---
sourceDocument: Yokohama Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/security-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Confirm Potential Relationships from Related Records

# Confirm Potential Relationships from Related Records {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Confirm the relationships between the two SDOs.

## Before you begin

Role required: sn_sec_tisc.analyst

## Procedure

1. Navigate to WorkspacesThreat Intelligence Security Center.
2. Click on Threat Intel Library icon on the workspace.
3. Go to Related Records section.
4. Expand Potential Relationships.
5. Open any record such observables, indicators, or any other objects that you wish to confirm the relationships between two SDOs.
6. For example, here select Observables from the left navigation.
7. Select the Observable(s) records from the list.  
   Note:  
   The list section shows all the linked observable records of the associated observable.
8. Click Confirm Relationships button to confirm the relationships between the objects.  
   Note:  
   For more information, see[Relationships Objects](https://www.servicenow.com/docs/Kffra0ZJbg3rrW_AS5wO_g "Use the relationships objects to link together two observables or an observable and SDO to explain how they relate to each other.") and [Potential Relationships](https://www.servicenow.com/docs/dc1NAg3gI_TtywVl9FXRcg "The application uses automated correlation to establish potentially possible relationships between two SDOs, two Observables or an observable and SDO.").
9. Click Delete to delete the associated observables.  
   For information on how the potential relationships and relationships are established between the SDOs, see [Potential Relationships](https://www.servicenow.com/docs/dc1NAg3gI_TtywVl9FXRcg "The application uses automated correlation to establish potentially possible relationships between two SDOs, two Observables or an observable and SDO.") and [Relationships Objects](https://www.servicenow.com/docs/Kffra0ZJbg3rrW_AS5wO_g "Use the relationships objects to link together two observables or an observable and SDO to explain how they relate to each other.").
**Related concepts**   

* [Understanding the Data Model](https://www.servicenow.com/docs/JvbHihlTe8jVWT8lv~Tp1g "The data model and architecture of threat intelligence security center module is designed to support threat intelligence platform capabilities and different security views that provides detailed data for threat analysts.")
* [TISC Library Objects form view](https://www.servicenow.com/docs/jMSpvRfJXvu7R5ffjZRHdQ "The Threat Intelligence Security Center objects home page consists of the following features.")
* [TISC Library Repository](https://www.servicenow.com/docs/M~rXHs6WoWc7tQk8LH2~zg "IoC repository contains STIX objects, each of these objects contain a specific piece of information.")
* [Access Vulnerability Downstream actions](https://www.servicenow.com/docs/MxYDil~PTXIFReDSImpNDw "Access all downstream actions generated from a vulnerability record to track remediation progress and understand the scope of response activities.")
* [Automated Correlation](https://www.servicenow.com/docs/cOH1qz6X6W80lobk0Jq~aQ "Automated correlation helps you to identify the relationships between observables, indicators, and objects.")  
**Related tasks**   

* [Deleting threat intelligence library records](https://www.servicenow.com/docs/HBqtJBWLy8oOSlUgUHG7bg "Delete threat intelligence library records such as observables, indicators, and objects.")
* [Export intelligence data](https://www.servicenow.com/docs/OGCTjOwblyYRPOrzHe5qmw "Use the export feature to manually export the intelligence data in various formats.")

*[\>]: and then


