Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Add an exception approver for Application Vulnerability Response

Add users to the approver groups so that you can request an exception.

Before you begin

Role required: sn_vul.app_exception_approver

About this task

An exception request for an application vulnerable item is approved using the default two-level approval flow. The request can be approved by two levels of approvers. Adding users to the first-level group is mandatory. If there are no users in the second level, the request is approved after the first-level approval.

Procedure

  1. Navigate to All > User Administration > Groups.

  2. In the Name column, search for Exception, and click Application Exception Approver - Level 1.

    Note: Starting from Application Vulnerability Response v12.8.1, you can use the system properties provided in the base system for exception approvals via workflow in the System Properties [sys_properties] table. So, when an exception or false positive request is raised via workflow, it’s sent for approval to the group IDs defined in the system property. Navigate to All > System Properties and select sn_vul.app_exception_approver_L1, sn_vul.app_exception_approver_L2, or sn_vul.app_false_positive_approver_group to change the property value.

  3. On the Group Application Exception Approver - Level 1 form, click the Group Members related list.

  4. Click New to create a list.

  5. On the form, fill in the fields.

FieldDescription
User IDUnique identifier for the user.
First nameUser's first name.
Last nameUser's last name.
TitleUser's job title. Enter a title or job description, or select one from the list.
DepartmentUser's department.
PasswordPassword assigned to the user. This password can be permanent or temporary.
Password needs resetOption to enable the user to reset the password to ensure security.
Locked outOption to lock the user out of the instance and terminate all the user's active sessions. The system prevents users with the admin role from locking themselves out.
ActiveOption to make this user active. Only you can see an inactive user in these areas:- Lists of users - Selection list on reference fields \(magnifying glass icon\) - Auto-complete list that appears when you type into a reference field
Web service access onlyOption to designate this user as a non-interactive user.
Internal Integration UserOption to designate this user as an internal integration user.
EmailUser's email address.
LanguageUser's preferred language.
Calendar integrationCalendar used to manage the work schedule. For example, Outlook.
Time zoneTime zone for this user's location.
Date formatUser's preferred format for dates.
Business phoneUser's business phone.
Mobile phoneUser's mobile phone.
PhotoPhoto that you can upload by clicking on Click to add....
  1. Click Submit.

  2. Repeat steps 1–5 to create an Application Exception Approver - Level 2.

    The approver must navigate to Application Vulnerability Response > My Approvals and approve requests.

Parent Topic:Exception Management in Application Vulnerability Response