Configure the Security incident resolution plan skill
Add your existing runbooks to the resolution plan generation skill. The runbooks provide additional context to the resolution plan generation skill.
Before you begin
Role required: sn_si.admin
About this task
Important: This generative AI skill is turned on by default. The skill will be automatically available to appropriate role users for the application. For more information, see Now Assist skills, agents, and agentic workflows on by default.
Procedure
Navigate to All > Now Assist Admin > Skills.
In Technology, select Security Operations.
The Now Assist skills for Security Operations page displays the list of available skills.
In the Security Incident resolution plan tile, select
More actions icon.
Select Edit.
Select Add AI Runbooks.
In the Additional Runbook Context page, select Add.
In Condition, enter a condition when the skill must reference the runbook.
For example, set the condition as
If category is Phishing and affected user VIP status is true.In Choose KB Reference, select a knowledge base article runbook.
In Order, set an order of importance.
You can set Order to any positive integer, a lower value indicating a higher priority.
Select Save and continue.