---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Retrieve vulnerability and exposure data with generative AI

# Retrieve Vulnerability and exposure data with generative AI {#ariaid-title1}

* Release version: Australia
* 
* Updated July 29, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Chat with an AI agent to retrieve information about Vulnerability Response (host) and Application Vulnerability Response findings (vulnerable items and application vulnerable items).

## Before you begin

Note:  
Depending on your license, you will have access to certain application features, generative AI skills, agentic workflows, and AI agents. For more information, see [ServiceNow product tiers](https://www.servicenow.com/docs/access?context=ai-native-sku-overview&version=australia&pubname=australia-intelligent-experiences&ft:locale=en-US).

The ServiceNow Otto® panel must be activated. For more information, see [Activate the ServiceNow Otto panel standard chat](https://www.servicenow.com/docs/access?context=activate-now-assist-panel&version=australia&pubname=australia-intelligent-experiences&ft:locale=en-US).  
Roles required:

* sn_vul.remediation_owner (host vulnerable items (VITs))
* sn_vul.vulnerability_analyst (host vulnerable items (VITs))
* sn_vul.app_sec_manager (application vulnerable items (AVITs))
{#retrieve-vr-data__ul_hqq_c43_shc}

## Procedure

1. Log in to your ServiceNow AI Platform instance.  
   The vulnerability records that you can see depend on the roles you have been assigned. Host Vulnerability Response and Application Vulnerability Response findings (VITs, AVITs) are supported.  
   Note:  
   You aren't required to have all of these roles assigned to chat with the AI agent. To view VITs, at a minimum, you must have either sn_vul.remediation_owner or sn_vul.vulnerability_analyst assigned. to view AVITs, at a minimum, you must have sn_vul.app_sec_manager assigned.
2. Alternatively, navigate to Workspaces in your ServiceNow AI Platform instance and choose one.  
   {#retrieve-vr-data__table_a5v_djj_shc__entry__3}

   | Option | ServiceNow AI Platform Role | Description |
   |-|-|-|
   | IT Remediation Workspace | sn_vul.remediation_owner for VITs. | The IT Remediation owner (legacy) workspace is supported by versions of Vulnerability Response earlier than version 30.0. |
   | Vulnerability Manager Workspace | sn_vul.vulnerability_analyst for VITs or sn_vul.app_sec_manager for AVITs. | The Vulnerability Manager (legacy) workspace is supported by versions of Vulnerability Response earlier than version 30.0. |
   | Security Exposure Management Workspace | * sn_vul.remediation_owner (host vulnerable items (VITs)) * sn_vul.vulnerability_analyst (host vulnerable items (VITs)) * sn_vul.app_sec_manager (application vulnerable items (AVITs)) {#retrieve-vr-data__ul_b5v_djj_shc} | The Security Exposure Management Workspace is supported by Unified Security Exposure Management (USEM). You must have version 30.0 or later of Vulnerability Response installed to view this workspace. See [Implementing Unified Security Exposure Management](https://servicenow-prod.fluidtopics.net/zutRES6UyPXLgGPH_zg8eA "This section guides you through the entire process of implementing Unified Security Exposure Management (USEM) on your ServiceNow AI Platform instance. It provides detailed instructions on how to download the application from the ServiceNow Store, install it, and configure it to optimize your security workflows.") for more information. |
   [ ]

   {#retrieve-vr-data__table_a5v_djj_shc}
3. Select the ServiceNow Otto® icon () on the header page from anywhere in your instance.  
   The ServiceNow Otto® panel is displayed. If you don't see the ServiceNow Otto® icon in the header on the page, you must activate the ServiceNow Otto® panel. For more information, see [Activate the ServiceNow Otto panel standard chat](https://www.servicenow.com/docs/access?context=activate-now-assist-panel&version=australia&pubname=australia-intelligent-experiences&ft:locale=en-US).
4. In the ServiceNow Otto® panel, select Retrieve VR data and enter your queries in natural language to start a conversation with the AI agent.  
   Note:  
   * This AI agent helps you answer query-related questions about data for Vulnerability Response (VITs) and Application Vulnerability Response (AVITs) findings.
   * Prompts that involve any sort of data analysis of the vulnerability data that might match your questions aren't supported by this AI agent.
   * The AI agent searches for the vulnerability data that matches your question, retrieves it, and creates responses for you based on the data available.
   * You might prefer to provide as much detail as you can for your questions to help the AI agent.For example, as a remediation owner, if you ask the agent a general question such as, Retrieve all the vulnerable items with scores 5 or greater, the AI agent's response might be, No vulnerable items with scores 5 or greater were found. You may want to rephrase your question or adjust your criteria.

     On findings records, there are multiple fields that might be populated by numeric values: Risk rating, Risk score, Common Vulnerability Scoring
     System (CVSS), and Exploit Prediction Scoring System (EPSS). Given the request for this example, the AI agent won't know which field you want unless you specify the field or provide more details. You can
     help the AI agent by being specific and rephrasing your question to something like, Show me all the open VITs with Risk rating 1 - Critical.
   * As long as you don't close the conversation, the AI agent uses the context of the conversation for its next response. Select the plus icon (![Icon that indicates you can start a new chat]()) to start a new chat.
   * Be sure to check the answers for accuracy.
   {#retrieve-vr-data__ul_zp4_dfh_5hc}
5. Enter follow up questions as needed.  
   See [Sample queries for the Retrieve Vulnerability Response data agentic workflow](https://servicenow-prod.fluidtopics.net/GctV2KIVEGsH3WRyre59~w "The following sample prompts might help you become familiar with the Retrieve Vulnerability Response data agentic workflow.") for a list of sample questions to help you get started.

