---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Requesting and approving an exception

# Requesting and approving an exception {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

You can request to defer the remediation of a vulnerable item or remediation task for a
specified period. For example, as a remediation owner, you can request an exception if a patch is
not available for a machine. Approvers who have access can approve requests from other
users.

You can request exceptions from the Vulnerability Response
Workspaces. See [Request an exception in the IT Remediation Workspace](https://servicenow-prod.fluidtopics.net/u8048LRMppDaxV9c9jKGkg "Request an exception for the host vulnerable item (VIT), application vulnerable item (AVIT), container vulnerable item (CVIT) and remediation task (VUL, AVUL, CVUL, or CRG) from the IT Remediation Workspace.").

* [Request an exception for a vulnerable item](https://servicenow-prod.fluidtopics.net/_YIHqpqwOY2IQCxK1__W~A "Request an exception for a vulnerable item (VI) that can’t be remediated immediately. For example, as a remediation owner, you can request an exception if a patch isn’t available for a machine.")
* [Request an exception for a remediation task](https://servicenow-prod.fluidtopics.net/MDg6kcJ7ENh4TmYtvTRTuA "Request an exception to defer a remediation task for a specified period if it can’t be resolved immediately.")
* [Request a bulk exception](https://servicenow-prod.fluidtopics.net/SPouIPhYOe2I_fBFZ0oKhg "Use the bulk edit option to request an exception for multiple vulnerable items (VITs) instead of manually selecting each item.")

{#request-approve-exception__ul_zq3_3yw_llb}

You can also request policy exceptions using GRC: Policy and Compliance Management:

* Request an exception using GRC: Policy and Compliance Management
* Request a bulk exception using GRC: Policy and Compliance Management

{#request-approve-exception__ul_kgm_nmw_qlb}  
Note:  
Email notifications are sent at every stage of exception management, providing the status and
other details of a request. For example, when an exception is requested, the requester receives
an email confirming that the request is raised. The approver also receives an email stating that
an exception has been requested.

Starting from v21.0 of Vulnerability Response, you can configure the time frames for approving false positives and exceptions, along with email notifications for both the approver and requester after a set number of days. When a request is raised, the vulnerable item changes to In-Review status and a state change record is created. If the approver doesn't respond within the configured time frame, the vulnerable item or remediation task reverts to Open status. The previous state is stored in the backup_state field. For more information, see [Configure approval rules for Exception Management](https://servicenow-prod.fluidtopics.net/2qnBR86wWLeVhdcl7TH_5w "Starting with Vulnerability Response v15.0, use the flow designer to approve exception requests for exception management, exception rules, and false positive management. If you are deploying Vulnerability Response (VR) for the first time, the flow designer is enabled by default.").

