---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Enable playbooks for analyst selection

# Enable playbooks for analyst selection {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Add new playbooks to the playbook selection list.

You can select an appropriate playbook to investigate security incidents in the Security Analyst Workspace ([Manage security threats using the Security Analyst Workspace](https://servicenow-prod.fluidtopics.net/ivFWY8MwE4YqB1jSs6JKFg "Security Incident Response includes a new user interface called the Security Analyst Workspace that features powerful tools for assisting in analysis, including the playbook, peek view, and tabs for working on multiple security incidents.")). The playbook selection option supports only the playbooks which are designed using
Flow Designer.

After you have created a playbook using Flow Designer, follow these steps to include it in the
Selected Playbook choice list:  
1. Navigate to sys_hub_flow table.
2. Search for the new playbook you have created using Flow Designer.
3. Add the sir_playbook tag to the playbooks that you want to include in the Selected Playbook choice list.
{#sir-new-ui-add-playbook__ol_kft_r2p_ylb}  
Note:  
If you have old playbooks that have not been migrated from workflows to Flow Designer, they will not appear in the list. But, if a playbook created using workflows is assigned to a security incident either by a trigger condition or by manual selection (using Run Orchestration option in the classic environment), this playbook is launched when you open the security incident in the Security Analyst Workspace.

