Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Inputs and triggers for Now Assist for Security Incident Response

You can configure some of the inputs or triggers for a generative AI skill. Inputs or triggers permit you to determine how and when a skill is used.

Inputs and triggers

Inputs identify the data used for a skill. Inputs include the table and fields used to generate a security incident summary. A trigger initiates an action. For example, triggers determine when the system generates a summary.

You can modify inputs and triggers, but you can't modify a skill's data source. The data source contains the tables and fields that the skill relies on.

Security incident summarization skill

Inputs for the security incident summarization skill identify the table and fields used when a security incident summary is generated. The following table lists the inputs for the Security Incident summarization skill from the Choose Input page in the Now Assist Admin console.

InputDescription
Data sourceSecurity Incident \[sn\_si\_incident\] table.
Input fields- Short description - Description - State - Priority - Work notes - Additional comments
Related Input tables
  • Affected CIs - configuration item
  • Affected Users - Users
  • Security Incident Response Task - Short description
  • State - Any state other than Cancelled.
  • Associated Observables - Observable finding is Malicious or Suspicious.

Resolution notes generation skill

Inputs for the Resolution notes generation skill identify the table and fields that are used when the resolution notes are generated for a security incident. The following table lists the inputs for the resolution notes generation skill from the Choose Input page in the Now Assist Admin console.

InputDescription
Data sourceSecurity Incident \[sn\_si\_incident\] table.
Input fields- Short description - Description - Work notes - Additional comments
InputDescription
Data sourceSecurity Incident [sn_si_incident] table.

Post incident analysis generation skill

InputDescription
Data sourceSecurity Incident [sn_si_incident] table.

Correlation insights generation skill

Your correlation insights for a security incident can contain records from the following tables, but you must have permission to access these tables and records.

InputDescription
Data sourceSecurity Incident \[sn\_si\_incident\] table. Configuration item \[cmdb\_ci\] table. Incident \[incident\] table. Change request \[change\_request\] table. Problem \[problem\] table. Vulnerable item \[sn\_vul\_vulnerable\_item\] table. Associate observable \[sn\_ti\_observable\] table.