Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Components installed with Configuration Compliance

Several types of components are installed with activation of the Configuration Compliance plugin, including tables and user roles.

Starting with v15.1.5 of Configuration Compliance, the most frequently used system properties are now accessible within the Configuration Compliance application. To view these system properties, navigate to AllConfiguration ComplianceProperties.

Note: The Application Files table lists the components that are installed with this application. For instructions on how to access this table, see Find components installed with an application.

Demo data is available for this feature.

Note: Starting with v14.9 of Configuration Compliance, the following terms have been renamed:

Terminology prior to v14.9Terminology v14.9 onwards
Test Result GroupRemediation Task
Group RulesRemediation Task Rules
PolicyTest group

View filtered lists for components installed with an application

Filter the Applications Files table so that only the roles, scheduled jobs, and tables that are installed with an application are displayed. The application you want to view these components for should be installed so that its files are loaded onto the instance and into the metadata table. Follow these steps to view filtered lists from the Applications Files table.

  1. In the filter navigator, enter sys_metadata.list to navigate to the metadata table.
  2. Select the condition builder (filter icon), and select, Application > is followed by the name of your application. For example, Application > is > Vulnerability Response.
  3. In the condition builder, to add a second filter, select AND, then select, Class > is a and choose one of the following classes from the list: Role, Scheduled job, or Table.
  4. Select Run.

The results for the class you selected are displayed in a filtered list.

Roles installed

Role title \[name\]DescriptionContains roles
Configuration Compliance administrator\[sn\_vulc.admin\]Able to modify application property, configuration, update rules, integrations of Configuration Compliance application. Starting with v15.0, an admin user cannot delete source records such as Expliots, CVEs, etc.sn_vulc.writeNote: Inherits the roles that are required for the administration of the records of the Configuration Compliance application.
read\[sn\_vulc.read\]Read lists and records in Configuration Compliance.Important: Starting with v24.0 of Vulnerability Response, the sn_vulc.read role has the privilege to access the Vulnerability Manager Workspace.- sn\_sec\_cmn.calc\_read - sn\_vul.view\_manager\_workspace
write\[sn\_vulc.write\]Write lists and records in Configuration Compliance.- sn\_vulc.read - sn\_vulc.remediation\_owner
write assignment\[sn\_vulc.write\_assignmentWrite to Test Result assignment fields.Contained in the sn\_vulc.remediation\_owner role.
remediation ownersn\_vulc.remediation\_ownerView and update permission for test results assigned to you or your group.Contained in the itil role. Contains: - sn\_sec\_cmn.read - sn\_vulc.write\_assignment - sn\_vul.view\_rem\_workspace
CC.Systemsn\_vulc.import\_adminRuns all scheduled jobs in configuration compliance application.Note: This user is the default run-as user for every scheduled job in configuration compliance.- sn\_vulc.write - import\_admin - sn\_vul\_tenable.read\_integration
VRCommon.Systemsn\_vul\_cmn.adminDefault run-as user for all scheduled jobs in Vulnerability Response common application.- sn\_vul\_cmn.write - sn\_sec\_cmn.admin - report\_admin
SecCommon.Systemsn\_sec\_cmn.adminDefault run-as user for all scheduled jobs which are used for the background jobs capability in Security support common application- sn\_sec\_cmn.int\_write - sn\_sec\_cmn.write - workflow\_admin - sn\_sec\_cmn.calc\_write - sn\_sec\_core.read\_dictionary - sn\_sec\_cmn.manage\_approval\_rules - sn\_sec\_int.admin - sn\_sec\_cmn.cap\_email\_write - sn\_sec\_cmn.manage\_classification\_rules - sn\_sec\_cmn.manage\_background\_job
V14.7: sn\_vulc.edit\_watch\_topicEdit watch topics for Configuration Compliance.sn\_vulc.read\_watch\_topic
V14.7: sn\_vulc.read\_watch\_topicRead watch topics for Configuration Compliance.cmdb\_read
V14.7: sn\_vulc.create\_watch\_topicCreate watch topics for Configuration Compliance.sn\_vulc.read\_watch\_topic
sn\_vulc.auditorAllow read for all configuration compliance modulessn\_vulc.read sn\_vulc.advanced\_read
sn\_vulc.advanced\_readAllow read for all the configuration compliance administration modulessn\_vulc.read\_auto\_close\_rules sn\_vulc.read\_exception\_configuration sn\_vulc.read\_assignment\_rules sn\_vulc.read\_task\_rules sn\_vulc.read\_auto\_exception\_rule sn\_vulc.read\_notifications sn\_vulc.read\_risk\_score\_configuration sn\_vulc.read\_test\_criticality\_mapping sn\_sec\_cmn.read\_approval\_rules sn\_vulc.read\_auto\_delete sn\_vulc.read\_remediation\_target\_rules
sn\_vulc.read\_test\_criticality\_mappingAllow read for test criticality mapping 
sn\_vulc.read\_task\_rulesAllow read for remediation task rules 
sn\_vulc.read\_assignment\_rulesAllow read for assignment rules 
sn\_vulc.read\_risk\_score\_configurationAllow read for risk score configuration 
sn\_vulc.read\_auto\_close\_rulesAllow read for auto close configuration 
sn\_vulc.false\_positive\_approverAllows approving /rejecting closing remediation tasks as false positivesn\_vul.view\_manager\_workspace
sn\_vulc.exception\_approverApproved or rejects exception requests.sn\_vul.view\_manager\_workspace
sn\_vulc.deleteDeletes source records. 

Scheduled jobs installed

Scheduled jobDescription
V15.0: Update test group on configuration testsUpdates test group on tests for Tenable and Microsoft Defender source. This is a one-time job.
V15.0: Populate existing test result fieldsUpdates values into newly added columns \(such as Age, Age closed, Active, etc\) in the test results table, saved filters and modules. This is a one-time job.
V15.0: Populate Vulnerable CIs table - Delete and Re-populate for Test ResultsPopulates total records in the Vulnerable CIs table. This is a one-time job.
Version 12.0 Calculate remediation metrics for all the test results groupsCalculates and updates values for status metrics on remediation task records.
Version 12.0: Calculate remediation metrics for all the test resultsCalculates and updates values for status metrics on test results records.
Version 12.0: Change Request State SynchronizationOn-demand job that synchronizes the states of all existing remediation tasks \(RTs\) with change requests \(CHGs\). As a change request moves through its life cycle, it also moves the states of any related remediation tasks automatically. Enables state synchronization going forward.
Version 11.1: Check Test Result Groups Deferment ExpirationSends notifications if remediation tasks have expired \(and if they expire in one week\).
Configuration Compliance CI countPopulates distinct configuration item \(CI\) count and the 90 day rolling average in the Configuration Item Count \[sn\_vulc\_cc\_configuration\_item\_count\] table.
Version 11.1: Evaluate and notify remediation targetsSets or updates remediation target dates on all test results. Determines the status of remediation target dates against rules. Sends notifications
V14.7: Insert Test Result Groups Into Unified Remediation TaskOne-time scheduled job to insert all the remediation tasks created in the classic UI into the Unified remediation task \(sn\_vul\_remediation\_task\).
Version 12.0: Populate CR-TRG m2m for CR and CR-ParentPopulates change requests on remediation tasks.
Removed in v11.1: Re-open deferred test result groupsNote: Deprecated for versions prior to 11.1. Do not use.Reopens deferred groups when the due-date has passed.
Reapply all assignment rulesReapplies all assignment rules.
Version 14.3: Reassignment count for assignment rulesRuns daily and posts the total number of test results and remediation tasks that are unassigned by this feature for a particular assignment rule.
Reassess the state of the test result groupsReassesses the state of remediation tasks for entries where assess_state is false. Runs every 15 minutes.
Rollup test result risk score to test result group and configuration testRuns hourly and calculates the rollup scores for the changed configuration tests and remediation tasks.- Calculates rollup risk score for all tests in sn\_vulc\_test\_manifest and deletes the manifest record upon completion. - Calculates the rollup risk score for all the tests in sn\_vulc\_result\_group\_manifest and deletes the manifest upon completion.
Version 12.0:Update policy remediation metricsStarting with v15.0 of Configuration Compliance, this scheduled job has been renamed to Update remediation metrics.- Calculates and updates values for status metrics on policy records. - Calculates test result compliance % of a CI on Discovered Item.
Version 14.3: Set deferral countsCollects the number of times a test result or a remediation task is deferred.
Update Risk Rating for Test ResultsUpdates Risk Rating for Test Results.
Update Rollup risk score for all non closed Result groups and Configuration tests.Updates the rollup risk score for all non-closed Result groups and Configuration Compliance tests.

Tables installed

TableDescription
Assignment Rule \[sn\_vulc\_assignment\_rule\]Contains the set of rules evaluated to set the assignment group on test results.
Authoritative Source \[sn\_vulc\_auth\_src\]Store imported authoritative sources.
Calculator \[sn\_vulc\_calculator\_risk\_score\]Contains the calculator that sets certain test result fields when certain conditions are met.
CC Configuration Item Count\[sn\_vulc\_cc\_configuration\_item\_count\]Contains the total number of configuration items.
Version 12.0: Change request association\[sn\_vulc\_action\_associate\_cr\]Staging table used for associating change requests to remediation tasks.
Version 12.0: Change request creation\[sn\_vulc\_action\_create\_cr\]Staging table used for creating change request forms.
Version 12.0: Change request form \[sn\_vulc\_cr\_form\]Base table for change request management.
Citation \[sn\_vulc\_citation\]Contains imported citations
Configuration Test \[sn\_vulc\_test\]Contains imported configuration test data.
Configuration test manifest \[sn\_vulc\_test\_manifest\]Contains the configurations tests for which the rollup risk score needs to be calculated.
Version 12.2 Missing asset table \[sn\_vul\_missing\_asset\]Contains temporary asset records for imported configuration compliance assessment data with unmatched assets.
Configuration Test Technology \[sn\_vulc\_test\_technology\]Contains imported configuration test technologies.
Remediation Task Rule\[sn\_vulc\_grouping\_rule\]Contains the rules that define the criteria with which groups are automatically created for a set of test results.
Test Groups \[sn\_vulc\_policy\]Contains imported policies.
Policy Configuration Test \[sn\_vulc\_policy\_test\]Contains imported policy configuration test data.
Remediation Target Rule \[sn\_vulc\_ttr\_rule\]Defines the expected time frame for remediating a test result.
Risk Calculators \[sn\_vulc\_calculator\_group\]Contains the grouping of Configuration Compliance calculators. The order of the calculator group determines which group is evaluated first, and in each group, one calculator at most is used.
Risk Score Rollup Calculator \[sn\_vulc\_risk\_score\_rollup\]Contains rollup calculator configurations.
Split remediation tasks \[sn\_vulc\_action\_split\_trg\]Staging table used for splitting remediation tasks.
State Change Approval \[sn\_vulc\_state\_change\_approval\]Contains approval state process data.
Technology \[sn\_vulc\_technology\]Contains imported technologies.
Test Criticality Map \[sn\_vulc\_test\_criticality\_map\]Contains criticality map data.
Test Result \[sn\_vulc\_result\]Contains imported test results.
Remediation Tasks \[sn\_vulc\_result\_group\]Contains imported remediation tasks.
Version 12.0:Remediation Task Change RequestsContains change requests for remediation tasks.
Remediation task manifest \[sn\_vulc\_result\_group\_manifest\]Contains the remediation tasks for which the rollup risk score needs to be calculated.
Remediation Tasks \[sn\_vulc\_m2m\_result\_result\_group\]Contains remediation task data.
Test Result History \[sn\_vulc\_result\_history\]Contains imported test result history.
Test Result Remediation StatusStatus of the test result against the closest applied remediation target rule.
V14.7: Watch Topic Test Counts\[sn\_vulc\_wt\_test\_counts\]Cache table for the Distinct Configuration Tests tab in the Vulnerability Manager workspace.