---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Activate a Security Incident Response flow

# Activate a Security Incident Response
flow {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Security administrators and flow designers can use the Security Incident Response flows to
automate the process of resolving security incidents in the organization.

## Before you begin

Role required: sn_si.admin, action_designer, and flow_designer

## About this task

The flows provided with the base system are in an inactive state. Activate these
flows before you use them.

## Procedure

1. [Download and
   install](https://servicenow-prod.fluidtopics.net/qGeljAXHdNqRLZ7BfdM03w "Downloading an application from the ServiceNow Store for the first time involves a number of easy steps. Some of the steps are performed on the ServiceNow Store and some in your instance.") the Security Operations Spoke application.  
   This Spoke application provides security operations actions that you can use while defining Security Incident Response flows.
2. Navigate to Flow DesignerDesigner and search for the Security Operations Spoke application to view the Security Incident related flows.  
   Notice that the flows have a published status and are inactive.
3. For example, if you want to activate the Automated Malware Playbook flow, select the Security Incident - Automated Phishing Playbook - Template V1 link to view the flow.  
   Note:  
   You cannot edit the flows provided with the base system as they are read-only flows. You can use these flows as they are or make a copy and modify them as required.
4. Select Activate to activate the flow.

## Result

The Automated Phishing Playbook flow is active and ready to use.

*[\>]: and then


