Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

System roles

Administrators can control access to features and capabilities on a ServiceNow instance by assigning roles to users.

Your ServiceNow includes roles to grant access to the platform features and applications included a base system instance. Applications you install on your instance may include additional roles to control access to those installed features. For more information about roles, see Exploring user administration.

Important: Base system and roles installed with applications can be deactivated by administrators, but can’t modify or rename these roles.

Base system roles

Base system roles are present in all ServiceNow instances and don’t require the installation of additional plugins.

RoleDescription
admin

The system administrator role. This role has access to all system features, functions, and data because administrators can override access control list (ACL) rules and pass all role checks. Avoid assigning this role to your users when more targeted roles are available.

Warning: Grant this privilege carefully. If you have sensitive information, such as HR records, that you need to protect, you must create a custom admin role for that area. You must also train any users authorized to see those records to act as the administrator. Also note the Special Administrative Roles.

agent\_adminAgent administrators can download and administer the system's built-in agent. They can manage MID Server-related scripts.
ais\_adminAI search administrators can query, create, update, and delete indexing and search settings and log messages through the AI Search application.
approval\_adminApproval administrators can view or modify approval requests not directly assigned to them. Use the approver\_user role to enable approvers to only view or modify requests directly assigned to them. Use of this role requires a Fulfiller license. Use of the approver\_user role requires an Approver license.
approver\_userApprover users can modify requests for approval routed to them. They also have all capabilities of requesters.Note: There’s a fee associated with this role. Don’t assign it to users without confirming your organization has the appropriate entitlement.
assignment\_rule\_adminAssignment rule administrators can manage assignment rules.
assetAsset users can manage hardware and software assets.
business\_process\_admin

Business process admins can create, read, update, and delete all records and their relationships in the business process.

In the context of Governance, Risk, and Compliance (GRC), users with the sn_grc.admin role who manage GRC applications and their setup automatically gain access to this role. This access enables the GRC administrators to administer a business process and its records similar to other GRC tables.

Important: This role is assigned to users who are administrators and have thorough information and training on business processes.

business\_process\_managerBusiness process managers can create, read, and update any business process and manage the relationship of business processes with other records. This role is assigned to business process managers who are usually specialists and manage multiple business processes in the organization. These users generally work with other employees and are experts around business processes. In the context of GRC, users with the sn\_grc.manager role automatically inherit this role that enables them to manage the business processes for the entire organization.
business\_process\_userBusiness process users can update the business processes that a user owns and can also read any business process. This role must be assigned to the respective process owners who manage the business process that they own. This role can also be provided to users who are required to view the business processes in the organization and understand them better. In the context of GRC, users with the sn\_risk.user role are automatically assigned this role as this role enables them to manage the business processes they own as well as read all business processes.
catalogCatalog users can access service catalog requests.
catalog\_adminCatalog administrators can manage the Service Catalog application, including catalog categories and items.
catalog\_editorCatalog editors can create, modify, and publish items within categories that they’re assigned to.
catalog\_item\_designerCatalog item designers can view the status of their category requests. This role is granted automatically to users when they make a request for an item designer category.
catalog\_managerCatalog managers can view and assign catalog editors to their categories. Can also create, modify, and publish items within their categories.
category\_managerCategory managers can create, edit, and delete model categories.
cmdb\_dedup\_adminCMDB de-duplication admins can review and remediate CMDB de-duplication tasks.
cmdb\_ms\_userCMDB multiscource readers can access and run a multi-source CMDB query, but can't create a query. This role contains Contains cmdb\_read role.
cmdb\_ms\_editorCan create and run a query, has full read and write access, but can't do Recompute. Contains cmdb\_ms\_read role.
cmdb\_ms\_adminCan create and run a query, and can modify CMDB 360 properties. Contains cmdb\_ms\_write role.
cmdb\_readCan read any CMDB table. Contained in admin and itil.
communication\_managerManages communication for major incidents and is responsible for communicating with all stakeholders.
contract\_managerCan create, edit, and delete contracts through the Contract Management application.
data\_classification\_adminAdministers all aspects of the Data Classification application, data classification code setup and assignment,
data\_classification\_auditorAudits Data Classification code assignments.
ecmdb\_adminCan administer the CMDB.
filter\_adminCan manage filters.
filter\_globalCan create global filters.
filter\_groupCan create filters that belong to groups of which the user is a member.
gauge\_makerCan create gauges from reports. Starting with Helsinki, reports are no longer made into gauges.
guided\_tour\_adminCan manage and administer Guided Tour functionality.
image\_adminCan manage image files on the Images \[db\_image\] table.
impersonatorCan impersonate users. This role doesn't allow impersonation of admin users.
import\_adminCan manage all aspects of import sets and imports.
import\_schedulerCan schedule imports. Warning: Grant this role carefully. The import_scheduler role is equivalent to giving the user the admin role, because the import_scheduler has the ability to execute scripts with administrator level privileges.
import\_set\_loaderCan load import sets.
import\_transformerCan manage import set transform maps and run transforms.
incident\_managerManages Incident properties and Major Incident trigger rules.
inventory\_adminCan create and delete stock information. Only users with the inventory\_admin role can edit stock rules, stockrooms, and stockroom types.
inventory\_userHas access to stock information. Can create and manage transfer orders.
itilCan perform standard actions for an ITIL helpdesk technician. Can open, update, close incidents, problems, changes, configuration management items. By default, only users with the itil role can have tasks assigned to them.
itil\_adminPossesses more privileges than the itil role and is intended for team leads. This role has the ability to delete incidents, problems, changes, and other related entities when both the itil and itil\_admin roles are assigned. In addition, the itil\_admin role grants full control of the CMDB. The itil\_admin role includes all of the permissions granted to the sn\_cmdb\_admin role, which provides full access to CMDB data, tools, and UIs.
knowledgeCan create, edit, and review knowledge base articles.
knowledge\_adminCan manage the knowledge base.
list\_updaterCan use Update Entire List and Update Selected menu options on lists.
maintReserved for ServiceNow use.
mid\_serverRole that any MID server user should be granted. This role gives the MID server access to the tables it ordinarily uses.
model\_managerCan create CMDB models. Model manager can control the base models and any model extensions that aren’t software or consumables. Consumable models are controlled by the asset manager role \(asset\). Software models are control by the software asset manager role \(SAM\).
major\_incident\_managerInitiates the major incident process by assessing and approving major incident candidates or creating a major incident. Maintains the ownership and accountability for the life cycle of the incident. Identifies the users and groups to be involved in the resolution activities and sets up communication channels.
nobody

The nobody role means that no user has access - not even admin or maint. Use the nobody role carefully. The nobody role takes precedence over the admin override option on ACLs, so even admins can’t have access. See Create an ACL rule.

Don’t assign it to specific users. You can use this role in ACLs that control access to resources, such as UI pages, processors, script includes, and records.

Warning: Applying the nobody role may be irreversible if applied to some important system functions.

personalizeCan configure forms, lists, rules, controls, scripts.
personalize\_choicesCan configure choices and predefined responses for non-journal fields designated as choice or suggestion fields.
personalize\_controlCan configure controls on lists, such as filters, links, and buttons.
personalize\_dictionaryCan configure dictionary entries and labels.
personalize\_formCan configure forms.
personalize\_listCan configure lists and list calculations.
personalize\_responsesCan configure predefined responses for journal fields designated as suggestion fields.
personalize\_rulesCan configure business rules and scripts. This role contains the following specialized roles for granting selective, administrative access to rules and scripts:- business\_rule\_admin - client\_script\_admin - ui\_policy\_admin - ui\_action\_admin
personalize\_stylesCan configure field styles.
personalize\_uiCan configure forms and lists.
publicNo login is required to access features or functions with the public role.
release\_adminCan edit Release history for a release.
report\_adminCan manage reports.
report\_globalCan create global reports.
report\_groupCan create reports and share reports with groups that the user is a member of. Users with this role can edit reports shared by other users in the group.
report\_publisherCan make reports available on a public page.
report\_schedulerCan schedule a report to be emailed.
script\_fix\_adminCan create and manage fix scripts but can’t run fix scripts.
search\_application\_adminCan query, create, update, and delete records on search UX-related tables. Contains the ais\_admin role.
sn\_appclient.app\_client\_company\_installerCan install applications containing the same company as the currently logged in instance. User role that enables first-time installation of applications for the company associated with the current instance. A user with this role can’t install an application for another company.
sn\_appclient.app\_client\_userCan install applications containing the same company as the currently logged in instance.
sn\_cmdb\_adminProvides full access to CMDB data, tools, and UIs. A CMDB Admin, for example, sets policies in the CI Class Manager and application service requirements. CMDB Admin provides the highest level of access to the CMDB.
sn\_cmdb\_editorProvides access to CMDB records. A CMDB Editor can't change policies such as in the CMDB Data Manager or in the CI Class Manager.
sn\_cmdb\_userProvides read-only access to CMDB data and to basic UIs such as CMDB reports and dashboards.
soapCan query, create, update, and delete records on all tables, as well as execute scripts.
soap\_createCan create records on all tables and columns.
soap\_deleteCan delete records on all tables and columns.
soap\_eccCan query, create, and update on the ECC Queue table only.
soap\_queryCan query records on all tables and columns.
soap\_query\_updateCan query and update records on all tables and columns.
soap\_scriptCan execute business rule endpoint function via script.do.
soap\_updateCan update records on all tables and columns.
survey\_adminCan see all Surveys, their definitions, questions, instances created by them and others. Survey administrators can use all modules in the Survey application menu.
survey\_readerUsers with survey reader role can view surveys and related information, such as survey responses, survey groups, scorecards, and reports. Survey\_reader can’t change or modify a survey or survey responses.
task\_editorCan edit protected task fields.
template\_editorCan create templates for personal use, and modify or delete personal templates. Included in the itil role in the base system.
template\_editor\_globalCan create templates for global use.
template\_editor\_groupCan create templates for groups.
template\_schedulerCan schedule template-based record creation.
text\_search\_adminCan customize Global Text Search groups and tables.
timecard\_adminCan approve, modify, and delete the time cards of other users.
ts\_adminCan administer Zing text indexing and search engine.
unlimited\_createnowRole for CreateNow unlimited licensed users.
upgrade\_appCan upgrade installed applications containing the same company as the currently logged in instance. Can’t perform first-time installations of applications published to the Application Client page.
userAvailable for customer use, has no function in the base system.
user\_adminCan administer users, groups, locations, and companies.
view\_changerCan switch active views.
workflow\_adminCan create, edit, publish, or delete graphical workflows.
workflow\_creatorCan create new graphical workflows.
workflow\_publisherCan publish graphical workflows.

Application-specific roles

Applications you install on your instance may include additional roles. Follow the links in this section to see roles documentation on roles installed along with applications.

ProductApplication
Platform CapabilitiesAdvanced Work Assignment

Parent Topic:Managing roles