Using agentic workflows
Summarize
Summary of Using agentic workflows
Agentic workflows in ServiceNow enable AI agents to autonomously complete tasks related to Vulnerability Response. These workflows leverage generative AI to assist vulnerability analysts and remediation owners by interpreting natural language questions and providing actionable insights. Access to these features depends on your ServiceNow license tier, which determines the available AI skills, workflows, and agents.
Show less
Available Agentic Workflows and AI Agents
Several agentic workflows exist to support different aspects of vulnerability management within the Legacy and Unified Security Exposure Management (USEM) environments. Each workflow is paired with specific AI agents and supported workspaces, allowing tailored automation and analysis:
- Security Exposure 360: Enables evaluation of vulnerability exposure including hosts, containers, and test results. Supports Data Analysis AI Agents in both Legacy and USEM workspaces.
- Guardrails Detector Agentic Workflow: Helps manage AI-related exposures by using AI to identify and automatically defer findings with existing mitigations or create exception rules. Utilizes the Guardrails Detector AI Agent within USEM.
- Assess Vulnerability Exposure: Assesses exposure of configuration items (CIs) and business services to vulnerabilities, including zero-day exploits tracked by CISA. It helps determine impact and facilitates remediation through watch topics. Supported by CISA Vulnerability Analysis, Vulnerability Exposure Analysis, and Watch Topic Creation AI Agents in both Legacy and USEM.
- Retrieve Vulnerability and Exposure Data: Allows natural language queries to quickly access vulnerability and exposure data across multiple sources. Uses the Retrieve VR Data AI Agent in both Legacy and USEM.
- Analyze Vulnerability Remediation Status: Provides compliance metrics and monthly remediation performance insights, broken down by severity, assignment group, and other factors to support SLA compliance reviews. Supported by the Remediation Compliance Analysis AI Agent in both Legacy and USEM.
Practical Considerations for ServiceNow Customers
- By default, agentic workflows and AI agent records are read-only. To customize, you must duplicate the workflow, then activate and optionally configure triggers for automatic invocation.
- The Otto AI agents for USEM come activated by default, simplifying initial use.
- Not all AI agents installed may be in use within agentic workflows. Customers can view all available AI agents to identify potential capabilities for their environment.
Key Benefits
- Automates complex vulnerability analysis and remediation tasks using AI, reducing manual effort and accelerating response times.
- Enables natural language interaction with security data, improving accessibility and decision-making.
- Supports compliance tracking and detailed reporting to help meet remediation SLAs effectively.
- Flexible customization options allow adaptation of workflows to specific organizational needs and automation strategies.
Use AI agents to complete your tasks autonomously.
| Agentic workflow name | Description | Available AI agents | Supported workspaces |
|---|---|---|---|
| Security Exposure 360 | Evaluate vulnerability exposure data with Security Exposure 360. Vulnerability analysts and remediation owners can enter questions in plain language and receive comprehensive answers about all types of findings that include host, container, and test results vulnerabilities. |
Data Analysis AI Agent | Legacy and Unified Security Exposure Management (USEM) |
| Guardrails detector agentic workflow | Manage potential AI exposures Use the AI agent to ask about the guardrails that were identified by the AI skill component in the AI Guardrails Helper. Automatically defer findings with existing mitigations in the form of guardrails, or create exception rules to auto-defer future findings. |
Guardrails detector agentic workflow | Unified Security Exposure Management (USEM) |
| Assess vulnerability exposure | Assess your vulnerability exposure
|
|
Legacy and Unified Security Exposure Management (USEM) |
| Retrieve vulnerability and exposure data | Retrieve Vulnerability and exposure data with generative AI. Ask questions in natural language to help you quickly retrieve vulnerability and exposure data across legacy sources and Unified Security Exposure Management (USEM). |
Retrieve VR data agent | Legacy and Unified Security Exposure Management (USEM) |
| Analyze vulnerability remediation status | Analyze vulnerability remediation status
|
Remediation compliance analysis AI Agent | Legacy and Unified Security Exposure Management (USEM) |
- Activate the agentic workflow. The ServiceNow Otto for Unified Security Exposure Management AI agents included with the application are activated by default.
- If required, you can add a trigger to invoke the agentic workflow automatically.
- See Configure an agentic workflow for more information.
There might be AI agents installed on your instance that are not used in agentic workflows. To learn how to see all agents that are available to you, see Find AI agents.