---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Create an approval group

# Create an approval group {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Create an approval group for the McAfee ePO for Security Operations integration that can approve requests for isolating host machines, restoring them to the network.

## Before you begin

You can't reassign the approval authority to a group, unless an approval group is available in your instance.  
Note:  
The approvals option in the [Configure settings](https://servicenow-prod.fluidtopics.net/gXWSrQWap~UEfHVn_Tkg1Q "After you create a profile and select the McAfee ePO capabilities that you want the profile to run, configure the settings so that the profile is invoked only under the specific conditions that you define.") appears only for Isolate Host and Remove Host Isolation capabilities.

Role required: ServiceNow AI Platform® Security incident administrator (sn_si.admin)

## About this task

Approval requests submitted by the security incident analyst to isolate host machines and remove isolation are assigned to the user with the sn_si.admin role by default. As a user with this role, you can reassign this
approval authority during the configuration step for a profile. Before you can reassign authority to an approval group, an approval group must be available on the Groups list in your ServiceNow AI Platform instance.

## Procedure

1. Navigate to AllUser AdministrationGroups.
2. In the groups list, click New.
3. On the form, fill in the fields.  
   {#create-approval-group-mcafee__table_qrc_tvh_fyb__entry__2}

   | Field | Description |
   |-|-|
   | Name | Name of the group that is displayed when an approval request is submitted, for example, <kbd class="ph userinput">Approvers McAfee host isolation</kbd>. |
   | Group email | Group email distribution list or the email address of the point of contact, such as the group manager, <kbd class="ph userinput">McAfeeapproval@servicenow</kbd>.com |
   | Manager | Name of group manager. Click the search icon to view the list. |
   | Parent | (Optional) Other group of which this group is a member, if this group has a parent. |
   | Description | Additional information about this group. |
   | Include members | Option to include members to this group. |
   | Default assignee | Option to choose a user as default assignee for this group. Use the Search option to open the list of users. |
   | Roles | Option to select the roles for this group. Use the Add and Remove option to add and remove roles. |
   | Type | Option to choose a category for this group. Use the Search option to open the list of group types. |
   | Vendors | Option to choose a vendor for this group. Use the Search option to open the list of vendors. |
   [Table 1. Approval group form]

   {#create-approval-group-mcafee__table_qrc_tvh_fyb}
4. Click Submit.  
   The new group is displayed in the Groups list.

   This group is available to process requests when you enable the Require approval option during the configuration of this profile.

   To
   monitor and process requests submitted by users with the sn_si.analyst role, each member of the approval group navigates to My Approvals tab in the ServiceNow AI Platform.
**Previous topic:** [Edit security tags in the ServiceNow AI Platform for the McAfee ePO integration](https://servicenow-prod.fluidtopics.net/t7yjTKU86iIWWMRdYA4o7Q "As part of the setup for the integration, edit the security tag names that you created in your McAfee ePO console in your ServiceNow AI Platform instance. Edit the tag names in your ServiceNow AI Platform instance so that they match the names of the tags in your McAfee ePO console.")  
**Next topic:** [McAfee ePO integration capability profiles](https://servicenow-prod.fluidtopics.net/KmuSjd1MW7GTkaPslRhOSQ "As a user with the security incident administrator (sn_si.admin) role, you create profiles for the McAfee ePO capabilities in your ServiceNow AI Platform instance. You group queries or actions in profiles and determine which McAfee ePO capabilities you want to run when a new security incident is created.")

*[\>]: and then


