---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# SIR Workspace interface overview

# SIR Workspace interface overview {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The SIR Workspace Overview page consists of the Security Incidents
and Response Tasks details that are under security analysts and their team.
There are various widgets present under each filter grouped by priority, category, state, and SLA, which are in the security analysts' queues and security analysts team's queue.

When filters are applied on the
widgets, the bottom half of the overview page is populated with the corresponding security incidents or response tasks presented as cards or list items. The analyst can toggle between the card view or the list view as
desired.  
For example, on the Priority widget if you want to select all the critical incidents or response tasks then select the Critical segment (example screen shot below) of the widget and those incidents or response task which are critical gets displayed in the list or card view.Figure 1. Overview section

You can assign or reassign the security incidents or response tasks directly from this view by selecting the ellipse icon and select the Assign (option in card view) or directly the
Assign button (option in list view) accordingly to assign an incident.  
Figure 2. Card view and Reassign example Figure 3. Assign incident  
Here is an example of the list view. The user can assign incidents from the list view as well.Figure 4. Assign incident  
Add or modify the assignee details such as Assignment group and Assigned to, add worknotes, if required.  
Note:  
You can assign one or more security incidents or response tasks to the assignment groups. The selected number is displayed on the Assign button.

The user can delete security incidents from this view. Select the Delete button to delete the security incident,
the record will be deleted from the list view.

The user can export the list content as well. Select the Export button to export the list in the desired format.
**Related concepts**   

* [SIR Workspace features](https://servicenow-prod.fluidtopics.net/8RpOO~NHgmEKOvLelppoQA "The Security Incident Response Workspace consists of the following key features.")
* [Upcoming section](https://servicenow-prod.fluidtopics.net/PYIvFKoYWjA3UhvVIOAXZA "This section displays the upcoming tasks such as the security incidents and response tasks that are due as on the same day and next day.")
* [Quick links section](https://servicenow-prod.fluidtopics.net/94_97N0fwDf7ASqbiWHc2A "Quick links work like bookmark links. You can add external URLs and quickly access them from within the workspace.")
* [Shift Handover Records section](https://servicenow-prod.fluidtopics.net/UXY0oW6ISmUwjCVrPnl48g "The section displays the list of Shift Handover records in the Security Incident Response Workspace.")
* [List view in SIR Workspace](https://servicenow-prod.fluidtopics.net/bStXEweV_IdnZ_UD5B0G9g "The list view consists of the security incidents, response tasks, phishing emails, and assessments.")  
**Related reference**   

* [SIR Workspace plugins](https://servicenow-prod.fluidtopics.net/DT9niT7CHKbBFZbGrlMamw "The following are the required applications to work with Security Incident Response Workspace (sn_si_aw) plugin.")

