---
sourceDocument: Yokohama Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/governance-risk-compliance

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Creating an action task for the operational vulnerability

# Creating an action task for the operational vulnerability {#ariaid-title1}

* Release version: Yokohama
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The Operational vulnerability analysts gather additional information or an evidence on the vulnerability by creating one or more action tasks. An action task can be of an assessment or investigation type.

The Operational vulnerability analysts assign the assessment or investigation action tasks to appropriate task owners. The task owners then review the tasks, note their observations, finish the assigned work, and inform
the task owners to review their work.  
Task owners typically perform the following actions:

* [Manage an assessment-type action task](https://servicenow-prod.fluidtopics.net/2aoRu8qrJgTv0XxxKCXf1g "Create and manage an action task for the Operational vulnerability, where the type of the task is assessment. You can then assign it to an appropriate task owner.")
* [Manage an investigation-type action task](https://servicenow-prod.fluidtopics.net/LwbTiaR5eYf3oBXJOg7uMQ "Manage an investigation-type action task for the Operational vulnerability. An investigation-type action task is initiated when additional investigation is needed to resolve the vulnerability. If the approver rejects the Operational vulnerability and requests more investigation, the task owner can create an investigation-type of action task, assign it to an appropriate user, review their completed work, and then request an approval again.")
{#creating-action-tasks__ul_q3k_q2d_xcc}

## Workflow states for an action task {#creating-action-tasks__section_k22_gkv_wcc}

An action task moves through the following workflow states. {#creating-action-tasks__table_ntr_jkv_wcc__entry__2}

| States | Description |
|-|-|
| Draft | The action task is in the draft stage. |
| Assigned | The action task has been assigned to an appropriate user. |
| Work in progress | Work on the action task is in progress. |
| Review | The action task is in the review stage. |
| Closed complete | The action task is in the Closed complete stage. |
| Closed incomplete | The action task is in the Closed incomplete stage. |
| Canceled | The action task has been canceled. |
[Table 1. Workflow states for an action task]

{#creating-action-tasks__table_ntr_jkv_wcc}

## Notifications for the action tasks associated with the vulnerabilities {#creating-action-tasks__section_l2s_s41_xcc}

When an action task \[sn_grc_case_mgmt_case_task\] associated with the vulnerability is assigned to the users, they receive email notifications informing them about the task details, upcoming actions, and due dates. Email notifications are sent to the following users:

1. When the action task is assigned to the task owner, they receive the email notification.
2. When the action task is assigned to the assignment group, the users in the assignment group receive the email notifications.
3. When the action task is submitted for a review, the analyst assigned to the operational vulnerability record receives the email notification to review the task.
{#creating-action-tasks__ol_m2s_s41_xcc}

