---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Linking an existing case from Investigation Canvas

# Linking an existing case from Investigation Canvas {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Use this section to link an existing case from the investigation canvas.

## Before you begin

Role required: sn_sec_tisc.analyst

## Procedure

1. Navigate to WorkspacesThreat Intelligence Security Center.
2. Select Threat Analyst Workbench icon.
3. Go to Case ManagementAll Cases.  
   This displays all the cases.
4. Select Case ManagementAll Cases
5. Open any case record from the list view.
6. Select Link Case from the Details section.  
   The Link a Case dialogue box appears.
7. Select a case ID from the list to associate the case to an investigation canvas.  

   A confirmation message is displayed confirming that the case is linked successfully.  
   Note:  
   In case if no case is available for linking to the Investigation Canvas, you can create a new case to initiate and organize your investigation context. For more information on how to create a new case, see [Creating a Case and Linking from Investigation Canvas](https://servicenow-prod.fluidtopics.net/OmHRilqOQfVUyqGxjhahZg "Use this section to create and link a case(s) from an investigation canvas.").
8. To remove a linked case, select the Unlink button.
{#tisc-link-existing-case-canvas__steps_b23_4wz_yfc}
**Related tasks**   

* [Creating an investigation canvas](https://servicenow-prod.fluidtopics.net/1HhM4WdIq0Dt81m4cclpuw "Create canvas to add observables from threat intelligence library.")

*[\>]: and then


