---
sourceDocument: Xanadu Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/xanadu/security-management

 Release :

    - xanadu

ft:locale :

    - en-US

ft:publication_title :

    - Xanadu Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Prerequisites for the Playbooks

# Prerequisites for the Playbooks {#ariaid-title1}

* Release version: Xanadu
* 
* Updated August 1, 2024
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

You need the following roles and plugins to build the Playbooks.
Role required: admin.

* Enable the Process Automation Designer (PAD) \[com.glide.pad.license\] plugin.
* Enable the following plugins for a playbook experience:
  * com.playbook_experience
  * now_playbook_exp
  * com.glide.playbook_experience.config
  {#getting-started-with-processes__ul_ylm_sv4_z5b}
* Enable Security Operations spoke to access flows \[com.snc.secops.spoke\].
* Enterprise Security Case Management PAD Commons.

{#getting-started-with-processes__ul_x3b_bv4_z5b}

Make sure that you have read the platform documentation on [Exploring playbooks](https://www.servicenow.com/docs/access?context=process-automation-designer&version=xanadu&pubname=xanadu-build-workflows&ft:locale=en-US) and [Process Automation Designer](https://www.servicenow.com/docs/access?context=process-automation-designer&version=xanadu&pubname=xanadu-build-workflows&ft:locale=en-US) before you start with this guide.
**Related concepts**   

* [Working with Security Incident Records](https://www.servicenow.com/docs/dlLDLMvqeD83gJtsSq9Vzw "The Security Incident Record consists of the following.")
* [Security Incident Playbook](https://www.servicenow.com/docs/LfQYHbqoZcTLWEeswHy0Uw#security-incident-playbook "Invoke the security incident playbook flow automatically or manually.")
* [Rebuilding existing playbooks in Workflow Studio](https://www.servicenow.com/docs/w~lMd_uh5MSW08qIh8ojvQ "You can’t convert existing flows directly into playbooks in Workflow Studio. Each flow designer step that creates a response task to guide the analyst must be broken down into separate actions or subflows.")
* [Activity Definitions](https://www.servicenow.com/docs/jH0QlYQv4AMbcYX8CJx3eA "The ServiceNow AI Platform provides a few activity definitions within the base system. In addition, for the playbooks that SIR Workspace base system, there are a few activity definitions defined in the base system under Enterprise Security Case Management PAD Commons application.")
* [Sample Playbooks for SIR Workspace](https://www.servicenow.com/docs/ejpJAv6NQqYDIkMnmwqAqw "You can create or configure playbooks for SIR Workspace quickly and easily without writing complicated code. You can use these playbooks to resolve security threats in a step-by-step manner. You can invoke the security incident playbook flow automatically or manually.")
* [Working with MSI Records](https://www.servicenow.com/docs/XC6yJY_u4yUfhX95hmx5bw "Using the Security Incident Response workspace, you can propose, promote, or link security incidents as major security incidents when the incidents are identified as critical threat to the organization.")
* [Working with Form UI actions](https://www.servicenow.com/docs/1Ss79kK58feMTSX~AS2JzQ "Following are the UI actions that are displayed on the security incident form.")  
**Related tasks**   

* [Security Incident Closure workflow](https://www.servicenow.com/docs/upeniKi3FYU_2f1_pV6cdQ "Close the security incident by updating the incident state.")
* [Handle security incidents using AWA](https://www.servicenow.com/docs/mjuDE~Jr1oZ6BNPje5ThtA "Using AWA, security analysts can handle the security incidents assigned to them, which are available in the inbox folder of SIR Workspace.")

