> For the complete documentation index, see [llms.txt](https://developer.harness.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://developer.harness.io/security-testing-orchestration/use-sto/sto-exempt-issues/exemption-workflows.md).

# Request Issue Exemption

Issue exemptions help unblock pipelines by allowing security teams to temporarily bypass specific security issues that would otherwise fail the build. To understand how exemptions fit into your security workflow, refer to the [issue exemptions workflow](/security-testing-orchestration/use-sto/sto-exempt-issues/issue-exemption-workflow.md).

You can create exemption requests in three ways:

* [**Create exemption request for an issue**](#create-exemption-request-for-an-issue): Request an exemption for a single issue from the **Issue Details** pane. Set the exemption scope at the [Project](#where-do-you-want-this-issue-to-be-exempted), [Pipeline](#where-do-you-want-this-issue-to-be-exempted), or [Target](#where-do-you-want-this-issue-to-be-exempted) level.
* [**Create bulk exemption requests**](#create-bulk-exemption-requests): Select multiple issues on the **Vulnerabilities** tab and submit pending exemption requests for all selected issues using the same scope, duration, and reason.
* [**Create exemption request for occurrences within an issue**](#create-exemption-request-for-occurrences-within-issue): Request an exemption for selected occurrences of a single issue. The exemption scope is limited to the [Target](#where-do-you-want-this-issue-to-be-exempted) level.

Reviewers have the flexibility to approve exemption requests either at the requested scope or extend the scope to the **Organization** or **Account** level during the review process. For more details, refer to [Manage Issue Exemptions](/security-testing-orchestration/use-sto/sto-exempt-issues/manage-exemptions.md). To view submitted requests, refer to [View Issue Exemptions](#view-issue-exemptions).

{% embed url="<https://youtu.be/08OmKwva9DM>" %}

<figure><img src="/files/nHE3eSaVbqRu2KzGF8Tv" alt=""><figcaption><p>Click to view full-size image</p></figcaption></figure>

{% hint style="info" %}
To create an exemption request, you must have the necessary permissions (**Exemptions: View, Create/Edit**) at the Project level, or you can have the **Security Testing Developer** or **Security Testing AppSec** roles assigned. Refer [Permissions required for issue exemptions](/security-testing-orchestration/use-sto/sto-exempt-issues/issue-exemption-workflow.md#required-permissions-for-issue-exemptions) for more details.
{% endhint %}

### Create Exemption Request for an Issue <a href="#create-exemption-request-for-an-issue" id="create-exemption-request-for-an-issue"></a>

To request an exemption for an entire issue, you can set the exemption scope at the [Project](#where-do-you-want-this-issue-to-be-exempted), [Pipeline](#where-do-you-want-this-issue-to-be-exempted), or [Target](#where-do-you-want-this-issue-to-be-exempted) level. To begin, [navigate to the **Vulnerabilities** tab](/security-testing-orchestration/use-sto/sto-security-issues/view-scan-results.md#navigate-to-security-test-results).

1. In the **Vulnerabilities** tab, locate and select the specific issue for which you want to request an exemption. This action opens the **Issue Details** pane on the right.
2. In the **Issue Details** pane, click **Request Exemption**.

<figure><img src="/files/oj1bPAHcbxtleWimMR1D" alt=""><figcaption><p>Click to view full-size image</p></figcaption></figure>

#### Submit Exemption Request <a href="#submit-exemption-request" id="submit-exemption-request"></a>

Fill out the **Request Exemption for Issue** form with the following fields:

<figure><img src="/files/YJZmmnQXjRtEPAZg8uvC" alt=""><figcaption><p>Click to view full-size image</p></figcaption></figure>

**Where do you want this issue to be exempted?**

Specify where the exemption should apply:

* **This Target**: Exempts the issue only for the selected target. The issue remains reported in other targets or pipelines.
* **This Pipeline**: Exempts the issue only in the current pipeline. The issue is still reported in other pipelines or projects.
* **This Project**: Exempts the issue across all pipelines and targets within this project. Choose carefully, as the exemption applies broadly within the project.

{% hint style="info" %}

* While requests can only be created with the scopes mentioned above, reviewers can approve and apply them at the requested scope or at a higher scope - **Organization** or **Account**.
* As you create exemption request at the issue level, all the future occurrences part of this issues will be automatically exempted. For exemptions at occurrences level, refer to [Create Exemption Request for Occurrences within Issue](#create-exemption-request-for-occurrences-within-issue)
* **Behind Feature Flag**: If your pipeline includes Pipeline stages with child pipelines, an exemption request with the **Pipeline** scope will apply **only to the child pipeline**, not the parent pipeline.
  {% endhint %}

**For how long?**

Select the shortest practical time window for the exemption to limit the risk exposure. Alternatively, you can enter a **custom duration (in days)** to specify a specific time period for the exemption.

**Reason**

Select one of the following reasons and provide relevant details:

* **Compensating controls**: Your organization has controls (e.g., firewall, IPS) in place that reduce the risk posed by this issue.
* **Acceptable use**: The flagged practice is acceptable based on internal security policies.
* **Acceptable risk**: The risk is low, and remediation would require significant resources or impact functionality.
* **False positives**: The scanner flagged a non-issue. Confirmed by a security assessor or internal review.
* **Fix unavailable**: No known fix or remediation steps currently exist for the issue.
* **Other**: Provide a detailed technical explanation for why the issue should be exempted.

**Further Description**

Add any technical context, mitigations, or supporting information that will help the reviewer understand why the exemption is justified.

**URL Reference**

Add a link to supporting documentation, source code, or any relevant resource that provides additional context.

After completing the form, click **Create Request** to submit the exemption. Once the exemption request is submitted:

{% hint style="info" %}
Once submitted, the request enters the **Pending** state. You can [set up notifications](/security-testing-orchestration/use-sto/sto-set-notifications/exemption-notifications.md) to automatically alert reviewers of new requests.
{% endhint %}

#### Create Exemption Request for Occurrences within Issue <a href="#create-exemption-request-for-occurrences-within-issue" id="create-exemption-request-for-occurrences-within-issue"></a>

To request an exemption for selected occurrences of an issue, the exemption scope must be set to the [Target](#where-do-you-want-this-issue-to-be-exempted) level. To begin, [navigate to the **Vulnerabilities** tab](/security-testing-orchestration/use-sto/sto-security-issues/view-scan-results.md#navigate-to-security-test-results).

1. In the **Vulnerabilities** tab, locate and select the specific issue for which you want to request an exemption. This opens the **Issue Details** pane on the right.
2. In the **Issue Details** pane, click the **Occurrences** tab.
3. Select the occurrences for which you want to request the exemption.

<figure><img src="/files/hS7RswHeuEINphRNoorg" alt=""><figcaption><p>Click to view full-size image</p></figcaption></figure>

4. Review your selections and click the **Request Occurrence Exemption** button. This opens the **Request Exemption** dialog box.

<figure><img src="/files/CzT4BgpYIgsHJWyWM9iI" alt=""><figcaption><p>Click to view full-size image</p></figcaption></figure>

If you select **all** occurrences of the issue: - The option **Exempt all future occurrences discovered for this issue** at the bottom becomes available. Checking this option converts the request from an occurrence-level exemption to an issue-level exemption. This ensures all future occurrences of the issue will automatically be exempted. - If any occurrences in the list are already exempted, this option will be disabled to prevent conflicts. To enable it, cancel the existing exemption requests for those occurrences. Once done, select all occurrences again and recreate the exemption request, the option should now be available to check or uncheck.

Follow the steps in the [Submit Exemption Request](#submit-exemption-request) section to complete and submit your request.

***

### Create bulk exemption requests <a href="#create-bulk-exemption-requests" id="create-bulk-exemption-requests"></a>

{% hint style="info" %}
Bulk exemption requests are behind the feature flag `STO_ENABLE_BULK_EXEMPTION`. Contact [Harness Support](mailto:support@harness.io) to enable this feature.
{% endhint %}

You can create a bulk exemption request when multiple issues need the same exemption scope, duration, and reason. Harness creates a separate pending exemption request for each selected issue.

The **Vulnerabilities** tab displays issues in a flat table. The **Scan** column tags each issue based on how STO compared this scan to the reference scan:

* **Current scan:** The issue appears only in this scan.
* **Previous/Baseline scan:** The issue was also present in the baseline or previous scan.

STO uses the target baseline as the reference scan when one is defined. If no baseline exists, STO compares against the previous scan of the same variant. Go to [Targets, baselines, and variants in STO](/security-testing-orchestration/new-to-sto/key-concepts/targets-and-baselines.md) to define a baseline for each target.

The **Active Issues** summary card shows the same **Current scan** and **Previous/Baseline scan** counts. Use the **Scan** filter (**All**, **Current scan**, or **Previous/Baseline scan**) to narrow the list before you select issues for bulk exemption.

1. In the pipeline [**Vulnerabilities**](/security-testing-orchestration/use-sto/sto-security-issues/view-scan-results.md#navigate-to-security-test-results) tab, select the issues you want to exempt:
   * **Row checkboxes:** Select individual issues.
   * **Header checkbox:** Select all issues on the current page.
   * **Existing exemptions:** You cannot select an issue that already has an exemption. The row checkbox is disabled, and a tooltip on the checkbox shows **An exemption for this issue already exists**. When you use the header checkbox, issues with an existing exemption are excluded from the selection count.
2. Verify the yellow selection banner shows how many issues are selected, for example 'All 17 issues in this page are selected'.
3. Click **'Action'** on the top right, then select 'Request Exemption (17)' (the number matches your selection count).
4. Complete the **Request Exemption for Issue** form. Provide the scope, duration, reason, description, and URL reference you enter apply to every selected issue. Go to [Submit exemption request](#submit-exemption-request) for field descriptions.
5. Select 'Send Request' to submit a separate pending exemption request for each selected issue.

<figure><img src="/files/ji9H8PoC3PGCr6d5htzx" alt="Action menu on the Vulnerabilities tab with Request Exemption (19) highlighted"><figcaption><p>Open Request Exemption from the Action menu</p></figcaption></figure>

***

### Filters in Exemption Section <a href="#filters-in-exemption-section" id="filters-in-exemption-section"></a>

The Exemptions section offers various filters to help narrow down issues:

{% hint style="info" %}
Filters for Exemptions page are behind the feature flag `STO_EXEMPTION_FILTER`. Contact [Harness Support](mailto:support@harness.io) to enable the feature.
{% endhint %}

#### Issue Type <a href="#issue-type" id="issue-type"></a>

Filter issues by type. Multiple selections are allowed.

* SAST
* DAST
* SCA
* IaC
* Secret
* Misconfig
* Bug Smells
* Code Smells
* Code Coverage
* External Policy

#### Targets <a href="#targets" id="targets"></a>

Filter issues by target names. Multiple selections are allowed. The dropdown lists all targets scanned within the project.

#### Target Type <a href="#target-type" id="target-type"></a>

Filter issues by target type. Multiple selections are allowed.

* Repository
* Container
* Configuration
* Instance

#### Pipelines <a href="#pipelines" id="pipelines"></a>

Filter issues by pipeline names. Multiple selections are allowed. The dropdown lists all pipelines used in the project.

#### Scanner <a href="#scanner" id="scanner"></a>

Filter issues by scanner names. Multiple selections are allowed. The dropdown lists all scanners used in the project.

#### Severity <a href="#severity" id="severity"></a>

Filter issues by severity levels. Multiple selections are allowed.

* Critical
* High
* Medium
* Low
* Info

#### Requested By: <a href="#requested-by" id="requested-by"></a>

Filter issues by the user who submitted the Exemption request. Multiple selections are allowed.

#### Reason: <a href="#reason" id="reason"></a>

Filter by the reason for the Exemption request was submitted. Multiple selections are allowed.

#### Scope: <a href="#scope" id="scope"></a>

Filter the Exemptions based on scope (Target, Organization, Account, Pipeline, Project) of the request. Multiple selections are allowed.

### View Issue Exemptions <a href="#view-issue-exemptions" id="view-issue-exemptions"></a>

You can view all exemption requests from the **Exemptions** section in the left navigation. This section is accessible from your **Project**, **Organization**, and **Account** views. Each scope displays exemption requests relevant to that level:

* The [**Project-level Exemptions**](#view-exemptions-at-the-project-level) section shows requests submitted for that specific project.
* The [**Organization-level Exemptions**](#view-exemptions-at-the-organization-level) section shows requests across all projects within the organization.
* The [**Account-level Exemptions**](#view-exemptions-at-the-account-level) section lists requests across projects from multiple organizations under the account.

{% hint style="info" %}
Exemption requests list you see at the **Organization** and **Account** views are still subject to your project-level view permissions. Refer to [Permissions for exemption requests](/security-testing-orchestration/use-sto/sto-exempt-issues/issue-exemption-workflow.md#required-permissions-for-issue-exemptions) to learn more.
{% endhint %}

In the **Exemptions** sections, the requests are displayed in tabs presenting their status, each request in the **Pending** tab includes:

* **Severity**: e.g., High
* **Issue**: e.g., `json5@2.2.0: Prototype Pollution`
* **Scope**: Requested exemption scope – Project, Pipeline, or Target
* **Reason**: e.g., False Positive, Acceptable Use
* **Exemption Duration**: e.g., Exempted for all time
* **Requested by**: User who submitted the request
* **Actions**: Based on your permissions and request status - Approve, Reject, Cancel, Reopen

<figure><img src="/files/BMPQ6qnTqKiKsSgjAGxA" alt=""><figcaption><p>Click to view full-size image</p></figcaption></figure>

Here are the columns that are specific to status tab.

* **Pending**: Displays severity, issue, scope, reason, exemption duration, requested by, and action buttons such as *Approve*, *Reject*, or *Cancel*.
* **Approved**: Shows *Approved by*, *Time remaining*, *Approved at*, *Requested by*, with actions to *Reject* or *Cancel*.
* **Rejected**: Displays *Requested by*, *Rejected by*, and options to *Reopen*, or *Approve* and *Cancel*.
* **Expired**: Displays *Requested by*, with options to *Approve*, *Reopen*, or *Cancel*.

{% hint style="info" %}
For details on exemption request statuses and actions, refer [Exemption Request Lifecycle](/security-testing-orchestration/use-sto/sto-exempt-issues/manage-exemptions.md#issue-exemption-lifecycle). To learn how to manage requests, [refer Manage Issue Exemptions](/security-testing-orchestration/use-sto/sto-exempt-issues/manage-exemptions.md).
{% endhint %}

Clicking an exemption request opens the **Issue Details** pane. At the top right of the side panel, you'll see the **Exemption Status** button, which provides a complete overview of the request along with the actions available to you (based on your permissions).

<figure><img src="/files/53wN635Q2lo8QpiCGvHM" alt=""><figcaption><p>Click to view full-size image</p></figcaption></figure>

Clicking on the **Exemption Status** button shows:

* **Current Status:** Indicates the state of the request — `Pending`, `Approved`, `Rejected`.
* **Requested By:** Displays the user who created the exemption request and the relative time since it was submitted (e.g., `David · 7 days ago`).
* **Comments:** Displays the latest comment added by a reviewer during the approval or rejection process.
* **Requested Duration:** Shows the time period for which the exemption is requested (e.g., `7 days`, `30 days`).
* **Scope:** Indicates the exemption's intended application scope, such as Target-level, Pipeline-level, or Project-level.
* **Reason:** Selected justification category provided during request creation (e.g., `Acceptable Risk`, `False Positive`, `Not Exploitable` etc.).
* **Response Actions:** If you have the [required permissions](/security-testing-orchestration/use-sto/sto-exempt-issues/issue-exemption-workflow.md#required-permissions-for-issue-exemptions), available actions include **Approve**, **Reject**, **Cancel**, or **Re-open**, depending on the current request state.

Additionally, alongside the **Exemption Status**, Harness also displays the **Exemption Log**, which upon clicking, displays the history of actions taken on the exemption, in chronological order. For more information, see the section below.

#### View the exemption log <a href="#view-the-exemption-log" id="view-the-exemption-log"></a>

Every exemption request keeps a running record of the actions taken against it. You can use these exemption logs to audit who took action on an exemption and when.

To view the logs, complete the following steps:

1. Navigate to the **Issue Details** pane in either of the following ways:
   * Navigate to **Issues** page and click on an **Issue**.
   * Navigate to the **Executions** page, click on a **Pipeline**, **Vulnerabilities** tab, and click on an **Issue** from the list.
2. In the **Issue Details** pane's top right corner, click **Exemption Log**.

The log opens in its own panel, where entries are listed in a timeline, most recent first, each marked with the acting user's initials. Each entry displays the following details:

<figure><img src="/files/whKitj21hAcSQulh8p9S" alt=""><figcaption><p>Exemption Log Panel</p></figcaption></figure>

* **Title**: The action taken and the user who took it, for example, *Exemption cancelled by John Doe*.
* **Status**: The status of the exemption, for example, *CANCELED*.
* **Timestamp**: The time at which the exemption was logged.
* **Scope**: The exemption's scope at the time of the action, for example, *PROJECT default/STO* or *TARGET default/STO/test*.
* **Duration**: The exemption duration, for example, *Exempted for all time*.
* **Reason**: The justification category selected for the exemption, for example, *Fix Unavailable* or *Compensating Controls*.
* **Type**: Whether the exemption applied to the issue or to specific occurrences, for example, *Issue*.
* **Comments**: Any comments added while requesting exemption.

{% hint style="info" %}
The most recent log entries also appear inline in the **Recent Activities** section of the **Issue Details** pane. Click **Exemption Log** for the complete history.
{% endhint %}

Further, you can use the **Download** icon in the panel's top right corner to download all logs in CSV format.

#### View exemptions at the Project level <a href="#view-exemptions-at-the-project-level" id="view-exemptions-at-the-project-level"></a>

* Make sure you have the [required permissions](/security-testing-orchestration/use-sto/sto-exempt-issues/issue-exemption-workflow.md#required-permissions-for-issue-exemptions) to view the requests.
* In your Harness project, go to the **left navigation** and click **Exemptions**.

This page displays exemption requests from the selected project.

#### View exemptions at the Organization level <a href="#view-exemptions-at-the-organization-level" id="view-exemptions-at-the-organization-level"></a>

To view all exemption requests across projects in an organization:

* Make sure you have the [required permissions](/security-testing-orchestration/use-sto/sto-exempt-issues/issue-exemption-workflow.md#required-permissions-for-issue-exemptions) to view the requests.
* In Harness, select the **Organization** from the top breadcrumb.
* In the left navigation, click **Exemptions**.

This page displays exemption requests from all projects within the selected organization that you have access to.

<figure><img src="/files/UYxtHQh1kOcz3BkONJgT" alt=""><figcaption><p>Click to view full-size image</p></figcaption></figure>

#### View exemptions at the Account level <a href="#view-exemptions-at-the-account-level" id="view-exemptions-at-the-account-level"></a>

To view exemption requests across the entire account:

* Make sure you have the [required permissions](/security-testing-orchestration/use-sto/sto-exempt-issues/issue-exemption-workflow.md#required-permissions-for-issue-exemptions) to view the requests.
* In Harness, select the **Account** from the top breadcrumb.
* In the left navigation, click **Exemptions**.

This page displays exemption requests from all projects across the organizations you have access to.

<figure><img src="/files/8CBoTayx2fTr82Zls3ir" alt=""><figcaption><p>Click to view full-size image</p></figcaption></figure>
