---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Configure approval rules for Exception Management

# Configure approval rules for Exception Management {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Starting with Vulnerability Response v15.0, use the flow designer to approve exception requests for exception management, exception rules, and false positive management. If you are deploying Vulnerability Response (VR) for the first time, the flow designer is enabled by default.

## Before you begin

Role required: sn_vul.vulnerability_admin

## About this task

To use the flow designer, create rules using the Approval Rules module. Using this module, you can configure approval rules for each of the following exception management workflows.

* Exception request for remediation tasks
* Exception request for container vulnerable items
* Exception rule
* False positive for remediation tasks
* False positive for container vulnerable items
{#cvr-exception-mgt-approval-rules__ul_nmx_sfr_mqb} You can also define conditions containing multiple levels of approval within a rule. The flow designer automatically inherits the rules created in this module and processes the matching approval workflow.

## Procedure

1. Navigate to AllContainer Vulnerability ResponseAdministrationApproval Rules.
2. On the Approval Rules page, select the group for which you want to set the approval rule.
3. On the form, fill in the fields.  
   {#cvr-exception-mgt-approval-rules__table_imd_lrv_drb__entry__2}

   | Field | Description |
   |-|-|
   | Name | Approval configuration name. |
   | Table | Table on which the rule is applied. |
   | Application | Default value is Vulnerability Response. |
   | Rule type | Specifies the rule type. For example, exception management, false positive or exception rule. |
   | Active | Enabled by default, signifying that the approval rule is in use. |
   | Description | Short description of the approval rules. |
   | Approval expiry (days) Starting from v2.5 of Container Vulnerability Response | Date until when the approver can approve the request. |
   | Notify approver (days) Starting from v2.5 of Container Vulnerability Response | Date after which the approver is notified to take action. |
   [Table 1. Approval Rule form]

   {#cvr-exception-mgt-approval-rules__table_imd_lrv_drb}
4. Select Update.  
   In the Approval Configurations tab, there are two levels of approvers set up by default. You can select a rule to define the conditions based on different use cases within a rule. For more information, see [Create configurations for an approval rule](https://servicenow-prod.fluidtopics.net/8ysmbKFeJ4XDD6vm1E4UAg "Define the conditions to filter out matching vulnerable items, remediation tasks, or exception rules for an approval level.").  
   Note:  
   In each configuration page, you can create multiple approval levels. For more information, see [Create approval levels for Exception Management](https://servicenow-prod.fluidtopics.net/IUlroXRX3pvoNdsNnWFJFw "Define the levels of users and user groups that are going to approve the exception requests.").

## Example

Based on different use cases, you can define different approval processes for the same vulnerabilities found on different configuration items.

*[\>]: and then


