Skip to content
Release: Australia · Updated: 2026-05-18 · Official documentation · View source

Inputs and triggers for Now Assist for Threat Intelligence Security Center

You can configure some of the inputs or triggers for a generative AI skill. Inputs or triggers permit you to determine how and when a skill is used.

Inputs and triggers

Inputs identify the data used for a skill. Inputs include the table and fields used to generate a threat case summary. A trigger initiates an action. For example, triggers determine when the system generates a summary.

You can modify inputs and triggers, but you can't modify a skill's data source. The data source contains the tables and fields that the skill relies on.

Case Summarization skill

Inputs for the Case Summarization skill identify the table and fields used when a threat case summary is generated. The following table lists the inputs for the Case Summarization skill from the Choose Input page in the Now Assist Admin console.

InputDescription
Data sourceCase \[sn\_sec\_tisc\_case\] table.
Input fields- Short description - Description - State - Priority - Work notes - Automation Activity - Case Type - Notes - Analysis and Findings - Contributors - TLP - Recommendations or Actions - Due date - Updated - Closure Summary \(available when the case is in a closed state\)
Related Input tables- MITRE Techniques - Related Observables - Related Indicators - Related Objects - Affected Assets - Affected Services - Case Task