---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Unlink records from Major Security Incident

# Unlink records from Major Security Incident {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Using the Major Security Incident Management workspace, unlink the major security
incident records from the Linked Records section.

## Before you begin

Role required: sn_msi.workspace_manager and sn_msi.workspace_responder  
Note:  
You can only unlink a single record at a time. After you unlink a record, the related rolled up information will be removed from the Incident Impact and Threat Intelligence sections on the workspace and the action can't be undone.
For more information on roll up records, see [Rollup Framework for MSIM](https://servicenow-prod.fluidtopics.net/~eETkXxZI1OwygBe2hZ0Vg "Extends the capability of linking the source records from Major Security Incident Management workspace.").

## Procedure

1. Navigate to Major Security Incident ResponseMSIM Workspace.
2. Navigate to Lists view, which is displayed in the left pane of the workspace.
3. Select Accepted to select the promoted major security incident records.
4. Select the Linked Records tab.  
   This section displays the linked records and its related records, which are linked to the Major Security Incident.
5. Select the desired table view such as Security Incidents, Remediation Tasks (vulnerable items), or Security Case.
6. Select the record to unlink from the list view of records.
7. Select Unlink Record.  
   Figure 1. Unlink Record
8. A warning message is displayed asking if you want to unlink the selected record from MSI.  
   Figure 2. Unlink Record Warning Message
9. Select Unlink Record.  
   The record is unlinked and once unlinked, the changes can't be reverted. The list view of Linked Records will be refreshed after unlinking.
**Related concepts**   

* [Propose, promote, and link incident records](https://servicenow-prod.fluidtopics.net/sk9rqHFZOINPE0X~1U5vMg "Propose or promote security incidents as major security incidents when incidents are identified as critical threat to the organization.")
* [View Major Security Incident impact metrics](https://servicenow-prod.fluidtopics.net/3KBNBqRoz_BkHzUxpjZhkg "Provides up-to-date summary reporting of the impact and progress of major security incidents, which is an important aspect of managing a major security incident using the new workspace.")
* [View Major Security Incident trend charts](https://servicenow-prod.fluidtopics.net/i9L9Hku8t6K3KLufujwM_Q "View the major security incident impact progress metrics visualized as bar graphs and charts.")
* [Update Major Security Incident details](https://servicenow-prod.fluidtopics.net/b07ElfZGURoZjC6mrNQUPg "View and update specific details related to the major security incident such as Incident Record Details, Active Team participants, and the corresponding activity log.")
* [Manage tasks in a Major Security Incident](https://servicenow-prod.fluidtopics.net/Yru0dCGME5pKnCMaKxhciw "The Task tab enables you to track and manage all the tasks associated with a major security incident from the MSIM workspace. You can view the various tasks using the default Visual Task Board (Kanban view) or the List view.")
* [Track collaboration activity via MSIM workspace](https://servicenow-prod.fluidtopics.net/oN75Hkl13nFA0yi30ej7pw#collab-tab "Track chat and file activities related to resolving major security incidents through the MSIM Workspace.")
* [Configure Linked Records in Major Security Incident Management](https://servicenow-prod.fluidtopics.net/UQvZiFC9DqKWKX5KKQIwPw "Use Linked Records Configuration to store the information of task tables that can be used to link/promote/propose to Major Security Incident.")
* [Configure Rollup Records in Major Security Incident Management](https://servicenow-prod.fluidtopics.net/9eu8e6Eam7vQOe4fzwglrQ "Configure Roll up records in Major Security Incident Management to control the information, which will be rolled up when the source record is linked/proposed/promoted as Major Security Incidents.")  
**Related tasks**   

* [Using MSI List view in the MSIM workspace](https://servicenow-prod.fluidtopics.net/KCnBshkJxFxNQC_44tHI8g "With the list view in the MSIM workspace, you can view proposed, promoted, and rejected major security incidents.")
* [Link additional records to Major Security Incident](https://servicenow-prod.fluidtopics.net/_LFdjo1aOyMiYBIDPKWA7Q "In the workspace, use the linking records functionality to link any related Security Incident records and its child security incidents, Remediation Tasks from Vulnerability Response, and Security Cases from Threat Intelligence to a Major Security Incident (MSI) record.")
* [Create and distribute MSIM Status Reports](https://servicenow-prod.fluidtopics.net/~mxDy9mmDysMOt7PL5mv3A "As a Major Security Incident (MSI) manager, you can create and distribute the different status reports to different stakeholders at various intervals based on the configured report template or a previous status report throughout the course of the major security incident resolution.")

*[\>]: and then


