Using agentic workflows

  • Release version: Zurich
  • Updated May 26, 2026
  • 2 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Using agentic workflows

    Agentic workflows in ServiceNow use AI agents to autonomously complete tasks related to Vulnerability Response. These workflows enable vulnerability analysts and remediation owners to interact with vulnerability data using natural language, automate remediation actions, and gain insights into exposure and compliance metrics. Access to specific workflows and AI agents depends on your ServiceNow license.

    Show full answer Show less

    Available Agentic Workflows and AI Agents

    The table below outlines key agentic workflows available for Vulnerability Response, their purposes, and the AI agents and workspaces they support:

    • Security Exposure 360: Evaluates vulnerability exposure across hosts, containers, and test results, allowing users to query findings in plain language. Supports Data Analysis AI Agent in Legacy and Unified Security Exposure Management (USEM) workspaces.
    • Guardrails Detector Workflow: Manages AI-identified guardrails by auto-deferring findings with existing mitigations or creating exception rules. Uses the Guardrails detector agentic workflow in USEM workspace.
    • Assess Vulnerability Exposure: Assesses exposure of configuration items (CIs) and business services to known vulnerabilities, including zero-day vulnerabilities flagged by CISA. Enables creation of watch topics for remediation. Utilizes CISA vulnerability analysis, vulnerability exposure analysis, and watch topic creation AI agents in Legacy and USEM workspaces.
    • Retrieve Vulnerability and Exposure Data: Allows natural language queries to quickly retrieve vulnerability and exposure data across legacy and USEM sources. Employs the Retrieve VR data agent in Legacy and USEM workspaces.
    • Analyze Vulnerability Remediation Status: Provides insights into compliance with remediation targets, including SLA reviews by severity, assignment group, configuration item, and vulnerability. Uses the Remediation compliance analysis AI agent in Legacy and USEM workspaces.

    Practical Notes for ServiceNow Customers

    • All agentic workflows and AI agent records are read-only by default. To customize a workflow, duplicate it first, then activate and configure it as needed.
    • The ServiceNow Otto AI agents for USEM are activated by default, but you can add triggers to automate workflow invocation.
    • Your instance may have AI agents not currently used in agentic workflows; you can review available agents to expand your capabilities.

    Use AI agents to complete your tasks autonomously.

    Note:
    Depending on your license, you will have access to certain application features, generative AI skills, agentic workflows, and AI agents. For more information, see .
    Table 1. Available agentic workflows for AI agents for Vulnerability Response
    Agentic workflow name Description Available AI agents Supported workspaces
    Security Exposure 360 Evaluate vulnerability exposure data with Security Exposure 360.

    Vulnerability analysts and remediation owners can enter questions in plain language and receive comprehensive answers about all types of findings that include host, container, and test results vulnerabilities.

    Data Analysis AI Agent Legacy and Unified Security Exposure Management (USEM)
    Guardrails detector agentic workflow Manage potential AI exposures

    Use the AI agent to ask about the guardrails that were identified by the AI skill component in the AI Guardrails Helper. Automatically defer findings with existing mitigations in the form of guardrails, or create exception rules to auto-defer future findings.

    Guardrails detector agentic workflow Unified Security Exposure Management (USEM)
    Assess vulnerability exposure Assess your vulnerability exposure
    • Determine if your configuration items (CIs) and business services are exposed to known vulnerabilities.
    • Determine the potential impact that a specific vulnerability might have throughout your environment.
    • Check CIs for any new Cybersecurity and Infrastructure Security Agency (CISA) exploitable (zero-day) vulnerabilities.
    • Create watch topics in the Vulnerability Manager workspace to remediate vulnerable items.
    • CISA vulnerability analysis AI agent
    • Vulnerability exposure analysis AI agent
    • Watch topic creation AI agent
    Legacy and Unified Security Exposure Management (USEM)
    Retrieve vulnerability and exposure data Retrieve Vulnerability and exposure data with generative AI.

    Ask questions in natural language to help you quickly retrieve vulnerability and exposure data across legacy sources and Unified Security Exposure Management (USEM).

    Retrieve VR data agent Legacy and Unified Security Exposure Management (USEM)
    Analyze vulnerability remediation status Analyze vulnerability remediation status
    • Gain insights into your compliance metrics and statistics for how well you're meeting remediation target dates on vulnerable item (VIT) records.
    • View your monthly VIT record remediation totals and identify missed targets.
    • Break down remediation data on VITs by Severity, Assignment group, Configuration item, and Vulnerability for your monthly Service Level Agreement (SLA) compliance reviews.
    Remediation compliance analysis AI Agent Legacy and Unified Security Exposure Management (USEM)
    Important:
    By default, all agentic workflows and AI agent records are read-only.
    To modify an agentic workflow, you must first duplicate the agentic workflow, and then proceed with the following steps:
    • Activate the agentic workflow. The ServiceNow Otto for Unified Security Exposure Management AI agents included with the application are activated by default.
    • If required, you can add a trigger to invoke the agentic workflow automatically.
    • See Configure an agentic workflow for more information.

    There might be AI agents installed on your instance that are not used in agentic workflows. To learn how to see all agents that are available to you, see Find AI agents.