---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Working with Form UI actions

# Working with Form UI actions {#ariaid-title1}

* Release version: Australia
* 
* Updated August 11, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 minutes to read

Following are the UI actions that are displayed on the security incident
form.  
To navigate to the form UI actions:

1. Go to WorkspacesSecurity Incident Response Workspace.
2. Select any security incident from the list view.
3. All the UI actions are present in the top-right corner of the security incident form.{#enable_workspace_form_ui_actions__table_jph_zrr_blb__entry__2}

   | Field Name | Description |
   |-|-|
   | Discuss | Create or start a sidebar discussion for the security incident. |
   | Save | Save or update the Security Incident Response record after making any changes. |
   | Create Response Task | Create a response task for the security incident. |
   | Compose Emails | Compose emails for the security incident. |
   | Add Playbook | Add the playbook manually for the security incident. |
   | Create Incident | Create an incident within the security incident. |
   | Create Customer Service Case | Create a customer service case for the security incident that will be tracked by the Customer Service Management (CSM) team. Note: This option is available only when Customer Service Management (CSM) is installed. |
   | Open Associated Wokflow(s) | Open any workflow(s) context associated with the security incident. This option would be visible only if there are any workflows. |
   | Create Change Request | Create a change request within the security incident. |
   | Create Problem | Create a problem within the security incident. |
   | Create Outage | Create an outage within the security incident. |
   | Calculate Severity | Calculate the severity of a security incident using predefined calculators. The severity is calculated based on the predefined rules in the calculators. The severity of an incident is based on the Risk score, Business Impact, and Priority. |
   | Run EDR Profile | Select and run the EDR Profile for the required integration. Note: This option is available only when any integrations are installed. |
   | Link to Major Security Incident | Link a security incident to a major security incident. |
   | Report risk event | Report this security incident as a risk event to the Risk Management team. The Risk Management team analyzes the event and ensure that such events and the associated losses don't reoccur. Note: This option is available only when Risk Management is installed. |
   | Unlink from Major Security Incident | Unlink from major security incident. |
   | Propose as Major Security Incident | Propose a security incident as a major security incident. |
   | Promote to Major Security Incident | Promote a security incident as a major security incident. |
   | Run Additional Action(s) on Endpoint | Run additional actions on the endpoint. Note: This option is available only when Endpoint integrations are installed. For example: FireEye HX |
   | Create a new Event in MISP | Create and modify events in MISP automatically or manually. Note: This option is available only when MISP integration is installed. |
   | Associate MITRE ATT\&K Technique | Associate MITRE ATT\&K Techniques to the security incident. Note: This option is available when MITRE ATT\&K is installed. |
   | Show MITRE ATT\&K info | Shows the MITRE ATT\&K information associated with the security incident. Note: This option is available when MITRE ATT\&K is installed. |
   | Add to Security Case | Add the security incident to an existing or new security case. Note: This option is available when Threat Intel is installed. |
   | Switch to Classic UI | Enable the analyst to switch between classic and new UI so that the analyst can also work on the existing functionalities that aren't available on the new workspace yet. |
   | Cancel | Cancel a security incident. After you select Cancel all the related records such as response tasks, child security incidents will also get canceled. |
   | Delete | Delete a security incident record. |
   [Table 1. Workspace Form UI actions]

   {#enable_workspace_form_ui_actions__table_jph_zrr_blb}
4. Select a security incident number to view the security incident record. You can see the UI actions on the top of the page.

{#enable_workspace_form_ui_actions__ol_jqg_crr_blb}
**Related concepts**   

* [Working with Security Incident Records](https://servicenow-prod.fluidtopics.net/TFUzgIYau3h8zmc3_FkDEA "The Security Incident Record consists of the following.")
* [Security Incident Playbook](https://servicenow-prod.fluidtopics.net/Or37s267AkF~R9MUgzRYiQ#security-incident-playbook "Invoke the security incident playbook flow automatically or manually.")
* [Prerequisites for the Playbooks](https://servicenow-prod.fluidtopics.net/POSOIYPbrf55BhB5oZj_Tw "You need the following roles and plugins to build the Playbooks.")
* [Rebuilding existing playbooks in Workflow Studio](https://servicenow-prod.fluidtopics.net/Gxrs6Kmn6bmfB680yQYz3A "You can’t convert existing flows directly into playbooks in Workflow Studio. Each flow designer step that creates a response task to guide the analyst must be broken down into separate actions or subflows.")
* [Activity Definitions](https://servicenow-prod.fluidtopics.net/IMGNwpKoJREVXgsdWM6BEg "The ServiceNow AI Platform provides a few activity definitions within the base system. In addition, for the playbooks that SIR Workspace base system, there are a few activity definitions defined in the base system under Enterprise Security Case Management PAD Commons application.")
* [Sample Playbooks for SIR Workspace](https://servicenow-prod.fluidtopics.net/LJZS56n6O87_ZQicnhxpTw "You can create or configure playbooks for SIR Workspace quickly and easily without writing complicated code. You can use these playbooks to resolve security threats in a step-by-step manner. You can invoke the security incident playbook flow automatically or manually.")
* [Working with MSI Records](https://servicenow-prod.fluidtopics.net/EzBRz3gfWLnRuxl~O9DXuA "Using the Security Incident Response workspace, you can propose, promote, or link security incidents as major security incidents when the incidents are identified as critical threat to the organization.")  
**Related tasks**   

* [Security Incident Closure workflow](https://servicenow-prod.fluidtopics.net/eUcWbP2pHl3bZk_3cBQ5EA "Close the security incident by updating the incident state.")
* [Handle security incidents using Advanced Work Assignment](https://servicenow-prod.fluidtopics.net/T3UyVFGugN7M9V4Ol1CCLg "Handle security incidents assigned to you in SIR Workspace using Advanced Work Assignment.")

*[\>]: and then


