---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Automated Sharing of Outbound Intelligence Records

# Automated Sharing of Outbound Intelligence Records {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Automated Outbound Intelligence Sharing enables the seamless and automatic distribution of intelligence records to external systems.

## Before you begin

Role required:

* System Administrator (view, create or edit)
* sn_sec_tisc.admin (view)
{#tisc-automated-outbound-intel-share__ul_akc_bth_qfc}

## About this task

The automated flow action creates an outbound intelligence sharing record with the specified records and processes them accordingly.

Creating an outbound intelligence share record via automated process:

## Procedure

1. Navigate to AllThreat Intelligence Security CenterAdministration.
2. Select Automated Flows.
3. Select Automated sharing of high-risk IOC's with trusted partners action link to view the respective rule details in the flow designer.
4. View the flow designer action for the following triggers:  

       Daily at 12.00.00
       Run every day once

5. Go to Actions

   | Action | Description |
   | Select the Sharing Template | Templates with a usage mode of both On-Demand and Automated Sharing, and Automated Sharing can be selected for Automated Sharing. |
   | List of Observables | Select the type of observables record to add to an outbound intelligence record. |
   | List of Indicators | Select the type of indicators to add to an outbound intelligence record. |
   | List of Objects | Select the type of objects to add to an outbound intelligence record. |
   | Include Related Records | Add the related records of the selected observables, including indicators and objects. |
   | Requires approval | Select the check box that requires approval for the outbound intelligence record. [Defining Approval Rule for Outbound Intel](https://servicenow-prod.fluidtopics.net/tBYkoIRyd~7SM0oHgw4MMw "Define approval rules to control whether certain users require approval before sharing the shared intelligence."). |
   | Users assigned to approve requests | Select the users responsible for reviewing and approving outbound intelligence sharing record. For more information, see [Defining Approval Rule for Outbound Intel](https://servicenow-prod.fluidtopics.net/tBYkoIRyd~7SM0oHgw4MMw "Define approval rules to control whether certain users require approval before sharing the shared intelligence."). |
   | Groups assigned to approve requests | Select the groups responsible for reviewing and approving outbound intelligence sharing record. [Defining Approval Rule for Outbound Intel](https://servicenow-prod.fluidtopics.net/tBYkoIRyd~7SM0oHgw4MMw "Define approval rules to control whether certain users require approval before sharing the shared intelligence."). |
   |-|-|

   {#tisc-automated-outbound-intel-share__choicetable_dkc_bth_qfc}
6. Select Done.
{#tisc-automated-outbound-intel-share__steps_ckc_bth_qfc}

## What to do next

Activate the flow. For more information on automated flows, see [Automated sharing of high-risk IOC's with trusted partners](https://servicenow-prod.fluidtopics.net/M5XZUkj~h_Ndyj4pfQGfPQ "Learn how to automate sharing of high-risk IOC's with trusted partners.").
**Related tasks**   

* [Configuring Outbound Intel Sharing Controls](https://servicenow-prod.fluidtopics.net/1hZHuAm0zEGADdPfUVXaIg "Use this section to configure outbound sharing controls, which determine the entities enabled for intelligence sharing from TISC to external systems.")
* [Sharing of Outbound Intelligence Records from GUI](https://servicenow-prod.fluidtopics.net/b~DwM~dlSXMJ5pYPtajp_g "This section outlines the functionality that enables users to share intelligence records directly from the Threat Intelligence (TI) Library within the TISC application.")

*[\>]: and then


