Security metrics analysis AI agent

  • Release version: Australia
  • Updated August 14, 2026
  • 1 minute to read
  • This Operational Technology Security Incident Response agent calculates and analyzes security incident response metrics for an individual analyst or a team over a specified time range.

    Workflow

    1. Determine whether the user is asking about an individual analyst or a team (group), and extract the time range. Convert dates to GlideDate or GlideDateTime format.
    2. Run the Calculation tool with the analyst or group name and date range. Results are displayed automatically.
    3. Ask if the user wants a deeper look at a specific metric: security incident volume, MTTR, or MTTA. If accepted, run the Analysis tool for the selected metric.
    4. If analysis completed successfully, ask if the user wants improvement suggestions. If accepted, run the recommend tool using the analysis results.
    5. Ask if the user needs anything else. Route out-of-scope questions to other agents.
    Table 1. Configuration
    Field Description
    Allow third party to access this AI agent

    When enabled, third-party AI agents can use this agent. This value is off (false) by default. This setting is defined in the AI Agent configs [sn_aia_agent_config] table on the External discoverable field.

    Allow AI specialists to access this AI agent

    When enabled, AI specialists can use this agent. This value is off (false) by default. When set to true, more configuration options for tools become available so that an AI specialist can map inputs and response templates to tool outputs. This setting is defined in the AI Agent configs [sn_aia_agent_config] table on the Specialist enabled field.

    Manage long-term memory

    When enabled, all previous user interactions are used as context for the LLM. This value is off (false) by default. This setting is defined by the sn_aia.ltm.enable_long_term_memory system property. For more information, see ServiceNow Otto AI agents reference.

    Tools
    Scripts
    Analysis
    Calculation
    Recommend
    Agent roles (ACLs) sn_si.manager
    Data access roles sn_si.manager
    Triggers

    Optional. None defined by default. An admin can specify triggers if desired. For more information, see Add a trigger to an AI agent.

    Channels

    Enable the AI agent for the ServiceNow Otto panel.

    Used in agentic workflows

    Analyze security operations metrics

    Learn more about Operational Technology Security Incident Response at .