---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Create approval levels for Exception Management

# Create approval levels for Exception Management {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Define the levels of users and user groups that are going to approve the exception
requests.

## Before you begin

Role required: sn_vul.vulnerability_admin

## Procedure

1. Navigate to AllVulnerability ResponseAdministrationApproval Rules.
2. Select an approval rule and navigate to the Approval Configurations tab.
3. Select a configuration.
4. In the Approver Levels section, select an approver level.
5. On the form, fill in the fields.  
   {#exception-mgt-config-approval-rule__table_cn3_tmz_kqb__entry__2}

   | Field | Description |
   |-|-|
   | Name | Approval level name. |
   | Required approval | Select how many approvals are required for the selected level: * One approver required * All users must approve {#exception-mgt-config-approval-rule__ul_lm1_bpz_kqb} |
   | Active | Enabled by default, signifying that the approval level is in use. |
   | Order | Execution order of various configurations within a rule. For example, a configuration with an order entry of 100 runs before a configuration with an order entry of 200. |
   | Approval rule | Contains the table and type details for the approval rule. |
   | Approval configuration | Contains the approval configurations. |
   | Assign using | Select an option from: * User and user group * Approval table field * Script {#exception-mgt-config-approval-rule__ul_vg5_v4z_kqb} |
   | Groups | Approver level group consisting of multiple users. The user must have one of the following roles: * sn_vul.exception_approver: For exception management and exception rules * sn_vul.false_positive_approver: For false positive {#exception-mgt-config-approval-rule__ul_ax5_dc1_5qb} |
   | Users | Edit the users listed in the groups. |
   [Table 1. Approver Level form]

   {#exception-mgt-config-approval-rule__table_cn3_tmz_kqb}
6. To save the changes, select Update.  
   Note:  
   Prior to v15.0, the workflow process is functional if there are users only in Exception level 1. However, starting from v15.0, there must be at least one user in each level.

   Prior to v15.0, in the workflow, if there was no
   user in the second level, the vulnerability item or vulnerable group was
   deferred. However, v15.0 onwards, if there is no user in the second
   level, the approval request is automatically rejected.

## Example

There can be different approval levels for vulnerabilities for Linux and Windows
servers.

*[\>]: and then


