---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Bulk edit for false positive

# Bulk edit for false positive {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Use bulk edit to mark multiple vulnerable items (VITs) as false positive. If multiple VITs are selected, a remediation task is formed with these items.
Important:  
As an admin or analyst, you can use the bulk edit feature in the Vulnerability Manager Workspace to mark multiple VITs as false positive. For more information, see [Bulk edit for false positive in the Vulnerability Manager Workspace](https://servicenow-prod.fluidtopics.net/x~p_g0PPce1XvDT_s6bO8g "Mark one or more records (VITs, AVITs, CVITs, or TRs) as false positive concurrently using the bulk edit feature from the Vulnerability Manager Workspace instead of manually selecting each item.").

## Before you begin

Role required: remediation owner

Persona and granular roles are available to help you manage what users and groups can see and do in the Vulnerability Response application. For an initial assignment of the persona roles in Setup Assistant, see [Assign the Vulnerability Response persona roles using Setup Assistant](https://servicenow-prod.fluidtopics.net/msi8kaFkGNjyRib_XBHEzQ "Assign the Vulnerability Response persona roles to groups or users with Setup Assistant."). For more information about managing granular roles, see [Manage persona and granular roles for Vulnerability Response](https://servicenow-prod.fluidtopics.net/WeKNf9YHNMJmJIA6yCsRvA "After you complete your initial assignment of persona roles using Setup Assistant, manage additional granular role assignments to users or groups from the User Administration module in your instance.").

You can also request false positives in the classic environment:

## Procedure

1. Navigate to Vulnerability ResponseVulnerable ItemsAll and select the items you want to mark as false positive.  
   The selected items must be in Open, Under investigation, or Awaiting implementation state.
2. Click Bulk Edit.
3. On the form, fill in the fields.  
   {#bulk-edit-fp__table_vk2_jgc_hlb__entry__2}

   | Field | Description |
   |-|-|
   | Record selection | Records to be selected for bulk edit. |
   | State | State of the vulnerable items. Select Closed to mark as false positive. |
   | Reason | Substate for the State that was selected. If you selected Closed as the State, select False Positive here to mark as false positive. |
   | Unassign | Submit a request to clear the Assigned to and Assignment group fields. |
   | Preferred solution | Solution targeted for remediating all the vulnerable items selected for bulk edit. |
   | Assignment group | Assignment group for the VI. Select manually, or using Assignment Recommendations if it is enabled. |
   | Work notes | Notes to be added. |
   [Table 1. Vulnerable Item Bulk Edit form]

   {#bulk-edit-fp__table_vk2_jgc_hlb}
4. Click OK.  
   A new remediation task is created containing the selected VIs, and this task is sent for approval.
{#bulk-edit-fp__steps_y5m_sly_jlb}

*[\>]: and then


