---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Use agentic workflows

# Using agentic AI workflows {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Using agentic AI workflows

Agentic AI workflows in Security Incident Response enable autonomous task completion by leveraging AI agents.
These workflows use role masking to control user access, with roles typically predefined by the application.
Customers must configure security controls to grant access to users with specific roles.
Access to agentic workflows and AI features may vary based on your ServiceNow license and product tier.
Show full answer Show less  
Some generative AI skills, AI agents, and agentic workflows are enabled by default depending on whether you are a new or existing customer. New customers get these features automatically upon installation, while existing customers retain their current configurations unless changes were never made or the AI plugin was newly installed.

## Key Features

* **Role-based access control:** Access to agentic workflows is managed via role masking, ensuring appropriate security and permissions.
* **Preconfigured agentic workflows:** Various workflows support common Security Incident Response tasks, such as:
  * Wrapping up security incidents using natural language interaction.
  * Analyzing security operations metrics including case volume, mean time to assign (MTTA), and mean time to resolve (MTTR).
  * Resolving security incidents with guidance and closure support.
  * Generating shift handover reports with incident details.
* **Read-only default settings:** Agentic workflows and AI agent records are read-only by default; to modify workflows, duplication is required.
* **Automation triggers:** Optionally, triggers can be added to invoke workflows automatically to streamline processes.
* **Availability of AI agents:** Some AI agents may exist on your instance without being linked to agentic workflows; you can view all available agents to explore further capabilities.

## Practical Implications for ServiceNow Customers

By leveraging these agentic AI workflows, security teams can streamline incident management with AI-powered automation, improving efficiency and accuracy in incident closure, analysis, and reporting. Role-based security ensures that only authorized users access sensitive AI-driven capabilities, maintaining compliance and control.

Customers should verify their license entitlements to understand which AI features and workflows are available and configure security controls accordingly. Modifications to workflows require duplicating existing ones, preserving out-of-the-box configurations.  
Use the Security Incident Response AI agentic workflows to complete your tasks autonomously.

Agentic workflows and their AI agents use [role masking](https://www.servicenow.com/docs/access?context=aia-role-masking&version=australia&pubname=australia-intelligent-experiences&ft:locale=en-US) to determine which users can access them. Ones installed with your applications have specific roles that come included with the application. If you select Users with specific roles for user access, you must configure the security controls to include these roles. For the instructions to change the security controls, see [Define security controls for an agentic workflow](https://www.servicenow.com/docs/access?context=define-sec-controls-aw&version=australia&pubname=australia-intelligent-experiences&ft:locale=en-US).  
Note:  
Depending on your license, you will have access to certain application features, generative AI skills, agentic workflows, and AI agents. For more information, see [ServiceNow product tiers](https://www.servicenow.com/docs/access?context=ai-native-sku-overview&version=australia&pubname=australia-intelligent-experiences&ft:locale=en-US).  
Important:  
Some generative AI skills, agents, and agentic workflows are turned on by default. The default behavior works as follows:

New customers
:   When you install an AI product, designated generative AI skills, AI agents, or agentic workflows are turned on automatically.

Existing customers who are upgrading (starting with Zurich Patch 4)

:   There is no change to skills, agents, or agentic workflows that are currently enabled and customized.An AI asset is turned on if:

    * The AI plugin is installed, but the asset was never turned on.
    * An admin has never adjusted roles for the skill.

    {#using-now-assist-ai-agents-sir__ul_yvc_bvq_g3c}  
    An AI asset is not turned on if:

    * The asset was previously turned on, and then turned off again.
    * An admin has adjusted roles for the asset.
    {#using-now-assist-ai-agents-sir__ul_zvc_bvq_g3c}
For more information, see [AI agents, skills, and agentic workflows on by default](https://www.servicenow.com/docs/access?context=now-assist-skills-on-by-default&version=australia&pubname=australia-intelligent-experiences&ft:locale=en-US).
{#using-now-assist-ai-agents-sir__table_fsq_52h_m2c__entry__3}

| Agentic workflow name | Description | Available AI agents |
|-|-|-|
| Wrap up security incident | This agentic workflow helps the security analysts to close a security incident using natural language in the ServiceNow Otto panel. | Security incident wrap-up generator AI agent |
| Analyze security operations metrics | This agentic workflow helps a security operations center (SOC) manager analyze their security analysts' performance. Metrics are generated for security incident response (SIR) records for case volume, mean time to assign (MTTA), and mean time to resolve (MTTR). | * Security incident retrieval AI agent * Security metrics analysis AI agent {#using-now-assist-ai-agents-sir__ul_nxz_v3m_w2c} |
| Resolve security incident | This agentic workflow helps the security analysts to identify a security incident resolution path. This workflow also assist the security analysts to close a security incident using natural language in the ServiceNow Otto panel. | * Security incident resolution AI agent * Exchange online integration handling AI agent * Security incident wrap up generator AI agent * Observable analysis AI agent * Security incident activities handling AI agent * EDR AI agent {#using-now-assist-ai-agents-sir__ul_nx5_2ty_1fc} |
| Generate SIR Shift Handover Report | This agentic workflow adds details of a security incident to the shift handover report. The agent populates the different sections of the shift handover with appropriate content by identifying the relevant details from the security incident. | Security incident shift handover AI agent |
[Table 1. Available agentic workflows for AI agents for Security Incident Response]

{#using-now-assist-ai-agents-sir__table_fsq_52h_m2c}  
Important:  
By default, all agentic workflows and AI agent records are read-only.

To modify an agentic workflow, you must first [duplicate the agentic workflow](https://www.servicenow.com/docs/access?context=clone-aia-usecase&version=australia&pubname=australia-intelligent-experiences&ft:locale=en-US). If required, you can add a trigger to invoke the workflow automatically.

There might be AI agents installed on your instance that are not used in agentic workflows. To learn how to see all agents that are available to you, see [Find AI agents](https://www.servicenow.com/docs/access?context=find-ai-agents&version=australia&pubname=australia-intelligent-experiences&ft:locale=en-US).

