---
sourceDocument: Zurich Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/security-management

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Close a security incident

# Close a security incident {#ariaid-title1}

* Release version: Zurich
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Chat with an AI agent in the ServiceNow Otto panel to help you close a security
incident.

## Before you begin

Role required: sn_si.analyst or sn_si.manager

## About this task

Important:  
This agentic workflow is turned on by default. For more information, see [AI agents, skills, and agentic workflows on by default](https://www.servicenow.com/docs/access?context=now-assist-skills-on-by-default&version=zurich&pubname=zurich-intelligent-experiences&ft:locale=en-US).

## Procedure

1. Navigate to AllSecurity IncidentSecurity Incident Response Workspace.
2. Open the security incident that you want to close by using the AI agent.
3. Select the ServiceNow Otto icon (![AI Sparkle icon.]()) icon.  
   The panel is displayed.
4. Close the security incident by using one of the following options.

   | Option | Description |
   | Close a security incident | On the panel, ask the agent to close the security incident in natural language by entering <kbd class="ph userinput">Close this incident</kbd>, <kbd class="ph userinput">Close this security incident</kbd>, or <kbd class="ph userinput">Close the security incident: SIR0012345</kbd>. Note: * When you enter <kbd class="ph userinput">Close this incident</kbd> or <kbd class="ph userinput">Close this security incident</kbd>, the panel picks the security incident in context. When you provide a specific security incident number, such as <kbd class="ph userinput">Close the security incident: SIR0012345</kbd>, the agentic workflow takes action for the suggested security incident. * You can close any security incident from the panel by providing the security incident number in your text. * When you request a security incident closure, the Wrap up security incident agentic workflow cancels the mandatory post incident assessment, flow actions, playbook actions, workflow actions, and response tasks. However, you can close these actions manually before initiating the security incident closure request. {#close-sir-incident-aiagent__ul_nqs_xrw_m2c} The Wrap up security incident agentic workflow provides content for each of the following fields and asks for your feedback. The agentic workflow populates your accepted feedback. After you accept the content for a field, the agentic workflow provides content for the next field. * Post Incident Analysis: Accept the suggested content by replying with a positive response such as <kbd class="ph userinput">looks good</kbd> or <kbd class="ph userinput">Ok</kbd>. Ask the agentic workflow to refine the content and suggest the changes you require. * Close notes: Accept the suggested content by replying with a positive response such as <kbd class="ph userinput">looks good</kbd> or <kbd class="ph userinput">Ok</kbd>. You can ask the agentic workflow to refine the content and you can also suggest the changes you require. * Close code: On the basis of the security incident details, the agentic workflow suggests a close code. You can accept the close code or suggest an alternative close code for the security incident. {#close-sir-incident-aiagent__ul_es1_lc3_m2c} The AI agent closes the security incident. Note: When a field is changed, the activity stream appends the words "AI AGENT:" with a description of the update made by the AI agent. For example, AI AGENT: Close code is updated. |
   | Close a security incident as false positive | On the panel, you can ask the AI agent to close the security incident as false positive. For example, <kbd class="ph userinput">Close this incident as false positive</kbd> or <kbd class="ph userinput">close this security incident as false positive</kbd>. The agentic workflow provides the summary of the security incident. To close the security incident, enter positive responses such as <kbd class="ph userinput">looks good</kbd> or <kbd class="ph userinput">Ok</kbd>. The AI agent closes the security incident. It also updates the Close notes as Closed by AI Agent as false positive and the Close code as False positive and cancels all active response tasks. |
   |-|-|

   {#close-sir-incident-aiagent__choicetable_ytr_35h_m2c}

*[\>]: and then


