---
sourceDocument: Yokohama Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/security-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Define object-observable relationships

# Define object-observable relationships {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Define relationships between SDOs and the observable object (SCO).

## Before you begin

Role required: sn_sec_tisc.analyst

## Procedure

1. Navigate to WorkspacesThreat Intelligence Security Center.
2. Click on Threat Intel Library icon on the workspace.
3. Go to RelationshipsObject-Observable.
4. Click New.
5. Complete the fields in the form as appropriate.

   | Field | Description |
   | Observable | Select and define the observable. |
   | Object | Select and define the object. |
   | Relationship Type | A description that provides more details and context about the relationship type. Define the relationship direction whether it is direct or inverse. * Inverse - This is the type of relationship between the observable and object. * Direct - This is the type of relationship between the object and observable. {#define-object-observable-relationships__ul_oxw_ngj_nzb} |
   | Start Time | Specifies the time when the relationship is created. |
   | Stop Time | Specifies the time when the relationship is stopped or removed. |
   | Description | A brief description about the object relationships. |
   |-|-|

   {#define-object-observable-relationships__choicetable_uvs_2cc_nzb}
6. Click Submit.
{#define-object-observable-relationships__steps_tvs_2cc_nzb}

*[\>]: and then


