Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Activity Definitions

The ServiceNow AI Platform provides a few activity definitions within the base system. In addition, for the playbooks that SIR Workspace base system, there are a few activity definitions defined in the base system under Enterprise Security Case Management PAD Commons application.

Role required: sn_si.admin.

Here’s the list of activity definitions that are a part of the base system:

Activity DefinitionTableDescriptionApplication
Wait For Condition with No ExperienceGlobal[global]Wait for Condition with no experienceEnterprise Security Case Management PAD Commons
Submit to CSF X SandboxSecurity Incident [sn_si_incident]Submit to sandboxEnterprise Security Case Management PAD Commons
Send EmailSecurity Incident [sn_si_incident]Send email activity for SIR playbooks.Enterprise Security Case Management PAD Commons
Search EmailSecurity Incident [sn_si_incident]Search emails on email serverEnterprise Security Case Management PAD Commons
Update Task StateSecurity Incident [sn_si_incident]Update the task stateEnterprise Security Case Management PAD Commons
Delete EmailSecurity Incident [sn_si_incident]Delete emailsEnterprise Security Case Management PAD Commons
Yes No OutcomeTask [task]Expected outcomeEnterprise Security Case Management PAD Commons

Parent Topic:Using SIR Workspace

Related topics

Working with Security Incident Records

Security Incident Playbook

Prerequisites for the Playbooks

Rebuilding existing playbooks in Workflow Studio

Sample Playbooks for SIR Workspace

Working with MSI Records

Working with Form UI actions

Security Incident Closure workflow

Handle security incidents using Advanced Work Assignment