---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Define object-indicator relationships

# Define object-indicator relationships {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Define relationships between the indicator object and other SDOs.

## Before you begin

Role required: sn_ti.admin

## Procedure

1. Navigate to AllThreat IntelligenceIoC RepositoryObject-Indicator-Relationships.
2. Click New.
3. Complete the fields in the form as appropriate.

   | Field | Description |
   | Object | Select and define the object. |
   | Type | Specifies the object type based on the object you selected. |
   | Indicator | Select the indicators of compromise. |
   | Relationship Direction | Define the relationship direction whether it is direct or inverse. |
   | Relationship Type | A description that provides more details and context about the relationship type. |
   | Source | Specifies the threat source from which this record is created. |
   | Source ID | Uniquely identifies the source object. |
   |-|-|

   {#define-object-indicator__choicetable_sq4_yvf_wmb}
4. Click Submit.
{#define-object-indicator__steps_hms_23t_wmb}

*[\>]: and then


