---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Marking and approving a false positive

# Marking and approving a false positive {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Vulnerable items (VIs) and remediation tasks (VULs) can be marked as false positives. Approvers with write access can approve such requests from other users.

* [Mark as a false positive](https://servicenow-prod.fluidtopics.net/6Pgd9ctqtcuGxxk0zw_S0g "Mark a vulnerable item (VI) or remediation task (VUL) as a false positive if the warning given by the scanner is not actually an issue. For example, if a configuration item has been decommissioned but the scanner is still raising an issue related to it, mark it as a false positive.")
* [Bulk edit for false positive](https://servicenow-prod.fluidtopics.net/qUvHbYpGtOL3t5_l~UDnzQ "Use bulk edit to mark multiple vulnerable items (VITs) as false positive. If multiple VITs are selected, a remediation task is formed with these items.")
* [Approve or reject a false positive](https://servicenow-prod.fluidtopics.net/GKzSRC8Og_PyfY8rgE~7xQ "As a false positive approver, you can approve or reject false positive requests from other users.")

{#request-approve-fp__ul_zq3_3yw_llb}  
Note:  
Email notifications are sent at every stage of the false positive workflow, providing the status and other details of a request. For example, when a VI or remediation task is marked as a false positive, the requester receives a
confirmation email. Simultaneously, the approver receives an email stating that a VI or remediation task has been marked as a false positive.

Starting from v21.0 of Vulnerability Response, you can configure the time frames for approving false positives and exceptions, along with email notifications for both the approver and requester after a set number of days. When a request is raised, the vulnerable item changes to In-Review status and a state change record is created. If the approver doesn't respond within the configured time frame, the vulnerable item or remediation task reverts to Open status. The previous state is stored in the backup_state field. For more information, see [Configure approval rules for Exception Management](https://servicenow-prod.fluidtopics.net/2qnBR86wWLeVhdcl7TH_5w "Starting with Vulnerability Response v15.0, use the flow designer to approve exception requests for exception management, exception rules, and false positive management. If you are deploying Vulnerability Response (VR) for the first time, the flow designer is enabled by default.").

