---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Approval recommendations using generative AI

# Approval recommendations using generative AI {#ariaid-title1}

* Release version: Australia
* 
* Updated May 26, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Approval recommendations using generative AI

The Approval Recommendation generative AI skill in ServiceNow's Vulnerability Response streamlines the approval process for exception and false positive requests.
It helps approvers make faster, more consistent decisions by reducing manual analysis efforts.
These requests typically involve findings---vulnerabilities detected on assets---that may not require immediate remediation, such as false positives or cases where fixes are pending.
Users submit exception requests to defer remediation or mark findings as false positives, which often require multiple levels of review and can be time-consuming.
Show full answer Show less  

## Key Features

* **AI-driven recommendations:** Provides approvers with approval or rejection suggestions, confidence scores, and supporting reasoning to facilitate decision-making.
* **Data-driven insights:** Considers historical approval data, questionnaire responses (if enabled), previous approval comments, and general request details such as risk rating, remediation status, assignment group, and justification notes.
* **Asset and vulnerability context:** Utilizes detailed information from Configuration Item (CI) records, container and application vulnerability data, and configuration compliance test results to inform recommendations.
* **Multi-level approval support:** Incorporates comments from earlier approval stages to refine recommendations at subsequent levels.

## Sources and Input Parameters

The AI skill analyzes data from various ServiceNow tables, including:

* **Change Approval \[snsecexceptionchangeapproval\]:** Tracks historical approval outcomes, comments, and general request metadata.
* **Questionnaire responses \[snsmartasmtquestioninstance\]:** Optional input from remediation owner questionnaires.
* **Asset details:** Host, container, and application configuration items with business criticality, environment, and exposure status.
* **Vulnerability details:** Severity, CVSS scores, exploit status, preferred solutions, and other metrics across hosts, containers, applications, and configuration compliance.

## Benefits for ServiceNow Customers

* **Accelerates approval workflows:** Automates recommendation generation to reduce delays in exception and false positive approvals.
* **Improves decision quality:** Uses comprehensive data and historical patterns to provide consistent and well-supported recommendations.
* **Reduces manual effort:** Minimizes the need for extensive manual analysis by approvers.
* **Enhances security exposure management:** Integrates seamlessly within the Security Exposure Management Workspace to support effective vulnerability handling.

## Next Steps

ServiceNow customers can enable and invoke the Approval Recommendation generative AI skill to start receiving AI-driven approval suggestions directly on approval request records. This feature supports more efficient and accurate exception management in Vulnerability Response.  
Learn more about the how the Approval Recommendation generative AI skill arrives at its approval recommendations and the sources it uses to generate them.

## Overview for the Approval Recommendation skill {#now-assist-vr-generating-approvals__section_ocm_wbr_s3c}

The Approval Recommendation generative AI skill provides exception and false positive approvers in Vulnerability Response with recommendations to help them make faster, more consistent decisions while reducing manual analysis effort.

A finding (vulnerable item) is a vulnerability detected on an asset. Some findings don't require immediate remediation, for example, false positives or cases where a fix isn't yet available. From these types of findings and
remediation tasks, users submit exception requests and ask for approval to defer remediation or indicate that a finding is a false positive. Users can request to defer the remediation of a finding or remediation task for a specified
period.

For example, an analyst might request a deferral for a finding that will be fixed with an upcoming patch
that isn't currently available. A false positive might be a warning given by a scanner that is not actually an issue, for example, if a configuration item has been decommissioned but the scanner is still raising there is issue
related to it.  
In some cases, the approval requests for these exceptions and false positives require multiple levels or review and approval and can be quite time consuming. The Approval Recommendation AI skill can help locate historical, asset, and vulnerability details for exception and false positive requests and provide approvers with the following information:

* A recommendation to approve or reject the request.
* A confidence score.
* Supporting reasoning.
{#now-assist-vr-generating-approvals__ul_qzg_rfr_s3c}

## Sources and input parameters used for the recommendations {#now-assist-vr-generating-approvals__section_uyy_yfr_s3c}

The Approval Recommendation generative AI skill considers information from following tables, data sources, and information to arrive at its approval recommendations.

* See the following table for asset (configuration item) and vulnerability details.
* Historical Approval data - Count totals for how many times similar request types for false positives and deferrals from a finding type (VIT, CVIT, AVIT, CTR) have been approved or rejected on records on the Change Approval \[sn_sec_exception_change_approval\] table.
* Questionnaire responses (optional configuration) - If questionnaires are activated and available for exception requests, the questions and the remediation owner's answers are considered from records on the \[sn_smart_asmt_question_instance\] table. If questionnaires are not activated, this data is not considered.
* Comments (justifications) from previous approvals - If multiple approval levels are configured, comments provided by approvers at earlier levels on records on the Change Approval \[sn_sec_exception_change_approval\] table are considered when generating a recommendation at the next level.
* General request details - The following fields on records on the Change Approval \[sn_sec_exception_change_approval\] table are considered:
  * Risk rating
  * Until date (how long the exception is being requested for)
  * Remediation status (in-flight, no target)
  * Assignment group
  * Reason / justification notes (why a request is submitted)
  * Work notes
  * Request type
  * Compensating control (if available)
  {#now-assist-vr-generating-approvals__ul_cxd_4zx_s3c}
{#now-assist-vr-generating-approvals__ul_nxb_kgr_s3c}

## Asset and Vulnerability details {#now-assist-vr-generating-approvals__section_pky_y3r_s3c}

{#now-assist-vr-generating-approvals__table_yls_f1y_s3c__entry__3}

| Application | Source table | Description |
|-|-|-|
| Vulnerability Response (Host) | Configuration item (CI) \[cmdb_ci\] table records for Host assets | Total number of assets, business criticality, environment, internet-facing, and external-facing status. |
| Container Vulnerability Response (CVR) | Discovered Item (Container) \[sn_vul_container_image\] table records for Container assets | Total number of assets, business criticality, environment, internet-facing, and external-facing status status. |
| Application Vulnerability Response (AVR) | Discovered Item (Application) \[sn_vul_app_release\] records for Application Vulnerability Response | Total number of applications, business criticality, active/inactive status. |
| Configuration Compliance CC | Test Results \[sn_vulc_result\] table for Configuration Compliance | Total number of assets, business criticality, environment, internet-facing, and external-facing status status. |
[Table 1. Asset (configuration item) details]

{#now-assist-vr-generating-approvals__table_yls_f1y_s3c} {#now-assist-vr-generating-approvals__table_o1m_4xx_s3c__entry__2}

| Application | Vulnerability details |
|-|-|
| Vulnerability Response (Host VR) | Total counts of vulnerabilities, normalized severity, CVSS scores, CISA exists, active exploit, preferred solution, EPSS percentile. |
| Container Vulnerability Response (CVR) | Total counts of container vulnerabilities, normalized severity, CVSS scores, CISA exists, active exploit, preferred solution, EPSS percentile. |
| Application Vulnerability Response (AVR) | Total counts of application vulnerabilities, normalized severity, CVSS scores, active exploit, preferred solution, EPSS percentile, and if threat exists. |
| Configuration Compliance (CC) | Test result data is used instead of vulnerability data. Total counts of tests, test source category, test subcategory, criticality, and technology. |
[Table 2. Vulnerability details]

{#now-assist-vr-generating-approvals__table_o1m_4xx_s3c}

The Approval Recommendation generative AI skill provides its suggestions and is visible on approval request records (CA)s. For more information about how to invoke the agent and get the recommendations, see [Generate approval recommendations with generative AI](https://servicenow-prod.fluidtopics.net/iRw~v9uImTG3FT_GIH_xAA "Use a generative AI skill to streamline the approval process for exceptions and false positive requests with AI-driven recommendations. Reduce manual effort and improve decision accuracy for your approvers in the Security Exposure Management Workspace.").
* **[Generate approval recommendations with generative AI](https://servicenow-prod.fluidtopics.net/iRw~v9uImTG3FT_GIH_xAA)**   
  Use a generative AI skill to streamline the approval process for exceptions and false positive requests with AI-driven recommendations. Reduce manual effort and improve decision accuracy for your approvers in the Security Exposure Management Workspace.

