---
sourceDocument: Australia Enable AI
sourceDocumentLink: https://www.servicenow.com/docs/r/intelligent-experiences

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Enable AI

ft:clusterId :

    - platai

bundleId :

    - platai

workflow :

    - Platform


---

# Security incident resolution AI agent

# Security incident resolution AI agent {#ariaid-title1}

* Release version: Australia
* 
* Updated August 14, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

This Operational Technology Security Incident Response agent walks the user through resolving a security incident by generating and executing a resolution plan.

## Workflow {#sir-security-incident-resolution-ai-agent__zsmdlwierhjt}

1. Fetch the security incident details and resolution plan. End if already closed or resolved.
2. Summarize the incident's current state, including any resolution steps already completed, and show it to the user.
3. Present the resolution plan for user review. Iterate on revisions until the user approves.
4. Execute each step in the approved plan in order. Falls back to other agents for steps it can't perform itself.
5. Confirm completion with the user. Only end when the user explicitly confirms no further actions are needed.
{#sir-security-incident-resolution-ai-agent__ol_pmx_t32_1kc}  
{#sir-security-incident-resolution-ai-agent__zsmdlwierhjt__entry__2}

| Field | Description |
|-|-|
| Allow third party to access this AI agent | When enabled, third-party AI agents can use this agent. This value is off (false) by default. This setting is defined in the AI Agent configs \[sn_aia_agent_config\] table on the External discoverable field. |
| Allow AI specialists to access this AI agent | When enabled, AI specialists can use this agent. This value is off (false) by default. When set to true, more configuration options for tools become available so that an AI specialist can map inputs and response templates to tool outputs. This setting is defined in the AI Agent configs \[sn_aia_agent_config\] table on the Specialist enabled field. |
| Manage long-term memory | When enabled, all previous user interactions are used as context for the LLM. This value is off (false) by default. This setting is defined by the sn_aia.ltm.enable_long_term_memory system property. For more information, see [ServiceNow Otto AI agents reference](https://www.servicenow.com/docs/MUqSU8rHp3ao~q3QEWgHkA "Find more information about user roles, tables, and the different properties that are installed in ServiceNow Otto AI agents."). |
| Tools | Script :   Fetch security incident details and resolution steps |
| Agent roles (ACLs) | sn_si.analyst |
| Data access roles | sn_si.analyst |
| Triggers | Optional. None defined by default. An admin can specify triggers if desired. For more information, see [Add a trigger to an AI agent](https://www.servicenow.com/docs/NXqRJBQV_Vw00FEzklcAJw "In the guided setup for an AI agent, add triggers to run the AI agent automatically when certain conditions are met."). |
| Channels | Enable the AI agent for the ServiceNow Otto panel. |
| Used in agentic workflows | Resolve security incident |
[Table 1. Configuration]

Learn more about Operational Technology Security Incident Response at .

