected rows choice menu.

## Before you begin

* Requires the Threat Intelligence plugin and activation. The Threat Intelligence plugin is available as a separate subscription.
{#create-security-annotations-multiple__ul_zvq_fyk_nsb}Role required: admin

## Procedure

1. Navigate to AllThreat IntelligenceObservables
2. Select one or more observables in the list.
3. From the Actions on selected rows drop-down menu, choose Add security annotation.
4. Enter an annotation.  
   Annotations can be in any text format.
5. Select Submit.
{#create-security-annotations-multiple__steps_tfz_1yz_pz}
**Related tasks**   

* [Create security annotations for CIs](https://servicenow-prod.fluidtopics.net/NOMV9oPcnSv1svsz1I8oDA "Annotations on CIs allow you to track activity across incidents. You can add annotations to a single or multiple CIs.")
* [Create security annotations for users](https://servicenow-prod.fluidtopics.net/mNagrCUb23CYtTLM1fywNA "You can select a single or multiple users and apply security annotations to them using the Actions on selected rows choice menu.")
* [View security annotations reports](https://servicenow-prod.fluidtopics.net/HqLUmCYUYeXHVvE8ZzwwtA "The Security Annotations report presents details stored in the Security Annotations [sn_sec_cmn_security_annotations] table. You can customize the columns in the report and group the data in any way that suits you.")

*[\>]: and then


