---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Create auto-close rules

# Create auto-close rules {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Use auto-close rules to close older AVITs automatically based on the filter conditions that you set.

## Before you begin

Role required: sn_vul.app_manage_auto_close_rules

## Procedure

1. Navigate to AllApplication Vulnerability ResponseAdministrationAuto-close rules.  
   The base system provides the following auto-close rules:

   Application Vulnerabilities last scanned Vulnerabilities not reported within the last 90 days are transitioned to
   Stale state.
2. Select New to create a new auto-close rule.
3. Fill in the fields on the form.  
   {#avr-create-auto-close-rules__table_zhf_44w_pbc__entry__2}

   | Field | Value |
   |-|-|
   | Name | Name of the auto-close rule. |
   | Active | Option to activate the rule. If activated, it closes any detections automatically that match its filter criteria. |
   | Execution order | Unique value for the execution of the auto-close rule. This value determines the order of execution. The default value is 100. |
   | Integration type | Application Vulnerability Integration |
   | Description | Description of the auto-close rule. |
   | Condition | Filter conditions used to identify detections that should be closed. |
   [ ]

   {#avr-create-auto-close-rules__table_zhf_44w_pbc}
4. Select Submit.  
   The Auto-close Rules Processor scheduled job runs on a nightly basis. It identifies AVITs based on the specified conditions and transitions the matching ones to the Stale
   state. In cases where there are AVITs with both "Closed" and "Stale" statuses, the AVIT is closed with the sub-state set as Fixed.

*[\>]: and then


