Configure post-runtime security metrics

  • Release version: Zurich
  • Updated May 2, 2026
  • 8 minutes to read
  • Customize security and content moderation policies, sampling rate, skill call usage limit, LLMs to use, and other settings for the Top AI asset security events metric and others.

    Before you begin

    Role required: AI steward [sn_ai_governance_ai_steward]

    Security and content moderation policies are grouped into LLM guardrail categories that reflect industry practices that align with OWASP Top 10 Risk & Mitigations for LLMs and Gen AI Apps and the OpenAI model specification. These categories are reflected in the Top AI asset security events metric.

    Procedure

    1. In AI Control Tower, navigate to Settings > Rules and templates > Security.
      Note:
      Alternatively, you can configure these metrics directly in the Post-runtime tab. Navigate to the tab and select Configure. The inline metric settings are organized by OWASP threat category, which is slightly different from how they're organized in Settings by LLM guardrail category.
    2. Select the ServiceNow AI systems tab.
    3. Under Data Model Integrity, configure the metrics and select Save and Close.
      Table 1. Data Model Integrity metrics
      Metric Description
      Data integrity incident detection Designed to help show potential violations of certain LLM guardrail policies in LLM responses. To show data for this metric in Top AI asset security events, select Configure, and then select Detection enabled.
      Note:
      If you disable the metric, past data shows on the chart for 90 days. AI judge model classifications are probabilistic in nature and may be incomplete or incorrect. They don't constitute professional advice and shouldn't be relied on as the sole basis for assessing risk.
      You can configure these settings:
      • Categories:
        • Physical, Chemical, Biological Harmful Content Detection
        • Guardrail Circumvention Attempt
        • Untrusted Links Or Downloads
        • Malware Detection
        • Over and Under Refusal Detection
        • Insecure Code Output
        • Confidential Information Extraction Attempts
        • Fraud or Deceptive Facilitation
        • Internal System Instruction Detection
      • Sampling rate – The percentage of transactions that are evaluated. Selecting a rate lower than 100% results in fewer AI calls, but potentially less accurate data. Lower sample rates reduce overhead but may not detect all security events. For critical systems, consider using 100%. For balanced coverage, consider using 75% or higher.
      • Max skill calls per execution – The amount of AI usage per call, with a minimum of 10 calls and a maximum of 100 calls. The default is 10 calls. Entering a lower number results in fewer AI calls, but potentially less accurate data.
      • Single or multiple analysis – Single analysis uses the default LLM to determine whether the model's output or behavior violates predefined security policies. Multiple analysis uses the results from three or more LLMs that ServiceNow supports to make a determination, using the majority result from the LLMs. Multiple analysis requires an odd number of LLMs.
      System prompt leakage System prompt leakage occurs when the model inadvertently reveals its system prompt or configuration instructions to users. To show data for this metric in Top AI asset security events, select Configure, and then select Detection enabled.
      Note:
      If you disable the metric, past data shows on the chart for 90 days.
      You can configure these settings:
      • Sampling rate – The percentage of transactions that are evaluated. Selecting a rate lower than 100% results in fewer AI calls, but potentially less accurate data. Lower sample rates reduce overhead but may not detect all security events. For critical systems, consider using 100%. For balanced coverage, consider using 75% or higher.
      • Max skill calls per execution – The amount of AI usage per call, with a minimum of 10 calls and a maximum of 100 calls. The default is 10 calls. Entering a lower number results in fewer AI calls, but potentially less accurate data.
      • Single or multiple analysis – Single analysis uses the default LLM to determine whether the model's output or behavior violates predefined security policies. Multiple analysis uses the results from three or more LLMs that ServiceNow supports to make a determination, using the majority result from the LLMs. Multiple analysis requires an odd number of LLMs.
      For external AI systems, configure the Sampling rate. Configure additional settings in AI Evaluation.
      Correctness detection Correctness measures whether the information provided in the model’s response is factually accurate and logically valid given the prompt and context. To show data for this metric in Top AI asset security events, select Configure, and then select Detection enabled.
      Note:
      If you disable the metric, past data shows on the chart for 90 days.
      You can configure these settings:
      • Sampling rate – The percentage of transactions that are evaluated. Selecting a rate lower than 100% results in fewer AI calls, but potentially less accurate data. Lower sample rates reduce overhead but may not detect all security events. For critical systems, consider using 100%. For balanced coverage, consider using 75% or higher.
      • Max skill calls per execution – The amount of AI usage per call, with a minimum of 10 calls and a maximum of 100 calls. The default is 10 calls. Entering a lower number results in fewer AI calls, but potentially less accurate data.
      • Single or multiple analysis – Single analysis uses the default LLM to determine whether the model's output or behavior violates predefined security policies. Multiple analysis uses the results from three or more LLMs that ServiceNow supports to make a determination, using the majority result from the LLMs. Multiple analysis requires an odd number of LLMs.
      For external AI systems, configure the Sampling rate. Configure additional settings in Correctness (factuality) in AI Evaluation.
    4. Under Threat monitoring, configure the metrics and select Save and Close.
      Table 2. Threat monitoring metrics
      Metric Description
      Prompt injection Prompt injection attacks occur when malicious input is crafted to override or deviate from the model’s instructions, causing unintended behavior. To show data for this metric in Top AI asset security events, select Configure, and then select Detection enabled.
      Note:
      If you disable the metric, past data shows on the chart for 90 days.
      You can configure these settings:
      • Sampling rate – The percentage of transactions that are evaluated. Selecting a rate lower than 100% results in fewer AI calls, but potentially less accurate data. Lower sample rates reduce overhead but may not detect all security events. For critical systems, consider using 100%. For balanced coverage, consider using 75% or higher.
      • Max skill calls per execution – The amount of AI usage per call, with a minimum of 10 calls and a maximum of 100 calls. The default is 10 calls. Entering a lower number results in fewer AI calls, but potentially less accurate data.
      • Single or multiple analysis – Single analysis uses the default LLM to determine whether the model's output or behavior violates predefined security policies. Multiple analysis uses the results from three or more LLMs that ServiceNow supports to make a determination, using the majority result from the LLMs. Multiple analysis requires an odd number of LLMs.
      For external AI systems, configure the Sampling rate. Configure additional settings in Prompt injection in AI Evaluation.
      Improper input and output handling When AI predictions are consumed in workflows without the right potential security vulnerability checks, it can lead to incorrect, unsafe, or biased actions. To show data for this metric in Top AI asset security events, select Configure, and then select Detection enabled.
      Note:
      If you disable the metric, past data shows on the chart for 90 days.
      You can configure these settings:
      • Output security vulnerability
      • Input security vulnerability
      Agent goal deviation Shows when AI agents may be deviating from their intended role or objective. For example, unauthorized actions or prompt injection attempts. To show data for this metric in Top AI asset security events, select Configure, and then select Detection enabled.
      Note:
      If you disable the metric, past data shows on the chart for 90 days.
      You can configure these settings:
      • Sampling rate – The percentage of transactions that are evaluated. Selecting a rate lower than 100% results in fewer AI calls, but potentially less accurate data. Lower sample rates reduce overhead but may not detect all security events. For critical systems, consider using 100%. For balanced coverage, consider using 75% or higher.
      • Max skill calls per execution – The amount of AI usage per call, with a minimum of 10 calls and a maximum of 100 calls. The default is 10 calls. Entering a lower number results in fewer AI calls, but potentially less accurate data.
      • Single or multiple analysis – Single analysis uses the default LLM to determine whether the model's output or behavior violates predefined security policies. Multiple analysis uses the results from three or more LLMs that ServiceNow supports to make a determination, using the majority result from the LLMs. Multiple analysis requires an odd number of LLMs.
      For external AI systems, configure the Sampling rate. Configure additional settings in Agent goal deviation in AI Evaluation.
    5. Under Sensitive data disclosure, configure the metrics and select Save and Close.
      Table 3. Sensitive data disclosure metrics
      Metric Description
      Output screening Output screening monitors AI-generated responses for sensitive or personally identifiable information (PII) before they're delivered to users. To show data for this metric in Top AI asset security events, select Configure, and then select Detection enabled.
      Note:
      If you disable the metric, past data shows on the chart for 90 days.
      You can configure these settings:
      • Output extended PII – Collect more potential PII data occurrences and show in the metric. The data is collected by analyzing LLM output for additional potential PII data patterns beyond those specified in Data Privacy. These PII data patterns include US CA drivers license, US passport number, US TIN number, and vehicle ID number.
      • Output PII violation – Collect and show data in the metric. The data is collected by analyzing LLM output for potential PII sensitive data patterns specified in Data Privacy. For example, US phone number or credit card number.
      Input screening Input screening monitors user input to detect and anonymize sensitive or personally identifiable information (PII) before it reaches the AI model. To show data for this metric in Top AI asset security events, select Configure, and then select Detection enabled.
      Note:
      If you disable the metric, past data shows on the chart for 90 days.
      You can configure these settings:
      • Input extended PII – Collect more potential PII data occurrences and show in the metric. The data is collected by analyzing LLM input for additional potential PII data patterns beyond those specified in Data Privacy. These PII data patterns include US CA drivers license, US passport number, US TIN number, and vehicle ID number.
      • Input PII violation – Collect and show data in the metric. The data is collected by analyzing LLM input for potential PII sensitive data patterns specified in Data Privacy. For example, US phone number or credit card number.
    6. Select the External AI systems tab and repeat steps 3-5.
      Some settings aren't available to be configured in security for external AI systems. Instead, you're directed to the Evaluation tab in Settings to configure the settings.