Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

SIR Workspace plugins

The following are the required applications to work with Security Incident Response Workspace (sn_si_aw) plugin.

Applications

Installing the Security Incident Response application version 13.4.5 or later automatically installs the Security Incident Response Workspace and the following apps.

  • Enterprise Security Case Management PAD Commons [sn_escm_pad_cmn]
  • Security Operations Common Workspace [sn_escm_ws_cmn]
  • Security Incident UI Card Component [sn_sirw_evam]
  • Security Operations spoke [sn_sec_spoke]

Important:

  • Installing the Security Incident Response 13.4.5 version or later from the ServiceNow Store automatically installs the Security Incident Response Workspace (sn_si_aw) 1.5.1 version or later by default.
  • The Security Incident Response Workspace versions 1.5.1 and above can only be installed/upgraded through an installation/upgradation of Security Incident Response and can’t be installed independently.

Enterprise Security Case Management PAD Commons requires the Playbook Experience [playbook_experience] plugin.

For information on the Security Incident Response roles, tables, properties, and scheduled jobs, see Components installed with Security Incident Response.

Parent Topic:Exploring SIR Workspace

Related topics

SIR Workspace features

SIR Workspace interface overview

Upcoming section

Quick links section

Shift Handover Records section

List view in SIR Workspace