Add an exception approver for Application Vulnerability Response
Add users to the approver groups so that you can request an exception.
Before you begin
Role required: sn_vul.app_exception_approver
About this task
An exception request for an application vulnerable item is approved using the default two-level approval flow. The request can be approved by two levels of approvers. Adding users to the first-level group is mandatory. If there are no users in the second level, the request is approved after the first-level approval.
Procedure
Navigate to All > User Administration > Groups.
In the Name column, search for Exception, and click Application Exception Approver - Level 1.
Note: Starting from Application Vulnerability Response v12.8.1, you can use the system properties provided in the base system for exception approvals via workflow in the System Properties [sys_properties] table. So, when an exception or false positive request is raised via workflow, it’s sent for approval to the group IDs defined in the system property. Navigate to All > System Properties and select sn_vul.app_exception_approver_L1, sn_vul.app_exception_approver_L2, or sn_vul.app_false_positive_approver_group to change the property value.
On the Group Application Exception Approver - Level 1 form, click the Group Members related list.
Click New to create a list.
On the form, fill in the fields.
| Field | Description |
|---|---|
| User ID | Unique identifier for the user. |
| First name | User's first name. |
| Last name | User's last name. |
| Title | User's job title. Enter a title or job description, or select one from the list. |
| Department | User's department. |
| Password | Password assigned to the user. This password can be permanent or temporary. |
| Password needs reset | Option to enable the user to reset the password to ensure security. |
| Locked out | Option to lock the user out of the instance and terminate all the user's active sessions. The system prevents users with the admin role from locking themselves out. |
| Active | Option to make this user active. Only you can see an inactive user in these areas:- Lists of users - Selection list on reference fields \(magnifying glass icon\) - Auto-complete list that appears when you type into a reference field |
| Web service access only | Option to designate this user as a non-interactive user. |
| Internal Integration User | Option to designate this user as an internal integration user. |
| User's email address. | |
| Language | User's preferred language. |
| Calendar integration | Calendar used to manage the work schedule. For example, Outlook. |
| Time zone | Time zone for this user's location. |
| Date format | User's preferred format for dates. |
| Business phone | User's business phone. |
| Mobile phone | User's mobile phone. |
| Photo | Photo that you can upload by clicking on Click to add.... |
Click Submit.
Repeat steps 1–5 to create an Application Exception Approver - Level 2.
The approver must navigate to Application Vulnerability Response > My Approvals and approve requests.
Parent Topic:Exception Management in Application Vulnerability Response