---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Return excluded security artifacts to a case

# Return excluded security artifacts to a case {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

After you have excluded artifacts from a list in a case, you can return them to the
case you can continue to work on them.

## Before you begin

The Threat Intelligence plugin must be activated to use Security Case Management.

Role required: sn_ti.case_user_write

## Procedure

1. Open a case that contains artifacts that you previous excluded from a list that you want to return to the list.
2. Click the Case Artifacts related list.
3. Click the tab associated with the artifacts you want to return to the list.
4. Click the Artifact Filter drop-down list and select Excluded Artifacts.  
5. Select one or more artifact records that you want to return to the Include list.
6. From the Actions on selected items drop-down list, select Include.  
7. Click Include in the confirmation box.  
   The selected artifacts are removed from the list of excluded artifacts and returned to the list of artifacts included in the case.
{#include-artifacts__steps_lr2_m11_2z}
**Related tasks**   

* [Exclude security artifacts from a case](https://servicenow-prod.fluidtopics.net/zBspK7oSNiYxVD~DE8eCCg "You can remove artifacts from the lists of supporting artifacts. They are not permanently removed and can be returned to the case as needed.")

