---
sourceDocument: Zurich Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/security-management

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Generate closure notes

# Generate closure notes {#ariaid-title1}

* Release version: Zurich
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Automatically generate a draft of the closure notes for a security incident when you close it. The draft is editable and will be reviewed before closing the security incident, and it can be used or modified as needed. Closure
notes provide information about the resolution of a security incident to other analysts, managers, and key stakeholders.

## Before you begin

Roles required: sn_si.analyst, sn_si.manager, or sn_si.basic  
Note:  
If the Close code or Close notes fields are already updated for a security incident, ServiceNow Otto will not modify these fields, regardless of the incident's current state. To enable ServiceNow Otto to update these fields, verify that both the Close Code and Closure Notes fields are left empty.

## Procedure

1. In the legacy Core UI, navigate to AllSecurity IncidentIncidents and open a security incident that is assigned to you.
2. Alternatively, navigate to AllSecurity IncidentSecurity Incident Response Workspace and open a security incident that is assigned to you.
3. Close the security incident.

   | Option | Description |
   | Close the security incident in legacy Core UI16 | 1. Change the State field to Closed. The Closure modal is displayed. 2. Click on the Close notes section. The close notes will be auto-generated if no text exists, or you can modify the existing text as needed by choosing the required option from NACM. Note: You might want to review the generated text and make sure it's accurate before you close the security incident. Edit the notes or delete them to provide your own. You can also Elaborate or Shorten the generated text. 3. Select the required option from the ServiceNow Otto context menu. Elaborate will help you to elaborate the text and replaces the selected resolution text. In case, if you wish to shorten the resolution text you can select Shorten option from the Context menu to make the text more concise. 4. Update the Close code and select Close incident. The resolution summary is displayed in the Resolution Information section on the security incident record. Note: Using the ServiceNow Otto context menu, you can directly add or generate the resolution notes in the Close notes section on the incident record itself, when the incident is in the Review state. For more information, see the screen shot below. {#generate-closure-notes-si-now-assist-sec-incident__ol_hrc_5rr_1cc} |
   | Close the security incident from the Security Incident Response Workspace | 1. On the Details tab of the workspace, change the State field to Closed. The stepper modal is displayed. 2. Review each step and select Next. 3. Select Provide resolution details 4. Click on the Close notes section. The close notes will be auto-generated if no text exists, or you can modify the existing text as needed using the NowAssist options. Note: You might want to review the generated text and make sure it's accurate before you close the security incident. Edit the notes or delete them to provide your own. You can also Elaborate or Shorten the generated text. 5. Select the required option from the ServiceNow Otto context menu. Elaborate will help you to elaborate the text and replaces the selected resolution text. In case, if you wish to shorten the resolution text you can select Shorten option from the context menu to make the text more concise. 6. Update the Close code and select Close incident. The resolution summary is displayed on the Details tab on the security incident record in the workspace. Note: Using the context menu, you can directly add or generate the resolution notes in the Close notes section on the incident record itself, when the incident is in the Review state. For more information, see the screen shot below. {#generate-closure-notes-si-now-assist-sec-incident__ol_nmk_csr_1cc} |
   |-|-|

   {#generate-closure-notes-si-now-assist-sec-incident__choicetable_dkw_4rr_1cc}  
   The following screen shot depicts the resolution notes generated for closing the security incident in Core UI16.

   Auto-generated resolution notes from the Security Incident Response Workspace.  
   Edit the resolution notes generated using the ServiceNow Otto context menu on the Security Incident Response workspace.

*[\>]: and then


