---
sourceDocument: Zurich Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/security-management

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Agentic workflows with USEM

# Using agentic workflows {#ariaid-title1}

Release version: Zurich  
Updated May 26, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Using agentic workflows

Agentic workflows in ServiceNow enable AI agents to autonomously complete tasks related to vulnerability response.
These workflows leverage generative AI skills and AI agents to assist vulnerability analysts and remediation owners in managing and analyzing security exposures and vulnerabilities efficiently.
Access to these features depends on your ServiceNow license tier.
Show full answer Show less  

## Key Features

* **Security Exposure 360:** Allows users to query vulnerability exposure data in natural language across hosts, containers, and test results using Data Analysis AI Agent across both Legacy and Unified Security Exposure Management (USEM) platforms.
* **Guardrails Detector Agentic Workflow:** Helps manage AI-identified guardrails by automatically deferring findings with existing mitigations or creating exception rules for future findings, using the Guardrails detector agentic workflow in USEM.
* **Assess Vulnerability Exposure:** Enables assessment of configuration items (CIs) and business services for known vulnerabilities, potential impacts, and identification of zero-day vulnerabilities from CISA. It also supports creating watch topics for remediation within the Vulnerability Manager workspace using multiple AI agents.
* **Retrieve Vulnerability and Exposure Data:** Facilitates quick retrieval of vulnerability and exposure information through natural language queries, covering both legacy sources and USEM with the Retrieve VR data agent.
* **Analyze Vulnerability Remediation Status:** Provides insights into compliance metrics and remediation target achievements by severity, assignment group, configuration item, and vulnerability for SLA compliance reviews, powered by the Remediation compliance analysis AI Agent.

## Practical Use and Configuration

* All agentic workflows and AI agent records are read-only by default. To modify a workflow, you must duplicate it first, then activate and optionally configure triggers for automatic invocation.
* The AI agents included with the Unified Security Exposure Management application are activated by default, simplifying initial setup.
* Some AI agents may be installed but not used in agentic workflows; you can view all available AI agents to understand your options.

## Benefits for ServiceNow Customers

By using agentic workflows, ServiceNow customers can streamline vulnerability management tasks, gain actionable insights through AI-driven analysis, and reduce manual effort in assessing and remediating security exposures. These workflows improve efficiency and accuracy in vulnerability response processes, helping maintain compliance and enhance security posture.  
Use AI agents to complete your tasks autonomously.
Note:  
Depending on your license, you will have access to certain application features, generative AI skills, agentic workflows, and AI agents. For more information, see [ServiceNow product tiers](https://www.servicenow.com/docs/access?context=ai-native-sku-overview&version=zurich&pubname=zurich-intelligent-experiences&ft:locale=en-US).
{#using-now-assist-ai-agents-vr__table_lpw_nx2_r2c__entry__4}

| Agentic workflow name | Description | Available AI agents | Supported workspaces |
|-|-|-|-|
| Security Exposure 360 | [Evaluate vulnerability exposure data with Security Exposure 360](https://www.servicenow.com/docs/UwCSbxYQXrwxN~Hs6~dxGQ "Use the Security Exposure 360 agentic workflow to review vulnerability data about your environment. Vulnerability analysts and remediation owners can enter questions in plain language and receive comprehensive answers about host, container, and test results vulnerabilities."). Vulnerability analysts and remediation owners can enter questions in plain language and receive comprehensive answers about all types of findings that include host, container, and test results vulnerabilities. | Data Analysis AI Agent | Legacy and Unified Security Exposure Management (USEM) |
| Guardrails detector agentic workflow | [Manage potential AI exposures](https://www.servicenow.com/docs/_q9p~lLOUy2_bCgOQP3Qfw "AI Security Exposure Management is a part of the Unified Security Exposure Management product suite of applications. AI Security Exposure Management integrates with third-party AI security products to help you manage various types of potential AI exposure across your environment.") Use the AI agent to ask about the guardrails that were identified by the AI skill component in the AI Guardrails Helper. Automatically defer findings with existing mitigations in the form of guardrails, or create exception rules to auto-defer future findings. | Guardrails detector agentic workflow | Unified Security Exposure Management (USEM) |
| Assess vulnerability exposure | [Assess your vulnerability exposure](https://www.servicenow.com/docs/LhmVbThvguHOxlQYYUm82A "Chat with an AI agent to help you assess the potential exposure of your configuration items and your business services to vulnerabilities.") * Determine if your configuration items (CIs) and business services are exposed to known vulnerabilities. * Determine the potential impact that a specific vulnerability might have throughout your environment. * Check CIs for any new Cybersecurity and Infrastructure Security Agency (CISA) exploitable (zero-day) vulnerabilities. * Create watch topics in the Vulnerability Manager workspace to remediate vulnerable items. {#using-now-assist-ai-agents-vr__ul_bnt_jxz_r2c} | * CISA vulnerability analysis AI agent * Vulnerability exposure analysis AI agent * Watch topic creation AI agent {#using-now-assist-ai-agents-vr__ul_ccx_xzz_r2c} | Legacy and Unified Security Exposure Management (USEM) |
| Retrieve vulnerability and exposure data | [Retrieve Vulnerability and exposure data with generative AI](https://www.servicenow.com/docs/BK~nlPdn_f1JsCbpjdj5Pg "Chat with an AI agent to retrieve information about Vulnerability Response (host) and Application Vulnerability Response findings (vulnerable items and application vulnerable items)."). Ask questions in natural language to help you quickly retrieve vulnerability and exposure data across legacy sources and Unified Security Exposure Management (USEM). | Retrieve VR data agent | Legacy and Unified Security Exposure Management (USEM) |
| Analyze vulnerability remediation status | [Analyze vulnerability remediation status](https://www.servicenow.com/docs/KZk9Cun5UsQLmRibWUixOA "Chat with an AI agent to help you gain insights into your monthly remediation compliance metrics for vulnerable items.") * Gain insights into your compliance metrics and statistics for how well you're meeting remediation target dates on vulnerable item (VIT) records. * View your monthly VIT record remediation totals and identify missed targets. * Break down remediation data on VITs by Severity, Assignment group, Configuration item, and Vulnerability for your monthly Service Level Agreement (SLA) compliance reviews. {#using-now-assist-ai-agents-vr__ul_ssg_sxz_r2c} | Remediation compliance analysis AI Agent | Legacy and Unified Security Exposure Management (USEM) |
[Table 1. Available agentic workflows for AI agents for Vulnerability Response]

{#using-now-assist-ai-agents-vr__table_lpw_nx2_r2c}  
Important:  
By default, all agentic workflows and AI agent records are read-only.  
To modify an agentic workflow, you must first [duplicate the agentic workflow](https://www.servicenow.com/docs/access?context=clone-aia-usecase&version=zurich&pubname=zurich-intelligent-experiences&ft:locale=en-US), and then proceed with the following steps:

* Activate the agentic workflow. The ServiceNow Otto for Unified Security Exposure Management AI agents included with the application are activated by default.
* If required, you can add a trigger to invoke the agentic workflow automatically.
* See [Configure an agentic workflow](https://www.servicenow.com/docs/Wq5AfS7BIz3Z1fKcpqiZeg "You can configure agentic workflows from the AI Agent Studio, but you must duplicate them to modify settings. The USEM AI agents included with the application and used in the agentic workflows are activated by default and aren't editable.") for more information.
{#using-now-assist-ai-agents-vr__ul_x3c_vfh_m2c}

There might be AI agents installed on your instance that are not used in agentic workflows. To learn how to see all agents that are available to you, see [Find AI agents](https://www.servicenow.com/docs/access?context=find-ai-agents&version=zurich&pubname=zurich-intelligent-experiences&ft:locale=en-US).

