---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# View flow action designer

# View automated phishing response playbook flow action designer {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

You can drill down to the Action Designer to view detailed information about the actions
being performed for a specific step in the automated phishing response playbook flow.

This page describes the Action Designer page for the Get Observables from Task step. Select a task in the Action Outline panel to view the details.

## Action Input {#action-phishing-playbook__section_y4p_m42_1hb}

This section shows details on how the action was created including the incident id, the type
of observable (hash or IP) and observable finding (malicious emails only).

## Get M2M Records {#action-phishing-playbook__section_m4q_542_1hb}

This section shows the conditions that have been defined to search for observables in a
specified table.

## Get Observables {#action-phishing-playbook__section_qzf_1p2_1hb}

This section shows the script used to retrieve observables based on the specified filter
conditions. Finally, the observables meeting this criteria and the count is displayed.

Note:  
All actions defined in this flow are reusable and can be modified according to your requirements.

