---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Prerequisites for the Playbooks

# Prerequisites for the Playbooks {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

You need the following roles and plugins to build the Playbooks.
Role required: admin.

* Enable the Process Automation Designer (PAD) \[com.glide.pad.license\] plugin.
* Enable the following plugins for a playbook experience:
  * com.playbook_experience
  * now_playbook_exp
  * com.glide.playbook_experience.config
  {#getting-started-with-processes__ul_ylm_sv4_z5b}
* Enable Security Operations spoke to access flows \[com.snc.secops.spoke\].
* Enterprise Security Case Management PAD Commons.

{#getting-started-with-processes__ul_x3b_bv4_z5b}

Make sure that you have read the platform documentation on [Exploring Playbook](https://www.servicenow.com/docs/access?context=process-automation-designer&version=australia&pubname=australia-build-workflows&ft:locale=en-US) and [Process Automation Designer](https://www.servicenow.com/docs/access?context=process-automation-designer&version=australia&pubname=australia-build-workflows&ft:locale=en-US) before you start with this guide.
**Related concepts**   

* [Working with Security Incident Records](https://servicenow-prod.fluidtopics.net/TFUzgIYau3h8zmc3_FkDEA "The Security Incident Record consists of the following.")
* [Security Incident Playbook](https://servicenow-prod.fluidtopics.net/Or37s267AkF~R9MUgzRYiQ#security-incident-playbook "Invoke the security incident playbook flow automatically or manually.")
* [Rebuilding existing playbooks in Workflow Studio](https://servicenow-prod.fluidtopics.net/Gxrs6Kmn6bmfB680yQYz3A "You can’t convert existing flows directly into playbooks in Workflow Studio. Each flow designer step that creates a response task to guide the analyst must be broken down into separate actions or subflows.")
* [Activity Definitions](https://servicenow-prod.fluidtopics.net/IMGNwpKoJREVXgsdWM6BEg "The ServiceNow AI Platform provides a few activity definitions within the base system. In addition, for the playbooks that SIR Workspace base system, there are a few activity definitions defined in the base system under Enterprise Security Case Management PAD Commons application.")
* [Sample Playbooks for SIR Workspace](https://servicenow-prod.fluidtopics.net/LJZS56n6O87_ZQicnhxpTw "You can create or configure playbooks for SIR Workspace quickly and easily without writing complicated code. You can use these playbooks to resolve security threats in a step-by-step manner. You can invoke the security incident playbook flow automatically or manually.")
* [Working with MSI Records](https://servicenow-prod.fluidtopics.net/EzBRz3gfWLnRuxl~O9DXuA "Using the Security Incident Response workspace, you can propose, promote, or link security incidents as major security incidents when the incidents are identified as critical threat to the organization.")
* [Working with Form UI actions](https://servicenow-prod.fluidtopics.net/BiVNOVqIU5VY5t0VA35xHg "Following are the UI actions that are displayed on the security incident form.")  
**Related tasks**   

* [Security Incident Closure workflow](https://servicenow-prod.fluidtopics.net/eUcWbP2pHl3bZk_3cBQ5EA "Close the security incident by updating the incident state.")
* [Handle security incidents using Advanced Work Assignment](https://servicenow-prod.fluidtopics.net/T3UyVFGugN7M9V4Ol1CCLg "Handle security incidents assigned to you in SIR Workspace using Advanced Work Assignment.")

