---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Workbench Overview

# Workbench Overview {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The Workbench Overview page consists of the Case Tasks and Cases that are under Threat Analysts and their team.

The overview lists all the open cases and their status which helps the analysts to manage their workload and prioritize their investigations.

Role required: sn_sec_tisc.analyst, sn_sec_tisc.admin

After the case is created, the analysts will then assign the case tasks to other analysts or teams for further investigation, and also collaborate with them to share information and insights.

There are various widgets present under each filter grouped by priority, status, and case type which are in the threat analysts' queues and threat analysts team's queue.

When filters are applied on the widgets, the bottom half of the overview page is populated with the corresponding cases or case tasks presented as list items. In order to remove the applied filters, click on Reset Filters to reset it to the original view.  
Using this page, the threat analysts and admins can view their work, teams work, and any unassigned work. You can navigate to dropdown list. The available options are:

* My Work: Select this option to view the work assigned to you.
* My team's work: Select this option to view your team's work assigned to all the groups that you are part of.
* Unassigned work: Select this option to view the case or case task that are unassigned. To assign the case or case task, you must go to the form view and assign the user(s) or user group(s) to the case and case task(s).
{#workbench-overview__ul_hvy_vz5_tzb}

You can also view cases and case tasks directly from the Workbench Overview that are assigned to you. By default, the case view is displayed, you can use the dropdown and select the case tasks if you want to view the case tasks by
priority and status.
**Related concepts**   

* [Working with Investigation Canvas](https://servicenow-prod.fluidtopics.net/EprH7pyEqFs2LVQ4KGvJ5w "The Investigation Canvas is a key significant feature, which provides more valuable information for the Threat Intelligence (TI) analysts. It provides a structured framework by mapping one to one or one to many relationships and visualizing information related to observables, indicators of compromise (IOCs), or entities.")
* [Using playbooks](https://servicenow-prod.fluidtopics.net/S_4Mkl_RpxIBoyykp2nXbQ "Playbooks in Threat Intelligence Security Center guide analysts through structured threat investigation stages. Each stage defines the actions to complete before the case advances to the next phase of the response process.")  
**Related tasks**   

* [Creating cases using Threat Analyst Workbench](https://servicenow-prod.fluidtopics.net/Xb8x3ylFD6FijaDvKqX3WA "Cases are used to track information about a campaign or threat actor threatening your organization. After a case is created, you can add artifacts that allow you to review and analyze all related information from a single case or case task.")
* [Summarize a Case using generative AI](https://servicenow-prod.fluidtopics.net/cR_IUVt2~1oWmLQRzSERog "Use to generate a concise summary of a case, including its key findings and recommended next steps.")
* [Creating case task using Threat Analyst Workbench](https://servicenow-prod.fluidtopics.net/QIyOkhiAbQsuKQ~ncYN_TQ "Create case tasks to associate with case(s).")
* [Add artifacts to case(s) or case task(s)](https://servicenow-prod.fluidtopics.net/w7jOBRuuDQT6Qje2vs23wg "After you have created a case, you can view or add artifacts, such as security incidents, CIs, and indicators of compromise, to the case. These artifacts act as clues in solving the case.")
* [Run Enrichment Actions within a case](https://servicenow-prod.fluidtopics.net/Gh87urOsiF~BhNjGZQsVqg "Use this section to understand how enrichments actions are performed on case(s).")
* [Generate a Case Report using generative AI](https://servicenow-prod.fluidtopics.net/1bdvh6WMLeuGwDMntyZLaA "Generate an AI-based, structured, threat intelligence case report from the data in a case and export it for stakeholder distribution.")
* [Generate a Case Report using a template](https://servicenow-prod.fluidtopics.net/6Y9mhLC9aae1X07xvHOfBg "Use a predefined report template to generate case reports. These reports include post investigation report or an executive summary report.")
* [Create a security incident from a TISC case](https://servicenow-prod.fluidtopics.net/7EbUdWlsxwChV5xDotZntQ "Create security incidents and associate observables to the security incidents from a TISC case.")
* [Upload Secure File Attachments](https://servicenow-prod.fluidtopics.net/~1CsuAO80SPkjnX1j_LDpQ "Use this section to understand on how to upload the secure file attachments to the case(s).")

