---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Use generative AI skills

# Using ServiceNow Otto for Security Incident Response (SIR) generative AI skills {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Using ServiceNow Otto for Security Incident Response (SIR) generative AI skills

ServiceNow Otto enhances Security Incident Response (SIR) by integrating generative AI skills, enabling security analysts to efficiently manage and close security incidents within their workflow.
These AI capabilities help summarize incident details, generate closure notes, recommend next steps, analyze post-incident data, and produce correlation insights and quality assessment reports, accelerating incident resolution and improving operational efficiency.
Show full answer Show less  

## Key Features

* **Domain-Separated Data Security:** AI skills operate within domain-separated environments, ensuring user access and AI responses are restricted to data within the user's domain. No data is co-mingled, and generative AI requests and responses are not persisted outside the instance.
* **Role-Based Access Control:** AI agents use role masking to control access to skills and data. Specific roles included with ServiceNow Otto applications must be configured in security controls and data access settings to enable user access.
* **Generative AI Capabilities:**
  * Summarize security incidents, including key details, observables, and actions taken.
  * Generate closure (resolution) notes automatically.
  * Recommend next steps and create remediation tasks (from Security Incident Response Workspace).
  * Generate post-incident analysis and performance metrics for remediation teams.
  * Produce correlation insights to speed up investigations.
  * Generate quality assessment reports for security incidents.
* **Access Points:** Security incident summaries and closure notes can be requested from security incident records, the Security Incident Response Workspace, and the ServiceNow Otto panel. However, recommended actions and post-incident analysis skills are not available through the Otto panel but can be accessed via incident records and the SIR Workspace.
* **Customization:** Input fields for AI skills can be customized to align with specific organizational requirements.
* **Licensing and Default Settings:** Availability of features depends on the customer's ServiceNow license tier. Some generative AI skills and workflows are enabled by default.

## Practical Benefits for ServiceNow Customers

* Accelerated incident closure through AI-generated summaries and notes, reducing manual effort for security analysts.
* Improved incident investigation speed with AI-generated correlation insights and recommended actions.
* Enhanced post-incident learning and reporting via automated analysis and quality assessment reports.
* Secure and compliant AI usage in domain-separated environments, ensuring data privacy and governance.
* Flexible integration within existing SIR workflows and multiple access points to maximize analyst efficiency.  
Security analysts can close security incidents quickly from within their flow of work with the generative AI skills supported by ServiceNow Otto for Security Incident Response (SIR).

## Skills in global domain reuse {#using-now-assist-for-security__section_vkh_cpq_mhc}

By default, all skills exist in the global domain. When you use AI in a domain-separated environment, users are only able to access data in their domain. For example, if a user uses the
summarization skill, AI only uses material that exists in the user's domain when generating that summary. Additionally, there is no co-mingling of data for domain-separated instances when using generative AI skills. The data resides
only on the instance, and the shared services used for generative AI do not persist any requests (prompts) and responses. For more information, see [Domain separation in the AI Admin Hub console](https://www.servicenow.com/docs/access?context=domain-separation-in-the-now-assist-admin-console&version=australia&pubname=australia-intelligent-experiences&ft:locale=en-US). (Note that global domain is not the same as global scope. For more information, see [Exploring Next Experience pickers](https://www.servicenow.com/docs/access?context=next-experience-pickers&version=australia&pubname=australia-platform-user-interface&ft:locale=en-US).){#using-now-assist-for-security__na-skills-global-domain-explanation}
AI agents use [role masking](https://www.servicenow.com/docs/access?context=aia-role-masking&version=australia&pubname=australia-intelligent-experiences&ft:locale=en-US) to determine which users can access them and what data they have access to. Ones installed with ServiceNow Otto applications have specific roles that come included with the application. If you select Users with specific roles for user access, you must configure the security controls to
include these roles. Data access settings must also include these roles. For the instructions to change the security controls, see [Define security controls for an AI agent](https://www.servicenow.com/docs/access?context=define-sec-controls-aia&version=australia&pubname=australia-intelligent-experiences&ft:locale=en-US).{#using-now-assist-for-security__agentic-ai-req-roles-aia}  
Important:  
Some generative AI skills, AI agents, and agentic workflows are turned on by default. For more information, see [AI agents, skills, and agentic workflows on by default](https://www.servicenow.com/docs/access?context=now-assist-skills-on-by-default&version=australia&pubname=australia-intelligent-experiences&ft:locale=en-US).  
Note:  
Depending on your license, you will have access to certain application features, generative AI skills, agentic workflows, and AI agents. For more information, see [ServiceNow product tiers](https://www.servicenow.com/docs/access?context=ai-native-sku-overview&version=australia&pubname=australia-intelligent-experiences&ft:locale=en-US).

With generative AI skills with ServiceNow Otto for Security Incident Response (SIR), your security analysts have the option to:

* Summarize security incident details and review the context quickly in a concise, easy-to-read format.
* Generate closure (resolution) notes.
* Generate recommended actions for a security incident
* Generate post incident analysis data
* Generate performance metrics for your remediation teams.This skill is activated for use with an AI agent. See [Analyze security operations metrics](https://servicenow-prod.fluidtopics.net/IOjk1qFmeHEg25PcW3Qbow "Chat with an AI agent from the ServiceNow Otto panel to help you gain insight into how efficiently your security analysts are working with security incidents resolution.") for more information.

* Generate correlation insights to speed up incident investigation.
* Generate a quality assessment report of a security incident

Security managers and analysts can request security incident summaries and closure notes from the following locations:

* Security incident records
* Security Incident Response Workspace
* The ServiceNow Otto panel.  
  Note:  
  The security incident recommended actions and post-incident analysis skills are not available from the ServiceNow Otto panel.

{#using-now-assist-for-security__ul_hlb_gb4_bcc}  
Security managers and analysts can generate recommended next steps and post-incident analysis data from the following locations:

* Security incident records
* Security Incident Response Workspace
{#using-now-assist-for-security__ul_krk_gld_ycc}

Security managers and analysts can create remediation tasks from generated recommended actions only from security incidents in the Security Incident Response Workspace.

Security managers and analysts can request security incident summaries and closure notes from the following locations:

* Security incident records
* Security Incident Response Workspace
* The ServiceNow Otto panel.  
  Note:  
  The security incident recommended actions and post-incident analysis skills are not available from the ServiceNow Otto panel.

Security managers and analysts can generate recommended next steps and post-incident analysis data from the following locations:

* Security incident records
* Security Incident Response Workspace

Security managers and analysts can create remediation tasks from generated recommended actions only from security incidents in the Security Incident Response Workspace.

1. [Summarize a security incident](https://servicenow-prod.fluidtopics.net/WuiYXhGs_TTCmYr4nkbuCg "Understand the context of a security incident with the Security Incident summarization generative AI skill.")

   Generate a summary for a security incident that includes the underlying issue, incident details, related lists data (observables), and key actions already taken.
2. [Generate recommended actions](https://servicenow-prod.fluidtopics.net/~o2W9XqVxDNrJDbRLYNZhg "Automatically generate the next steps your analysts can take to help them close a security incident in the Security Incident Response Workspace. The recommended steps are based on existing security incidents and knowledge articles.")
3. [Generate a post-incident analysis](https://servicenow-prod.fluidtopics.net/x4G0umVhTvkHQVXZoOsoEQ "Automatically generate a post-incident analysis for a security incident that includes a root cause analysis, impact assessment, and learning and recommendations information.")
4. [Generate correlation insights in the ServiceNow Otto panel](https://servicenow-prod.fluidtopics.net/nd7OD2F4ij~YsTFxxZT2QA "Generate correlation insights from the ServiceNow Otto panel to help you connect past events to the security incident that you're working on.")
5. [Generate a quality assessment report](https://servicenow-prod.fluidtopics.net/n5T6sRsgFb921PP3UdPIAA "Generate a quality assessment report for a security incident using a predefined rule set.") for a security incident
6. [Generate closure notes](https://servicenow-prod.fluidtopics.net/HWeP1dIXilE1F2K8DTzG7w "Automatically generate a draft of the closure notes for a security incident when you close it. The draft is editable and will be reviewed before closing the security incident, and it can be used or modified as needed. Closure notes provide information about the resolution of a security incident to other analysts, managers, and key stakeholders.")

   Automatically generate the closure notes for a security incident.
7. [Request generative AI skills](https://servicenow-prod.fluidtopics.net/5RHqkhdiFcEeWS8EL0RWUA "Request a security incident summary or closure notes from the ServiceNow Otto panel.")

   Generate summaries and closure notes from the ServiceNow Otto panel.  
   Note:  
   The security incident recommended actions and post-incident analysis skills are not available from the ServiceNow Otto panel.
8. [Customize a skill](https://servicenow-prod.fluidtopics.net/ZmCGJ3QeQAyiz4JinFR8ow "Customize some of the input fields of a generative AI skill to suit the requirements of your environment.")

   Customize the input fields of a skill to suit the requirements of your environment.
{#using-now-assist-for-security__cf-using-parent-steps-ol}

