---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Exclude security artifacts from a case

# Exclude security artifacts from a case {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

You can remove artifacts from the lists of supporting artifacts. They are not
permanently removed and can be returned to the case as needed.

## Before you begin

* The Threat Intelligence plugin must be activated to use Security Case Management.
{#exclude-records__ul_idt_k2d_nsb}Role required: sn_ti.case_user_write

## Procedure

1. Open a case that contains artifacts that you want to exclude from a list.
2. Click the Case Artifacts related list.
3. Click the tab associated with the artifacts you want to exclude.  
   For example, click Incidents to exclude security incidents from the list.
4. Select one or more artifact records that you want to exclude.  
5. From the Actions on selected items drop-down list, select Exclude.
6. Click Exclude in the confirmation box.  
   The selected artifacts are removed from the list.
{#exclude-records__steps_lr2_m11_2z}
**Related tasks**   

* [Return excluded security artifacts to a case](https://servicenow-prod.fluidtopics.net/SqbcrN5mgARewNITC8JQqg "After you have excluded artifacts from a list in a case, you can return them to the case you can continue to work on them.")

