---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Defining Approval Rule for Outbound Intel

# Defining Approval Rule for Outbound Intel {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Define approval rules to control whether certain users require approval before sharing the shared intelligence.

## Before you begin

Role required: sn_sec_tisc.admin

You can configure approval rules on the Outbound Intel record. These rules determine if a sharing requires approval based on the user roles or other criteria.

## Procedure

1. Navigate to WorkspacesThreat Intelligence Security Center.
2. Click on Administration icon on the workspace.
3. Go to Outbound Intel Sharing.
4. Select Approval Rule for Outbound Intel.  
   Note:  
   Within the base system, the Approval Rule for Outbound Intelligence is the default rule provisioned within the base system to activate the approval workflow.

   The approval rule is applicable to only on-demand outbound intelligence sharing. For more information on on-demand outbound intelligence, see. [Configuring Outbound Intel Sharing Templates](https://servicenow-prod.fluidtopics.net/160U6adHmYOxO_VAdpfWAA "Outbound Intel Sharing Templates enable you to define and control the data shared externally from the Threat Intelligence Security Center (TISC).").
5. On the approval rule form, enter at least one user or user group in each of the following sections:
   1. Select User or Groups requiring approval
   2. Select approver(s)
   {#tisc-approval-outbound-intel__substeps_my2_yxd_mfc}
6. Click on Enable button to enable the approval flow for the Inbound Intel.  
   Note:  
   * Once enabled, any applicable Outbound Intel record will be routed to the approval queue.
   * The assigned approver(s) will review the changes made by the analyst and choose to either approve or reject the request.
   * After a decision is made, an email notification is sent to the user(s) or user group(s), indicating whether the record has been approved or rejected.
   {#tisc-approval-outbound-intel__ul_vpr_gyd_mfc}
{#tisc-approval-outbound-intel__steps_uww_fxd_mfc}
**Related tasks**   

* [Configuring Outbound Intel Sharing Controls](https://servicenow-prod.fluidtopics.net/1hZHuAm0zEGADdPfUVXaIg "Use this section to configure outbound sharing controls, which determine the entities enabled for intelligence sharing from TISC to external systems.")
* [Configuring Outbound Intel Data Exclusion Rule](https://servicenow-prod.fluidtopics.net/2d0fdgmQ6bqkYGvIbuuyug "Use this section to create exclusion rules, which can be configured by TISC admin to restrict sharing of records that match the defined criteria.")
* [Configuring Outbound Intel Sharing Profiles](https://servicenow-prod.fluidtopics.net/s7Ot22IjeEsnaEQo8k8U5Q "Use this section to create new Outbound Intelligence Profiles. The outbound intelligence profiles specify the endpoint details to which threat intelligence data is sent.")
* [Configuring Outbound Intel Sharing Groups](https://servicenow-prod.fluidtopics.net/991t1csl9sSEPta9MtviDg "Outbound Intel Sharing Groups allow you to combine multiple profiles and use them collectively when sharing data.")
* [Configuring Outbound Intel Sharing Templates](https://servicenow-prod.fluidtopics.net/160U6adHmYOxO_VAdpfWAA "Outbound Intel Sharing Templates enable you to define and control the data shared externally from the Threat Intelligence Security Center (TISC).")
* [Working on the Redaction Library](https://servicenow-prod.fluidtopics.net/I2Fnhq550Id7apaHgnUDHw "Redaction is the process of replacing sensitive information from shared data to protect confidentiality during intelligence sharing.")

*[\>]: and then


