Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Define policy exception approval rules

Approval rules define the criteria (risk rating, policy or control objective) that is used for sending approval requests for an exception. Rules can be configured for an application and you can identify multiple levels of approvers, as needed.

Before you begin

Role required: sn_compliance.manager

About this task

You can configure approvals to be sent out automatically or manually after review.

Note: When policy exceptions are created from upstream applications (from Vulnerability Response for example), the policy exception must have impacted controls present before you can request approval.

For policy exceptions created using Policy and Compliance Management, exceptions can be requested for a policy without impacted controls being present, even if both policies and control objectives are added to the exception form. However, for policy exceptions created for control objectives alone, impacted controls must be present before you can request approval.

You can also use the GRC Approval Configurator to configure policy exception rules. For more information, see Define policy exception and extension rules.

Procedure

  1. Navigate to All > Policy and Compliance > Policy Exceptions > Approval Rule.

  2. Click New.

  3. On the form, fill in the fields.

    FieldDescription
    TypeDefaults to Approval Rule.
    NameEnter a name for this approval configuration.
    Short descriptionProvide a brief description of the purpose of the configuration.
    Source applicationSelect the application for that applies to this approval rule. Only applications that have been previously added to the Integration Registry are listed.
    ActiveIf this is selected, this approval rule is active.
    Risk ratingThe risk rating is determined by running a risk assessment on the policy exception.
    PolicySelect the policy against which this policy exception is being applied.
    Control objectiveSelect the control objective that references the selected policy.
    Auto-trigger approvalsSelect this check box to automatically trigger all approvals after the review is completed. If you do not select it, the compliance manager can manually trigger the approvals defined by this rule.
    OrderOrder defines the precedence of triggering this rule as compared to another rule that is applicable to the exception and defined with similar criteria.
  4. Click Update.

    The Approver Levels related list appears. This related list allows you to define multiple approver levels for a rule. One or more users, or a group of users can be selected as approvers for each level. Approvers must be assigned the survey_reader role. You can make it mandatory for all selected users to approve the exception or optionally allow a single user to approve on behalf of all approvers.

  5. Select New.

  6. On the form, fill in the fields.

FieldDescription
NameEnter a name for this approval level.
DescriptionProvide a brief description of the approval level.
Required approvalSelect One approval required to allow a single user to approve on behalf of all approvers.Select All users must approve to make it mandatory that all designated users approve the selection.
UsersSelect one or more users to act as policy exception approvers.
GroupsSelect one or more groups to act as policy exception approvers.Note: Users who belong to the group must have GRC business user (sn_grc.business_user) role.
OrderSelect the order to determine the sequence of levels used with respect to other levels \(that is, order 1 is displayed first\).
  1. Click Submit.

    If you selected the Auto-trigger approvals check box, the designated approvers are notified that their approvals are required. Alternatively, the approvers are notified when the compliance manager clicks the Send for Approval button.

Parent Topic:Allow policy exception requests from other applications