Security incident shift handover AI agent

  • Release version: Australia
  • Updated August 14, 2026
  • 1 minute to read
  • This Operational Technology Security Incident Response agent adds a security incident to a shift handover report, walking the user through each section for review.

    Workflow

    1. Get a valid security incident number from the user if one is not provided.
    2. Run the pre-processor to find active shift handover records for the user. If none exist, inform the user and end.
    3. If multiple shift handover records exist, ask the user to select one.
    4. Validate the selected handover record and generate its content. If validation fails, ask for a valid record number.
    5. If the security incident is already in the report, inform the user and get confirmation before adding it again.
    6. Walk through each section of the report. For each section, show the content, collect approval or revisions, and save to the database before moving to the next section.
    7. After all sections are processed, show a summary of saved and skipped sections.
    Table 1. Configuration
    Field Description
    Allow third party to access this AI agent

    When enabled, third-party AI agents can use this agent. This value is off (false) by default. This setting is defined in the AI Agent configs [sn_aia_agent_config] table on the External discoverable field.

    Allow AI specialists to access this AI agent

    When enabled, AI specialists can use this agent. This value is off (false) by default. When set to true, more configuration options for tools become available so that an AI specialist can map inputs and response templates to tool outputs. This setting is defined in the AI Agent configs [sn_aia_agent_config] table on the Specialist enabled field.

    Manage long-term memory

    When enabled, all previous user interactions are used as context for the LLM. This value is off (false) by default. This setting is defined by the sn_aia.ltm.enable_long_term_memory system property. For more information, see ServiceNow Otto AI agents reference.

    Tools
    Script
    Pre-processor for shift handover
    Save section content to database
    Validate and generate shift handover content
    Agent roles (ACLs) sn_si.manager, sn_si.analyst
    Data access roles sn_si.basic, sn_escm_sh.shift_analyst
    Triggers

    Optional. None defined by default. An admin can specify triggers if desired. For more information, see Add a trigger to an AI agent.

    Channels

    Enable the AI agent for the ServiceNow Otto panel.

    Used in agentic workflows

    Generate SIR Shift Handover Report

    Learn more about Operational Technology Security Incident Response at .