Defining Approval Rule for Outbound Intel

  • Freigeben Version: Australia
  • Aktualisiert 12. März 2026
  • 1 Minute Lesedauer
  • Define approval rules to control whether certain users require approval before sharing the shared intelligence.

    Vorbereitungen

    Role required: sn_sec_tisc.admin

    You can configure approval rules on the Outbound Intel record. These rules determine if a sharing requires approval based on the user roles or other criteria.

    Prozedur

    1. Navigate to Workspaces > Threat Intelligence Security Center.
    2. Click on Administration icon on the workspace.
    3. Go to Outbound Intel Sharing.
    4. Select Approval Rule for Outbound Intel.
      Hinweis:
      Within the base system, the Approval Rule for Outbound Intelligence is the default rule provisioned within the base system to activate the approval workflow.

      The approval rule is applicable to only on-demand outbound intelligence sharing. For more information on on-demand outbound intelligence, see. Configuring Outbound Intel Sharing Templates.

    5. On the approval rule form, enter at least one user or user group in each of the following sections:
      1. Select User or Groups requiring approval
      2. Select approver(s)
    6. Click on Enable button to enable the approval flow for the Inbound Intel.
      Hinweis:
      • Once enabled, any applicable Outbound Intel record will be routed to the approval queue.
      • The assigned approver(s) will review the changes made by the analyst and choose to either approve or reject the request.
      • After a decision is made, an email notification is sent to the user(s) or user group(s), indicating whether the record has been approved or rejected.