---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Create auto-close rules

# Create auto-close rules {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Use auto-close rules to close older detections automatically based on the filter conditions that you set.

## Before you begin

Role required: sn_vul.manage_auto_close_stale_vi

## Procedure

1. Navigate to AllVulnerability ResponseAdministrationAuto-Close Rules.  
   The base system provides the following auto-close rules:
   * Assets last scanned: Detections associated with assets that haven't been scanned within the last 90 days are transitioned to Stale state.
   * Manual detections last found: Manual detections that haven't been found within the last 90 days. If you activate Detections last found record, then this feature requires a successful integration run of Rapid7 Comprehensive Vulnerable Item Integrations and Microsoft TVM Machine Vulnerabilities Integration (Full import) within the last seven days.
   * Detections last found: Detections that haven't been found within the last 90 days.
   {#create-auto-close-rules__ul_ugw_flv_hbc}
2. Select New to create a new auto-close rule.
3. Fill in the fields on the form.  
   {#create-auto-close-rules__table_udn_y2q_fsb__entry__2}

   | Field | Value |
   |-|-|
   | Name | Name of the auto-close rule. |
   | Active | Option to activate the rule. If activated, it closes any detections automatically that match its filter criteria. |
   | Ignore deferred items | If selected, any detections that are mapped to the In-review or Deferred states are ignored and not closed. If you clear this option, any detections that match your criteria are closed. |
   | Execution order | Unique value for the execution of the auto-close rule. This value determines the order of execution. The default value is 100. |
   | Description | Description of the auto-close rule. |
   | Condition | Filter conditions used to identify detections that should be closed. |
   [ ]

   {#create-auto-close-rules__table_udn_y2q_fsb}
4. Select Submit.  
   The Auto-Close Stale Detections scheduled job runs daily. It identifies detections based on the specified conditions and transitions the matching ones to the Stale state. The job handles the following scenarios:
   * If all the detections within a vulnerable item (VIT) are marked as stale, the VIT is closed with the sub-state set as "Stale".
   * If there is at least one detection that remains open within a VIT, while others are in the Stale status, the VIT remains open.
   * In cases where there are detections with both "Closed" and "Stale" statuses within a VIT, the VIT is closed with the sub-state set as "Fixed".
   {#create-auto-close-rules__ul_iy4_1nv_hbc}

   When you upgrade to the latest version of Vulnerability Response, the conditions set in your auto-close rules also get updated accordingly. Additionally, if the rules are associated with different domains, the rules are created specifically within
   those domains.
{#create-auto-close-rules__steps_hxf_sxh_cbc}

*[\>]: and then


