---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Generate a Case Report using generative AI

# Generate a Case Report using generative AI {#ariaid-title1}

* Release version: Australia
* 
* Updated June 22, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Generate an AI-based, structured, threat intelligence case report from the data in a case and export it for stakeholder distribution.

## Before you begin

Important:  
Some generative AI skills, AI agents, and agentic workflows are turned on by default. For more information, see [AI agents, skills, and agentic workflows on by default](https://www.servicenow.com/docs/access?context=now-assist-skills-on-by-default&version=australia&pubname=australia-intelligent-experiences&ft:locale=en-US).  
Generative AI driven report generation is available only when the following prerequisites are met:

* Threat Intelligence Security Center-Advanced must be installed.
* TISC Report Authoring skill must be active.
* AI report styling must be configured by the Threat Intelligence administrator (sn_sec_tisc.admin). For more information, see [Configure report styling for TISC Case reports](https://servicenow-prod.fluidtopics.net/q1M8G13sCttlo4M_cyF~eQ "Configure the appearance of AI-generated threat intelligence case reports by setting colors, fonts, and organizational details in the report styling record.").

Role required: sn_sec_tisc.analyst

## About this task

Generate an AI-based, structured, threat intelligence case report from the data in a case.

## Procedure

1. Navigate to WorkspacesThreat Intelligence Security Center.
2. Select the Threat Analyst Workbench icon.
3. In Case Management, open the case to generate the report.
4. Select the Case Reports tab.
5. Select New with AI.
6. In Report type, enter the type of report you want to generate or save for future usage.  
   The report types are saved for the current user and listed under Saved Report Types.
7. In Report description, enter a brief description in a maximum of 500 characters of how AI should generate the report.  
   Tip:  
   The fields contain default values to help you understand the Report Authoring feature.
8. **Optional:** To reuse the report later, select Save Report Type.  
   You can save up to 10 report types per user. When you reach the limit, delete a saved report type before saving a new one.

   To modify a saved report type, select Save Changes or save it as a new report type, select Save as New.

   Use the search bar under Saved Report Types to find a saved report type.
9. Select Generate report.  
   A loading indicator appears for up to five seconds.
   * If the report generates within five seconds, the window closes and the report editor opens automatically.
   * If it takes longer, the window closes and a notification appears in the list view. The report editor opens when the report is ready.
   {#na-tisc-generate-ai-reports__ul_ai_result}
10. **Optional:** Edit the AI-generated report content in the report editor.  
    * Select the ![Edit report details icon]()Edit report details icon to edit the report name and description.
    * Select the ![Expand icon]()Expand icon to insert additional content --- for example, Observables or Indicators --- into the report.
    * Type <kbd class="ph userinput">/</kbd> to use a slash command and insert dynamic content, such as a record count, a specific record or field, or a system user. For the available slash commands and supported tables, see [Working with Reports in TISC](https://servicenow-prod.fluidtopics.net/9p3J4EDtDbwGioeDsHcI4Q "The Reports module in the Threat Intelligence Library section enables you to create, manage, and publish reports that use any intelligence available in the Threat Intelligence Library.").
    * Select Save Content to save your changes and enable Publish.
    * Select Preview to generate a PDF preview of the current content.
    {#na-tisc-generate-ai-reports__ul_intel_content}
11. When your edits are complete, select Publish.  
    After publishing, download the report as a PDF or share it with stakeholders by email.
{#na-tisc-generate-ai-reports__steps_t1l_3mc_rjc}
**Related concepts**   

* [Workbench Overview](https://servicenow-prod.fluidtopics.net/v09QNspsdgUKsjcssQ44nQ "The Workbench Overview page consists of the Case Tasks and Cases that are under Threat Analysts and their team.")
* [Working with Investigation Canvas](https://servicenow-prod.fluidtopics.net/EprH7pyEqFs2LVQ4KGvJ5w "The Investigation Canvas is a key significant feature, which provides more valuable information for the Threat Intelligence (TI) analysts. It provides a structured framework by mapping one to one or one to many relationships and visualizing information related to observables, indicators of compromise (IOCs), or entities.")
* [Using playbooks](https://servicenow-prod.fluidtopics.net/S_4Mkl_RpxIBoyykp2nXbQ "Playbooks in Threat Intelligence Security Center guide analysts through structured threat investigation stages. Each stage defines the actions to complete before the case advances to the next phase of the response process.")  
**Related tasks**   

* [Creating cases using Threat Analyst Workbench](https://servicenow-prod.fluidtopics.net/Xb8x3ylFD6FijaDvKqX3WA "Cases are used to track information about a campaign or threat actor threatening your organization. After a case is created, you can add artifacts that allow you to review and analyze all related information from a single case or case task.")
* [Summarize a Case using generative AI](https://servicenow-prod.fluidtopics.net/cR_IUVt2~1oWmLQRzSERog "Use to generate a concise summary of a case, including its key findings and recommended next steps.")
* [Creating case task using Threat Analyst Workbench](https://servicenow-prod.fluidtopics.net/QIyOkhiAbQsuKQ~ncYN_TQ "Create case tasks to associate with case(s).")
* [Add artifacts to case(s) or case task(s)](https://servicenow-prod.fluidtopics.net/w7jOBRuuDQT6Qje2vs23wg "After you have created a case, you can view or add artifacts, such as security incidents, CIs, and indicators of compromise, to the case. These artifacts act as clues in solving the case.")
* [Run Enrichment Actions within a case](https://servicenow-prod.fluidtopics.net/Gh87urOsiF~BhNjGZQsVqg "Use this section to understand how enrichments actions are performed on case(s).")
* [Generate a Case Report using a template](https://servicenow-prod.fluidtopics.net/6Y9mhLC9aae1X07xvHOfBg "Use a predefined report template to generate case reports. These reports include post investigation report or an executive summary report.")
* [Create a security incident from a TISC case](https://servicenow-prod.fluidtopics.net/7EbUdWlsxwChV5xDotZntQ "Create security incidents and associate observables to the security incidents from a TISC case.")
* [Upload Secure File Attachments](https://servicenow-prod.fluidtopics.net/~1CsuAO80SPkjnX1j_LDpQ "Use this section to understand on how to upload the secure file attachments to the case(s).")

*[\>]: and then


