---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Defining Approval Rule for Inbound Intel

# Defining Approval Rule for Inbound Intel {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Define approval rules to control whether certain profiles or groups require approval before processing the inbound intelligence.

## Before you begin

Role required: sn_sec_tisc.admin

## Procedure

1. Navigate to WorkspacesThreat Intelligence Security Center.
2. Select Administration icon on the workspace.
3. Go to Inbound Intel Sharing.
4. Select Approval Rule for Inbound Intelligence.  
   Note:  
   Within the base system, the Approval Rule for Inbound Intelligence is the default rule provisioned to activate the approval workflow.
5. On the approval rule form, enter at least one user or user group in each of the following sections:
   1. Select profile or group for approval: Under this section, select the Inbound Intel sharing profiles or Inbound intelligence sharing groups that requires approval for processing the inbound intelligence data.
   2. Select approver(s): Under this section, select the users or groups that are required to approve the inbound intelligence records received from the profiles/groups configured earlier.
   {#tisc-approval-inbound-intel__substeps_my2_yxd_mfc}
6. Select Enable button to enable the approval rule for the Inbound Intel.  
   Note:  
   * Once enabled, any applicable Inbound Intel record will be routed to the approval queue.
   * One or more assigned approvers review the changes made by the analyst and choose to either approve or reject the request.
   * After a decision is made, an email notification is sent to email addresses as configured in the corresponding inbound intelligence sharing profile, indicating whether the record has been approved or rejected.
   {#tisc-approval-inbound-intel__ul_vpr_gyd_mfc}
{#tisc-approval-inbound-intel__steps_uww_fxd_mfc}
**Related tasks**   

* [Configuring Inbound Intel Sharing Profiles](https://servicenow-prod.fluidtopics.net/u6zdRpUiMttYYKNStqn3zg "This section describes the inbound intelligence sharing profiles used to receive intelligence from external organizations into TISC.")
* [Configuring Inbound Intel Sharing Groups](https://servicenow-prod.fluidtopics.net/LiUOfAcmLVTMwFDwv7oo0w "Inbound Intel Sharing Groups enable administrators to group similar inbound intelligence sharing profiles together. These groups can be used to define approval rules that apply to all profiles within the group.")

*[\>]: and then


