Configuring ServiceNow Otto for Security Incident Response (SIR)

  • Release version: Australia
  • Updated March 12, 2026
  • 2 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Configuring ServiceNow Otto for Security Incident Response (SIR)

    The ServiceNow Otto for Security Incident Response (SIR) application integrates generative AI capabilities into the Security Incident Response Workspace and the legacy Core UI (UI16). It enhances your security incident management by providing AI-driven skills such as incident summarization, resolution notes generation, and recommended actions. Configuration is performed through the AI Admin Hub console, which centralizes installation and skill management.

    Show full answer Show less

    Key Features

    • AI Access Control: AI agents use role masking to control user access. If you select access based on specific user roles, you must configure corresponding security controls to include those roles.
    • Generative AI Skills: Includes security incident summarization (for incidents in any state except Draft), resolution notes generation, metrics analysis, recommended actions (excluding Closed and Cancelled states), correlation insights, post-incident analysis, shift handover content generation, resolution planning, and quality assessment.
    • AI Search Dependency: The Recommended Actions skill requires the AI Search application to be enabled in your instance.
    • Data Sharing: Sharing data with the ServiceNow AI development program improves prediction accuracy and user experience but can be opted out per instance via the AI Admin Hub console.
    • Automatic Updates: Updating the ServiceNow Otto for SIR application automatically updates its dependency applications, ensuring compatibility and feature continuity.
    • Guided Setup: Use the AI Admin Hub console to install required plugins, configure generative AI skills, and manage agentic workflows. Skills can be deactivated, configured, and reactivated as needed.

    Practical Considerations for ServiceNow Customers

    • Ensure you install both the ServiceNow Otto for Security Incident Response (snsecgenai) and Security Incident Response Core (snsi) applications.
    • Verify that AI Search is enabled to fully utilize recommended action features.
    • Manage user access carefully by configuring role-based security controls to match your organizational requirements.
    • Be aware of which AI skills and workflows are enabled by default, and adjust settings based on your operational preferences.
    • Regularly review and update your configurations via the AI Admin Hub console for optimal performance and security incident response efficiency.

    The ServiceNow Otto for Security Incident Response (SIR) application is supported in the Security Incident Response Workspace and in the legacy Core UI (UI16). Use the guided setup in the AI Admin Hub console to configure ServiceNow Otto for Security Incident Response (SIR).

    Configuration overview

    AI agents use role masking to determine which users can access them. Ones installed with your applications have specific roles that come included with the application. If you select Users with specific roles for user access, you must configure the security controls to include these roles. For the instructions to change the security controls, see Define security controls for an AI agent.

    Important:
    Some generative AI skills, AI agents, and agentic workflows are turned on by default. For more information, see AI agents, skills, and agentic workflows on by default.

    By sharing data with the ServiceNow® AI development program, you provide relevant data to help improve prediction accuracy, user experience, tailor products to your business needs, and reduce hallucinations for your activated ServiceNow Otto skills.

    You can opt out of a ServiceNow instance from sharing data from the AI Admin Hub console. See Opt out of data sharing for Now Assist. Repeat the opt-out process for all instances that use the ServiceNow Otto functionality.

    Use the AI Admin Hub console to configure ServiceNow Otto for Security Incident Response (SIR). This console contains everything to install the applications and configure the generative AI skills. For additional information, see Configuring AI skills.
    Note:
    When you update the ServiceNow Otto for Security Incident Response (SIR) applications, its dependency applications are automatically updated.

    The following table lists the features and skills that you can access from the AI Admin Hub console.

    Note:
    Depending on your license, you will have access to certain application features, generative AI skills, agentic workflows, and AI agents. For more information, see ServiceNow product tiers.
    Table 1. ServiceNow Otto for Security Incident Response (SIR) features and skills in the AI Admin Hub console
    ServiceNow Otto product Security incident skills
    ServiceNow Otto for Security Incident Response (SIR) Security incident summarization
    Note:
    The incident summarization supports security incidents in any state other than Draft.
    Resolution notes generation.
    Security operations metrics analysis
    Security incident recommended actions
    The security incident recommended actions skill supports security incidents in any state other than Closed and Cancelled.
    Note:

    The AI Search application must be enabled so that the Recommended Actions skill works for security incidents. To verify AI Search is enabled on your instance, navigate to All > AI Search > AI Search Status. Contact support if the page indicates that AI Search is not enabled.

    Correlation insights support security incidents in all states.

    Post-incident analysis
    Generate content for shift handover
    Security incident resolution plan

    Security incident quality assessment

    1. Install plugins for ServiceNow Otto.

      Install the ServiceNow Otto for Security Incident Response (SIR) application (sn_sec_gen_ai) and Security Incident Response Core [sn_si] applications.

      Note:

      When you update the ServiceNow Otto for Security Incident Response (SIR) application, its dependency applications are automatically updated.

    2. Configure a skill for ServiceNow Otto for Security Incident Response (SIR)

      You can deactivate, configure, and reactivate generative AI skills and agentic workflows in the Guided Setup.