EDR AI agent

  • Release version: Australia
  • Updated August 14, 2026
  • 1 minute to read
  • This Operational Technology Security Incident Response agent retrieves host details or isolates a host associated with a security incident.

    Workflow

    1. Identify the configuration item (CI) from the security incident using hostname, IP address, or device identifier. If no CI is found, inform the user and stop. Run the get host details action. If the request fails, inform the user and stop.
    2. Identify the CI and security incident from user input. If no CI is found, ask the user how to proceed. Run the isolate host action. If the request fails, ask the user how to proceed.
    Table 1. Configuration
    Field Description
    Allow third party to access this AI agent

    When enabled, third-party AI agents can use this agent. This value is off (false) by default. This setting is defined in the AI Agent configs [sn_aia_agent_config] table on the External discoverable field.

    Allow AI specialists to access this AI agent

    When enabled, AI specialists can use this agent. This value is off (false) by default. When set to true, more configuration options for tools become available so that an AI specialist can map inputs and response templates to tool outputs. This setting is defined in the AI Agent configs [sn_aia_agent_config] table on the Specialist enabled field.

    Manage long-term memory

    When enabled, all previous user interactions are used as context for the LLM. This value is off (false) by default. This setting is defined by the sn_aia.ltm.enable_long_term_memory system property. For more information, see ServiceNow Otto AI agents reference.

    Tools
    Subflows
    Isolate host
    Run get host details tool
    Agent roles (ACLs) sn_si.analyst
    Data access roles sn_si.analyst
    Triggers

    Optional. None defined by default. An admin can specify triggers if desired. For more information, see Add a trigger to an AI agent.

    Channels

    Configure an assistant for Virtual Agent or ServiceNow Otto panel using Assistant Designer.

    Used in agentic workflows

    Resolve security incident

    Learn more about Operational Technology Security Incident Response at .