---
sourceDocument: Yokohama Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/security-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Inputs and triggers

# Inputs and triggers for ServiceNow Otto for Security Incident Response (SIR) {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 15, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Inputs and Triggers for ServiceNow Otto for Security Incident Response (SIR)

This content explains how to configure inputs and triggers for generative AI skills in ServiceNow Otto specifically tailored for Security Incident Response (SIR) in the Yokohama release.
Inputs define the data used by AI skills, such as specific tables and fields, while triggers determine when these skills activate.
These configurations help automate and enhance security incident management by generating summaries, resolution notes, recommended actions, and more.
Show full answer Show less  

## Inputs and Triggers

Inputs specify the data sources and fields that AI skills use to operate, while triggers initiate the corresponding actions. Although you can customize inputs and triggers, the underlying data sources (tables and fields) that the skills depend on cannot be modified.

## Key AI Skills and Their Inputs

* **Security Incident Summarization Skill:**
  * Data source: `Security Incident [snsiincident]` table
  * Input fields: Short description, Description, State, Priority, Work notes, Additional comments
  * Related inputs: Affected CIs, Affected Users, Security Incident Response Task details, Associated Observables flagged as Malicious or Suspicious
  * Trigger example: Generates a summary when incident state changes (excluding Cancelled)
* **Resolution Notes Generation Skill:**
  * Data source: `Security Incident [snsiincident]` table
  * Input fields: Short description, Description, Work notes, Additional comments
* **Security Incident Recommended Actions Generation Skill:**
  * Data source: `Security Incident [snsiincident]` table
* **Post Incident Analysis Generation Skill:**
  * Data source: `Security Incident [snsiincident]` table
* **Correlation Insights Generation Skill:**
  * Data sources: Multiple tables including Security Incident, Configuration Item, Incident, Change Request, Problem, Vulnerable Item, and Associated Observable
  * Note: Proper permissions are required to access these tables and records
* **Security Incident Quality Assessment:**
  * Data sources: Security Incident, Configuration Item, Task CI, Associated Observable, Affected Users, Security Incident Task, Task SLA, Email, and Playbook Activities
  * Access permissions must be in place for these tables

## Practical Implications for ServiceNow Customers

Understanding and configuring the inputs and triggers for these AI skills enables your organization to automate key aspects of security incident response, such as summarization, resolution note creation, and quality assessment. This allows faster, more consistent incident handling, leveraging data across multiple related tables to provide comprehensive insights and recommended actions. Ensuring appropriate permissions and carefully setting triggers ensures the AI skills activate at the right times and use relevant data to support your security operations effectively.  
You can configure some of the inputs or triggers for a generative AI skill. Inputs or triggers permit you to determine how and when a skill is used.

## Inputs and triggers {#input-triggers-now-assist-security-incident__section_bkt_wh3_1cc}

Inputs identify the data used for a skill. Inputs include the table and fields used to generate a security incident summary. A trigger initiates an action. For example, triggers determine when the system generates a summary.

You can modify inputs and triggers, but you can't modify a skill's data source. The data source contains the tables and fields that the skill relies on.

## Security incident summarization skill {#input-triggers-now-assist-security-incident__section_lqj_d33_1cc}

Inputs for the security incident summarization skill identify the table and fields used when a security incident summary is generated. The following table lists the inputs for the Security Incident summarization skill from the
Choose Input page in the AI Admin Hub console.
{#input-triggers-now-assist-security-incident__table_arz_fk3_1cc__entry__2}

| Input | Description |
|-|-|
| Data source | Security Incident \[sn_si_incident\] table. |
| Input fields | * Short description * Description * State * Priority * Work notes * Additional comments {#input-triggers-now-assist-security-incident__ul_o2w_jk3_1cc} |
| Related Input tables | * Affected CIs - configuration item * Affected Users - Users * Security Incident Response Task - Short description * State - Any state other than Cancelled. * Associated Observables - Observable finding is Malicious or Suspicious. {#input-triggers-now-assist-security-incident__ul_nfq_pk3_1cc} |
[ ]

{#input-triggers-now-assist-security-incident__table_arz_fk3_1cc}

## Resolution notes generation skill {#input-triggers-now-assist-security-incident__section_pk4_bl3_1cc}

Inputs for the Resolution notes generation skill identify the table and fields that are used when the resolution notes are generated for a security incident. The following table lists the inputs for the resolution notes generation
skill from the Choose Input page in the AI Admin Hub console.
{#input-triggers-now-assist-security-incident__table_il3_sfj_1cc__entry__2}

| Input | Description |
|-|-|
| Data source | Security Incident \[sn_si_incident\] table. |
| Input fields | * Short description * Description * Work notes * Additional comments {#input-triggers-now-assist-security-incident__ul_pq5_xfj_1cc} |
[ ]

{#input-triggers-now-assist-security-incident__table_il3_sfj_1cc}

## Security incident recommended actions generation skill {#input-triggers-now-assist-security-incident__section_q44_2kd_ycc}

{#input-triggers-now-assist-security-incident__table_b4z_gkd_ycc__entry__2}

| Input | Description |
|-|-|
| Data source | Security Incident \[sn_si_incident\] table. |
[ ]

{#input-triggers-now-assist-security-incident__table_b4z_gkd_ycc}

## Post incident analysis generation skill {#input-triggers-now-assist-security-incident__section_rby_3kd_ycc}

{#input-triggers-now-assist-security-incident__table_sp5_kkd_ycc__entry__2}

| Input | Description |
|-|-|
| Data source | Security Incident \[sn_si_incident\] table. |
[ ]

{#input-triggers-now-assist-security-incident__table_sp5_kkd_ycc}

## Correlation insights generation skill {#input-triggers-now-assist-security-incident__section_l1b_cl5_pdc}

Your correlation insights for a security incident can contain records from the following tables, but you must have permission to access these tables and records.  
{#input-triggers-now-assist-security-incident__table_ytl_2l5_pdc__entry__2}

| Input | Description |
|-|-|
| Data source | Security Incident \[sn_si_incident\] table. Configuration item \[cmdb_ci\] table. Incident \[incident\] table. Change request \[change_request\] table. Problem \[problem\] table. Vulnerable item \[sn_vul_vulnerable_item\] table. Associate observable \[sn_ti_observable\] table. |
[ ]

{#input-triggers-now-assist-security-incident__table_ytl_2l5_pdc}

## Security Incident Quality Assessment {#input-triggers-now-assist-security-incident__section_ksn_tc4_jhc}

Your Quality Assessment report for a security incident can contain records from the following tables, but you must have permission to access these tables and records.
{#input-triggers-now-assist-security-incident__table_k2k_zc4_jhc__entry__2}

| Input | Description |
|-|-|
| Data source | Security Incident \[sn_si_incident\] table. Configuration item \[cmdb_ci\] table. Task CI \[task_ci\] Associated Observable \[sn_ti_observable\] Affected Users \[sn_si_m2m_task_affected_user\] Security Incident Task \[sn_si_task\] Task SLA \[task_sla\] Email \[sys_email\] Playbook Activities: sys_pd_activity_context |
[ ]

{#input-triggers-now-assist-security-incident__table_k2k_zc4_jhc}

