Problem
Security operations on ServiceNow needed AI-assisted threat triage, but the security team had strict data classification rules forbidding sensitive payloads from leaving the network. They wanted ServiceNow-native UX, not a sidecar tool.
Solution
Certified ServiceNow Scoped App (x_1894980_ollama_0) that orchestrates between local Ollama (sensitive data) and approved cloud LLMs (sanitized data) via the MID Server. Includes ATF test suite, Flow Designer automations for triage routing, and RBAC for who can use which model on which classification level.
Outcome
Security team gained AI assistance without violating data residency policies. The hybrid model became a template for other regulated departments looking at AI adoption inside ServiceNow.
