---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Edit a tag

# Edit the start and completion tag names and colors {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

You may prefer to edit the names and colors of the start and complete tags for the
initiate malware scan and isolate host capabilities. The start and complete tags help you
quickly identify which capabilities are invoked from ServiceNow AI Platform
Security Incident Response (SIR) security
incidents.

## Before you begin

Role required: sn_si.admin

## About this task

As a user with the sn_si.admin role, you may prefer to edit the colors and names of
the security tags that are displayed on SIR security
incidents. You may also assign tags to security tag groups to help you organize them
in your ServiceNow AI Platform® instance. For example, you can change the
colors of tags so the start tag of a capability is one color, and the completion tag
is another color. These different colors can help you quickly identify when scans
start and are successfully completed. For more information on how to set up security
tag groups and tags, see [Set up security tag groups and tags](https://servicenow-prod.fluidtopics.net/bus9vK7pliypx82WYkj9OQ "You can assign tags to security incidents, response tasks, vulnerable items, observables, IoCs, and security cases to create metadata on the responding record and define who should have access to specific types of security content. The tags can be added to security groups to organize them.").

## Procedure

1. To edit the names and colors of the security tags, navigate to McAfee EPO Capabilities, and, in the Name column, select an item in the list.  
   The record for the capability is displayed.
2. To edit a tag, to the right of a tag name, select the information icon, and open the tag record.  

   In the record that is displayed, edit the fields.

   | Field | Description |
   | Name | Enter a name for the security tag. |
   | Color | Security tag color. Select a color from the choice list. |
   | Security Tag Group | Enter a name of the security tag group. Click the information icon to view the available groups. Default is Metatag group. |
   | Enforce restricted access | Select this check box to assign read and write roles needed by users to read or write to records that have this security tag. Default is cleared. |
   | Order | Specify the order the tag appears on forms or within a list. Default is 100. To set the order on the list, enter a value. For example, 100, 200, 300, 400. The tag with the lowest the number is displayed first on the list. The profile with the highest number is displayed last. |
   | Active | Turn the tag on or off. |
   | Description | A description for the tag. |
   |-|-|

   {#mcafee-epo-edit-security-tag__choicetable_ohy_xpv_bgb}
3. Choose one to continue.

   | Option | Description |
   | Update | Update the page with new changes. |
   | Delete | Delete this tag record from the McAfee ePO capability. |
   |-|-|

   {#mcafee-epo-edit-security-tag__choicetable_xtw_hfp_z2b}
**Previous topic:** [Test security incidents and approve requests for the isolate host](https://servicenow-prod.fluidtopics.net/UMixk4nABVwyyt2n67pWyQ "The test and preview step permits you to validate that the host isolation and remove host isolation workflow results are returned as expected for the profile.")  
**Next topic:** [McAfee ESM - Email Parser integration](https://servicenow-prod.fluidtopics.net/t8po573AiJAv9ussOn6YpA "The ESM - Email Parser integration is supported by an email parser that consumes email notifications from ESM to create security incidents.")

