Security incident wrap up generator AI agent

  • Release version: Australia
  • Updated August 14, 2026
  • 1 minute to read
  • This Operational Technology Security Incident Response agent can close a security incident by performing all pre-closure validations. It can also generate close notes, generate post incident analysis, post work note, and update the state of the security incident to close it.

    Workflow

    1. If the user explicitly requests closing as a false positive, follow the short path. Otherwise, follow the full closure path.
    2. Retrieve the incident details. If already closed or cancelled, inform the user and end.
    3. If the user explicitly requests closing as a false positive, close the incident immediately and end.
    4. If the user doesn't explicitly requests closing as a false positive, warn the user if open response tasks or mandatory assessments will be affected. Get approval before continuing.
    5. Produce a post-incident analysis, close notes, and a suggested close code. The user reviews and approves or revises each before proceeding.
    6. Write the approved content to the record and confirm closure.
    Table 1. Configuration
    Field Description
    Allow third party to access this AI agent

    When enabled, third-party AI agents can use this agent. This value is off (false) by default. This setting is defined in the AI Agent configs [sn_aia_agent_config] table on the External discoverable field.

    Allow AI specialists to access this AI agent

    When enabled, AI specialists can use this agent. This value is off (false) by default. When set to true, more configuration options for tools become available so that an AI specialist can map inputs and response templates to tool outputs. This setting is defined in the AI Agent configs [sn_aia_agent_config] table on the Specialist enabled field.

    Manage long-term memory

    When enabled, all previous user interactions are used as context for the LLM. This value is off (false) by default. This setting is defined by the sn_aia.ltm.enable_long_term_memory system property. For more information, see ServiceNow Otto AI agents reference.

    Tools
    Scripts
    Close security incident as false positive
    Fetch security incident details
    Generate close notes for security incident
    Generate post incident analysis for security incident
    Update security incident closure information
    Agent roles (ACLs) sn_si.analyst
    Data access roles sn_si.analyst
    Triggers

    Optional. None defined by default. An admin can specify triggers if desired. For more information, see Add a trigger to an AI agent.

    Channels

    Enable the AI agent for the ServiceNow Otto panel.

    Used in agentic workflows

    Wrap up security incident

    Learn more about Operational Technology Security Incident Response at .