---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Security Incident Playbook

# Security Incident Playbook {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Invoke the security incident playbook flow automatically or manually.

A Playbook is visible only if at least one playbook is associated with a security incident. The playbook component works only for the Process Automation Designer (PAD) built processes and not for the flow designer-built flows. For
the existing flow designer enabled flows, it will continue to work, and the activities will be continuing to be rendered as response tasks.  
There are two ways of associating playbook with the security incident:

* Automatically invoke playbook
* Manually add playbook
{#security-incident-playbook__ul_wjb_qlg_y5b}

## Invoke playbook automatically {#security-incident-playbook__section_m1z_gmg_y5b}

For a Playbook to be invoked automatically, a process needs to be defined using
Process Automation Designer (PAD), and when the trigger condition is met
then automatically the playbook tab is rendered with the playbook activities being
displayed.

## Add playbook manually {#security-incident-playbook__section_uh3_lmg_y5b}

For a Playbook to be invoked manually, navigate to the Form UI action drop down and select Add Playbook. For more information see, [Add Playbook](https://servicenow-prod.fluidtopics.net/Or37s267AkF~R9MUgzRYiQ#manually_invoke_playbook "Use this section to add playbook manually.")  
Note:  
If there is already a playbook available then the new playbooks added will run in parallel to the existing playbooks.
* Within the playbook, the analyst can filter the playbook cards by status.
* The analyst can cancel a playbook by selecting it from the ellipse icon.
* Within each activity, the analyst will be able to perform the actions defined within the activity cards such as Skip, Mark as complete, Cancel, or Orchestration actions such as Submit to sandbox, Search Emails and so on.
* Each of these actions are defined within the activity definition, and the complete card visible is customizable at the time of building the activity definition itself.

{#security-incident-playbook__ul_zvh_tmg_y5b}  
Note:  
All the future activity definitions and the next steps to be performed are displayed with a lock icon and are in read-only mode to the user. The playbook display mode is controlled by a configuration as explained below.

1. Navigate to AllPlaybook Experiences.
2. In the Playbook Experiences page, select an SIR Playbook Experience.Figure 1. Playbook Experience  
   The Playbook Experience SIR Playbook Experience page is displayed.Figure 2. Playbook Experience Record
3. Select the Configuration record.
4. In the Configuration tab, select the SIR Playbook Experience Configuration.Figure 3. Playbook Configuration
5. Navigate to the Pending Item Visibility field's drop down list, select the desired option and save the record. Choose from the following options:
   * Hide pending activities: Select this option to hide the pending activities that you would like to see on the playbook section of the workspace.Figure 4. User Reported Phishing Example
   * Show pending stages and activities: Select this option to show pending stages and activities that you would to like to see on the playbook section of the workspace.Figure 5. Show pending stages and activities
   * Hide pending activities and stages: Select this option to hide pending activities and stages,that you would like to see on the playbook section of the workspace.Figure 6. Hide pending activities and stages
   {#security-incident-playbook__ul_e4m_y54_y5b}
6. On the Playbook section, use the filter option to filter the activities by Playbook card status (activity definition).Figure 7. Playbook card status
{#security-incident-playbook__ol_i11_5q4_y5b}
**Related concepts**   

* [Working with Security Incident Records](https://servicenow-prod.fluidtopics.net/TFUzgIYau3h8zmc3_FkDEA "The Security Incident Record consists of the following.")
* [Prerequisites for the Playbooks](https://servicenow-prod.fluidtopics.net/POSOIYPbrf55BhB5oZj_Tw "You need the following roles and plugins to build the Playbooks.")
* [Rebuilding existing playbooks in Workflow Studio](https://servicenow-prod.fluidtopics.net/Gxrs6Kmn6bmfB680yQYz3A "You can’t convert existing flows directly into playbooks in Workflow Studio. Each flow designer step that creates a response task to guide the analyst must be broken down into separate actions or subflows.")
* [Activity Definitions](https://servicenow-prod.fluidtopics.net/IMGNwpKoJREVXgsdWM6BEg "The ServiceNow AI Platform provides a few activity definitions within the base system. In addition, for the playbooks that SIR Workspace base system, there are a few activity definitions defined in the base system under Enterprise Security Case Management PAD Commons application.")
* [Sample Playbooks for SIR Workspace](https://servicenow-prod.fluidtopics.net/LJZS56n6O87_ZQicnhxpTw "You can create or configure playbooks for SIR Workspace quickly and easily without writing complicated code. You can use these playbooks to resolve security threats in a step-by-step manner. You can invoke the security incident playbook flow automatically or manually.")
* [Working with MSI Records](https://servicenow-prod.fluidtopics.net/EzBRz3gfWLnRuxl~O9DXuA "Using the Security Incident Response workspace, you can propose, promote, or link security incidents as major security incidents when the incidents are identified as critical threat to the organization.")
* [Working with Form UI actions](https://servicenow-prod.fluidtopics.net/BiVNOVqIU5VY5t0VA35xHg "Following are the UI actions that are displayed on the security incident form.")  
**Related tasks**   

* [Security Incident Closure workflow](https://servicenow-prod.fluidtopics.net/eUcWbP2pHl3bZk_3cBQ5EA "Close the security incident by updating the incident state.")
* [Handle security incidents using Advanced Work Assignment](https://servicenow-prod.fluidtopics.net/T3UyVFGugN7M9V4Ol1CCLg "Handle security incidents assigned to you in SIR Workspace using Advanced Work Assignment.")

## Add Playbook {#ariaid-title2}

Use this section to add playbook manually.

### Before you begin

Role required: sn_si.analyst

### Procedure

1. Navigate to AllSecurity IncidentSecurity Analyst Workspace.
2. Open an incident record.
3. Select Add Playbook.  
   The Add Playbook dialogue box is displayed.
4. Select the playbook template.
5. Select Add Playbook.  
   A confirmation message dialogue box is displayed for you to confirm.
6. Select Add Anyway.  
7. The Playbook gets added next to the Details tab.  
8. Select the Playbook tab.  
9. Perform the series of activities as listed to move to the next level.  
   Note:  
   If a Security incident is associated with a playbook, until the associated playbook gets closed or cancelled the user cannot again associate the same playbook to the same security incident.
{#manually_invoke_playbook__steps_sgk_zjj_v5b}

*[\>]: and then


