---
sourceDocument: Zurich Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/security-management

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Resolve security incidents

# Resolve security incidents {#ariaid-title1}

* Release version: Zurich
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Chat with an AI agent in the ServiceNow Otto panel to help you create a resolution plan for a security incident and to resolve it.

## Resolve security incident agentic workflow overview {#now-assist-sir-resolve-incident-ai-workflow__section_ocf_d2x_t2c}

Use the Resolve security incident agentic workflow to fetch incident details, knowledge articles and similar closed security incidents, get a resolution plan, and resolve the security incident.

To modify this agentic workflow, [duplicate](https://www.servicenow.com/docs/access?context=clone-aia-usecase&version=zurich&pubname=zurich-intelligent-experiences&ft:locale=en-US) it, adjust the settings to suit your specific needs, and activate the duplicated version of the agentic workflow instead.

## Agents used in the Resolve security incident agentic workflow {#now-assist-sir-resolve-incident-ai-workflow__section_tjt_sfx_t2c}

The Resolve security incident agentic workflow contains the following AI agents:

* Security incident resolution AI agent
* Exchange online integration handling AI agent
* Security incident wrap up generator AI agent
* Observable analysis AI agent
* Security incident activities handling AI agent
* EDR AI agent
{#now-assist-sir-resolve-incident-ai-workflow__ul_f2v_5zc_52c}

