---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Requesting and approving an exception in Container Vulnerability Response

# Requesting and approving an exception in Container Vulnerability Response {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

You can request to defer the remediation of a container vulnerable item (CVIT) for a specified period. For example, as a developer, you can request an exception if a patch is not available for a machine. Approvers who have
access can approve requests from other users.

To request or approve an exception, see:

* [Request an exception for a container vulnerable item](https://servicenow-prod.fluidtopics.net/JBWuOFo_N_x2HxYJvyC3Eg "Request an exception for a container vulnerable item (CVIT) that can’t be remediated immediately. For example, as a remediation owner, you can request an exception if a patch isn’t available for a machine.")
* [Request an exception for container vulnerabilities using GRC: Policy and Compliance Management](https://servicenow-prod.fluidtopics.net/JDUOE6xI2ytqp3mZBlfJig "Request policy exceptions using the GRC policy exception management capability in the Policy and Compliance Management application from within Container Vulnerability Response.")

{#cvr-request-approve-exception__ul_zq3_3yw_llb}  
Note:  
Email notifications are sent at every stage of exception management, providing the status and other details of a request. For example, when an exception is requested, the requester receives an email confirming that the request is raised.
The approver also receives an email stating that an exception has been requested. Starting from v2.5 of Container Vulnerability Response, you can configure the time frames for approving false positives and exceptions, along with email notifications for both the approver and requester after a set number of days. When a request is raised, the container vulnerable item changes to In-Review status and a state change record is created. If the approver doesn't respond within the configured time frame, the container vulnerable item or remediation task reverts to Open status. The previous state is stored in the backup_state field. For more information, see [Configure approval rules for Exception Management](https://servicenow-prod.fluidtopics.net/qvv6l_fxbZqG1_9uq7zGqw "Starting with Vulnerability Response v15.0, use the flow designer to approve exception requests for exception management, exception rules, and false positive management. If you are deploying Vulnerability Response (VR) for the first time, the flow designer is enabled by default.").
* **[Request an exception for a container vulnerable item](https://servicenow-prod.fluidtopics.net/JBWuOFo_N_x2HxYJvyC3Eg)**   
  Request an exception for a container vulnerable item (CVIT) that can't be remediated immediately. For example, as a remediation owner, you can request an exception if a patch isn't available for a machine.
* **[Request an exception for a container remediation task](https://servicenow-prod.fluidtopics.net/d3TImN5rS1~DH38LdlBArA)**   
  Request an exception to defer a container remediation task for a specified period if it can't be resolved immediately.
* **[Request an exception for container vulnerabilities using GRC: Policy and Compliance Management](https://servicenow-prod.fluidtopics.net/JDUOE6xI2ytqp3mZBlfJig)**   
  Request policy exceptions using the GRC policy exception management capability in the Policy and Compliance Management application from within Container Vulnerability Response.
* **[Define a policy reason mapping](https://servicenow-prod.fluidtopics.net/GqR9txt8GlzWjVSPendUoA)**   
  Define reason choices to be available to any user who requests an exception.
* **[Approve an exception request in Container Vulnerability Response](https://servicenow-prod.fluidtopics.net/xRL2L3nKrqZHDdPDNEqvSw)**   
  Approve exception requests for container vulnerable items or remediation tasks that can't be remediated immediately. You must assess these requests for risk and then approve them for deferral until they can be remediated.
* **[Defer a container vulnerable item in Container Vulnerability Response](https://servicenow-prod.fluidtopics.net/7LMq0WA35~FkwuSmrdAZAg)**   
  If you determine that the issue associated with a container vulnerable item (CVIT) is of low risk and can be immediately deferred without further analysis, you can use the Defer feature.
* **[Request an extension for a deferred container vulnerable item](https://servicenow-prod.fluidtopics.net/71IqED0tZhv~3R8p3~zHpQ)**   
  Request an extension for a deferred container vulnerable item before it reaches its deferred until due date. As a remediation owner, you're no longer required to wait until the deferred due date to make this request.

