---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Submit to CSF X Sandbox

# Submit to CSF X Sandbox {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Submit to CSF X Sandbox is an example of an activity definition process.

## Basic {#submit-to-csf-x-sandbox__section_dhd_jjq_bvb}

The basic details captures the name (label), application, description, Table, and
from which all applications it is accessible from.

Add the Automation plan, Activity experience and submit. Once submitted, edit the
document to add more details against each tab.

## Automation Plan {#submit-to-csf-x-sandbox__section_sx5_hfq_bvb}

The Automation Plan associates the backend action/subflow built using the flow designer. This example uses the Submit to Sandbox - ESCM Activity sub-flow.

This sub-flow enables submitting the malicious observables to sandbox. It has all the
input fields and output fields defined.

Security incident is the input field.

## Activity Experience {#submit-to-csf-x-sandbox__section_d1l_kfq_bvb}

In this example, Record type is selected.

## Associated Record {#submit-to-csf-x-sandbox__section_z1h_fgq_bvb}

Associated record is to store the associated data pertaining to the current activity. This would capture the run time data, as well the status of the experience.

* Associated table: Flow Data
* Associated Record: VL
* Experience status table: Flow Data
* Experience Status record: VL
{#submit-to-csf-x-sandbox__ul_hnn_hgq_bvb}

## Details {#submit-to-csf-x-sandbox__section_uyw_yhq_bvb}

* Tag Line: Send Email
* Icon: Envelope outline
* Title: ActivityActivity InstanceLabel. Here we have selected the activity instance's label. This dot walking will replace the label value as the title dynamically at run time.
* Description: VL (Sub-flow output is mapped)
* Pending State Title: blank
* Pending State Description: blank
* Record Fields
* Footer
{#submit-to-csf-x-sandbox__ul_gb5_13q_bvb}

## Form {#submit-to-csf-x-sandbox__section_amt_23q_bvb}

* Form View: blank
* Form Fields: blank
{#submit-to-csf-x-sandbox__ul_qgl_43q_bvb}

## Attachments {#submit-to-csf-x-sandbox__section_e42_t3q_bvb}

In this example:

* Attachment Source - None
* Attachment Read only - Unchecked

{#submit-to-csf-x-sandbox__ul_hjq_53q_bvb}

1. Attachment Source - This is a drop down. What attachments to show on the card: those attached to the Parent Record, the Associated Record, or none.
2. Attachment Read only - This is a True / False. Prevent the user from renaming or deleting the existing attachments.
{#submit-to-csf-x-sandbox__ol_qt5_w3q_bvb}

## Features {#submit-to-csf-x-sandbox__section_v4f_1jq_bvb}

In this example,

* Show SLA - Unchecked
* Show Checklist - Unchecked
* Is Automated - Unchecked
{#submit-to-csf-x-sandbox__ul_vbg_2jq_bvb}

## Playbook Actions in Activity Definition {#submit-to-csf-x-sandbox__section_evh_jjq_bvb}

This section has the actions that will be rendered on the activity card.

This example has Skip, View Sandbox Results, Submit to Sandbox, and Restart
actions.

To add a new action to the activity card, you need to create a new record in the
Playbook Actions related list present at the bottom of the page.

## Playbook override {#submit-to-csf-x-sandbox__section_qf1_klq_bvb}

No Playbook overrides for this example.

*[\>]: and then


