Customize SI to MSI flows (optional)

  • Release version: Australia
  • Updated August 3, 2026
  • 1 minute to read
  • Copy and customize the SI to MSI promotion flows to control how File Explorer and chat channels are configured when a Security incident is promoted to a Major Security Incident.

    Before you begin

    Role required: sn_msi.workspace_admin

    Note:
    You can't edit delivered flows directly. Copy the flow and edit the copy to preserve the original delivered flow.

    About this task

    Two Flow Designer flows control component setup when a security incident is promoted to a major security incident:

    • SI to MSI Promotion (SharePoint) sets up the File Explorer component by calling the Create Folder Structure subflow, which builds the folder hierarchy per the Create Folder Templates configuration.
    • SI to MSI Promotion (Teams) sets up the Chat component by calling the Chat Team and Channels Creation subflow, which builds the team and channels per the Create a chat channel template configuration.

    Both flows are active by default. Use this procedure only if you need to customize how these components are configured during promotion.

    Procedure

    1. In the ServiceNow AI Platform, navigate to Flow Designer.
    2. Search for the SI to MSI Promotion (SharePoint) flow.
    3. Open the flow and select Copy from the flow actions.
    4. In the Name field, enter a name for the copied flow.
    5. Select Save.
    6. Make your customizations to the flow.
      For example, modify the folder structure or add additional actions.
    7. Select Activate.
    8. Verify that the flow status shows Active and the flow trigger is set to Major security incident Created or Updated where MSI candidate state is Accepted.
    9. Repeat steps 2 through 8 for the SI to MSI Promotion (Teams) flow.

    Result

    Confirm your customized flow is in the Active state before configuring notification preferences.