---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Security Operations Integration - CI Enrichment flow

# Security Operations Integration - CI Enrichment flow {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The Security Operations Integration - CI Enrichment flow allows you to enrich data in configuration items (CI) associated with a security incident.

## Before you begin

Role required: sn_si.analyst

## About this task

This flow is triggered from Security Incident Response in two ways.

* by selecting one or more CIs from the Configuration Items tab (under the Affected Items related link) and selecting Run CI enrichment from the Actions on selected rows choice list.
* by opening a CI record and clicking the Run CI enrichment related link.

{#secops-integ-enrich-ci-wf__ul_oqw_mvx_v1b}  
Either method then allows you to specify which implementations to be used to enrich the selected CIs. The associated implementation flows are executed to perform the enrichment.  
Note:  
The base system does not include an implementation flow for this capability. To enrich CIs, you must create your own implementation [flow](https://www.servicenow.com/docs/access?context=c_WorkflowOverview&version=australia&pubname=australia-build-workflows&ft:locale=en-US).
Figure 1. CI Enrichment

Actions specific to this flow are described here. For more information on other actions, see [Common Security Operations integration flows and orchestration activities](https://servicenow-prod.fluidtopics.net/VeHrUh9NzKmFfa~3wxWcqQ "Many of the flows associated with third-party integrations include the same activities. For example, activities for beginning and completing processing.").  
The flow process actions include:

* [Legacy: Execution Tracking - Begin Flow Action](https://servicenow-prod.fluidtopics.net/f7TxzucZqzu26uA35DrhKQ "The Execution Tracking - Begin flow action starts the auditing process for a Security Operations Integration flow that operates on observables.")
* [Security Operations Integration - CI Enrichment flow](https://servicenow-prod.fluidtopics.net/wOq9Y7LynIzZYm0PMiVemw "The Security Operations Integration - CI Enrichment flow allows you to enrich data in configuration items (CI) associated with a security incident.")
* [Legacy: Capability Execution Tracking- No Impls action](https://servicenow-prod.fluidtopics.net/8gyoOnrdwEvCZgYXRRg4eg "The Capability Execution Tracking - No Impls flow action creates an error record when no integration capability implementation is found.")
* [Get Supported Security Capabilities action](https://servicenow-prod.fluidtopics.net/iiKXFyzD8b7PaGdn84u7ag "The Get Supported Capabilities flow action retrieves the name and number of integrations that are active and support the requested capability.")
{#secops-integ-enrich-ci-wf__ul_bc3_n4y_hcc}

