Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Configuring Now Assist for Security Incident Response

The Now Assist for Security Incident Response application is supported in the Security Incident Response Workspace and in the legacy Core UI (UI16). Use the guided setup in the Now Assist Admin console to configure Now Assist for Security Incident Response.

Configuration overview

AI agents use role masking to determine which users can access them. Ones installed with Now Assist applications have specific roles that come included with the application. If you select Users with specific roles for user access, you must configure the security controls to include these roles. For the instructions to change the security controls, see Define security controls for an AI agent.

Important: Some generative AI skills, AI agents, and agentic workflows are turned on by default. For more information, see Now Assist skills, agents, and agentic workflows on by default.

By sharing data with the ServiceNow® AI development program, you provide relevant data to help improve prediction accuracy, user experience, tailor products to your business needs, and reduce hallucinations for your activated Now Assist skills.

You can opt out of a ServiceNow instance from sharing data from the Now Assist Admin console. See Opt out of data sharing for Now Assist. Repeat the opt-out process for all instances that use the Now Assist functionality.

Use the Now Assist Admin console to configure Now Assist for Security Incident Response. This console contains everything to install the applications and configure the generative AI skills. For additional information, see Configuring Now Assist Admin features.

Note: When you update the Now Assist for Security Incident Response applications, its dependency applications are automatically updated.

The following table lists the features and skills that you can access from the Now Assist Admin console.

Note: Depending on your license, you will have access to certain application features, generative AI skills, agentic workflows, and AI agents. For more information, see ServiceNow product tiers.

Now Assist Technology productSecurity incident skills
Now Assist for Security Incident ResponseSecurity incident summarizationNote: The incident summarization supports security incidents in any state other than Draft.
Resolution notes generation.
Security operations metrics analysis

Security incident recommended actionsThe security incident recommended actions skill supports security incidents in any state other than Closed and Cancelled.

Note:

The AI Search application must be enabled so that the Recommended Actions skill works for security incidents. To verify AI Search is enabled on your instance, navigate to All > AI Search > AI Search Status. Contact support if the page indicates that AI Search is not enabled.

Correlation insights support security incidents in all states.

Post-incident analysis
Generate content for shift handover
Security incident resolution plan
Security incident quality assessment
  1. Install Now Assist plugins.

    Install the Now Assist for Security Incident Response application (sn_sec_gen_ai) and Security Incident Response Core [sn_si] applications.

    Note:

    When you update the Now Assist for Security Incident Response application, its dependency applications are automatically updated.

  2. Configure a skill for Now Assist for Security Incident Response

    You can deactivate, configure, and reactivate generative AI skills and agentic workflows in the Guided Setup.