---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Investigation Canvas

# SIR Workspace Investigation Canvas {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Security Incident Response Workspace allows the Security Analysts to view the key
information associated with the security incident during the incident remediation process. The key
information also includes the related lists such as Observables, Threat Lookup Results, Sighting
Search, Observable Enrichment, and so on.

In the classic UI, most of the orchestration actions associated with the out of the box
integrations are available against the related lists. For example, Run Threat Lookup, Run
Observable Enrichment, etc. are present against Associated Observables related list. Similarly
Get Host Details, Get Network Statistics and so on, are available against Configuration Items
related list.

When a Security Analyst performs these actions, results are populated in a different related
list. For example, when a user performs Run Threat Lookup, the results are available in Threat
Lookup Results table. Sometimes, results are available in multiple different tables. During this
process, the Security Analysts has a disjointed and unorganized user experience in co-relating
the information from multiple places.

In the re-imagined new SIR Workspace, the
Investigation canvas (tab) provides all the necessary information grouped
logically in one place for the Analyst to perform the investigation.
* **[Explore Investigation Canvas](https://servicenow-prod.fluidtopics.net/3Mx~XCZXw7LsX0QFKRP_eg)**   
  The primary objective of the investigation canvas is to present the necessary security incident data in one common place.

**Related concepts**   

* [Unified experience framework for integrations powered by Capability Framework](https://servicenow-prod.fluidtopics.net/4v600tZ3F9_LkTOKcHvD4Q "In the classic UI, the experience is disjointed when performing orchestration activities such as running threat look, performing sighting search, and so on. Each capability has its own experience while executing it. In the new workspace, there is unified experience across all capabilities.")

