Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Edit the start and completion tag names and colors

You may prefer to edit the names and colors of the start and complete tags for the initiate malware scan and isolate host capabilities. The start and complete tags help you quickly identify which capabilities are invoked from ServiceNow AI Platform Security Incident Response (SIR) security incidents.

Before you begin

Role required: sn_si.admin

About this task

As a user with the sn_si.admin role, you may prefer to edit the colors and names of the security tags that are displayed on SIR security incidents. You may also assign tags to security tag groups to help you organize them in your ServiceNow AI Platform® instance. For example, you can change the colors of tags so the start tag of a capability is one color, and the completion tag is another color. These different colors can help you quickly identify when scans start and are successfully completed. For more information on how to set up security tag groups and tags, see Set up security tag groups and tags.

Procedure

  1. To edit the names and colors of the security tags, navigate to McAfee EPO Capabilities, and, in the Name column, select an item in the list.

    The record for the capability is displayed.

  2. To edit a tag, to the right of a tag name, select the information icon, and open the tag record.

Image omitted: mcafee-edit-tag-im-5.png
Information icon highlighted.
In the record that is displayed, edit the fields.
FieldDescription
NameEnter a name for the security tag.
ColorSecurity tag color. Select a color from the choice list.
Security Tag GroupEnter a name of the security tag group. Click the information icon to view the available groups. Default is Metatag group.
Enforce restricted accessSelect this check box to assign read and write roles needed by users to read or write to records that have this security tag. Default is cleared.
OrderSpecify the order the tag appears on forms or within a list. Default is 100.To set the order on the list, enter a value. For example, 100, 200, 300, 400. The tag with the lowest the number is displayed first on the list. The profile with the highest number is displayed last.
ActiveTurn the tag on or off.
DescriptionA description for the tag.
  1. Choose one to continue.

    OptionDescription
    UpdateUpdate the page with new changes.
    DeleteDelete this tag record from the McAfee ePO capability.

Parent Topic:McAfee ePO integration

Previous topic:Test security incidents and approve requests for the isolate host

Next topic:McAfee ESM - Email Parser integration