---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Use capabilities in SIR Workspace

# Use capabilities in SIR Workspace {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Use the capabilities created using ServiceNow Otto for Security Incident Response (SIR) integration Toolkit in the SIR Workspace.

## Before you begin

Role required: sn_si_int_kit.integration_creator or sn_si.analyst

## Procedure

1. Navigate to WorkspacesSecurity Incident Response Workspace.
2. From the list view, select any security incident record.
3. Select the Investigation tab.
4. Select Associated Observable or Configuration Items.  
   The capabilities applicable to observables are available under the Associated Observable section. The capabilities applicable to configuration items are available under the Configuration Items section.
5. Select the observables on which you want to execute the capabilities.
6. Select the Capability button.  
   A pop-up appears with the list of applications.
7. Select the application to execute the capability.  
   The run() method is called from the SIR Workspace.

*[\>]: and then


