Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Granular admin roles

Granular admin roles enables you to verify proper access management by assigning roles that define user permissions and responsibilities. By doing so, organizations can maintain security, enforce conformance, and optimize their operations effectively.

Roles are a fundamental part of managing access and maintaining security within your instance. They define what you can see and do, verifying that you have the appropriate level of access based on your responsibilities. By assigning the correct roles to the users, organizations can safeguard sensitive data, enforce conformance, and streamline operations.

To optimize access management within the ServiceNow AI Platform, consider adopting granular admin roles. This approach enables you to assign specific permissions to developers or users who perform minor administrative tasks, without granting them unrestricted access to the full admin role.

Note:

  • Users who are assigned with admin role previously will have its granular admin roles assigned based on the product or module that they had access to earlier.
  • Each product within the ServiceNow AI Platform has its own set of granular admin roles. To determine the appropriate roles for your administrators or developers, refer to the specific product documentation.
  • You can assign the Instance operator (instance_operator) role for users who handle day-to-day operations without elevated system configuration privileges. Assign this role to users who need to:
    • Check logs and diagnose problems
    • Perform routine maintenance
    • Keep workflows running smoothly
  • Granular admin roles are separate from the existing admin role and must be assigned independently.

By adopting granular admin roles, you can create a more secure and efficient access management system that aligns with your organization's needs.

ProductRole NameDescription
Access Analyzeraccess\_analyzer\_adminRole required to use access-analyzer application.
AE - StreamConnectmessage\_replication\_adminRole required to access all IntegrationHub stream replication features, enable setup and connection to message brokers, and configure message stream replications.
AE - StreamConnectstream\_connect\_adminRole required to manage Stream Connect-related settings for subscriptions, topics, and other configurations.
Agent Chatawa\_adminRole required to access granular AWA capabilities.
Agent Chatinteraction\_adminRole required to access granular interaction configuration capabilities.
AI Agentssn\_aia.adminRole required to access and update Agentic AI tables.
AI Searchais\_adminRole required to manage and view AI Search and NowAssist for Search tables, properties, and configurations.
AI Virtual Agentsn\_nowassist\_admin.nsa\_adminRole required to enable your requesters to have a streamlined, conversational experience that is based on generative AI as they submit a catalog item request in Virtual Agent.
App Governancesn\_aemc.aemc\_adminRole required to have feature admin access for App Engine Management Center and includes scan\_user.
App Governancesn\_app\_summary.app\_summary\_adminRole required to have feature admin access for App Summary.
App Governancesn\_deploy\_pipeline.deployment\_pipeline\_adminRole required to have feature admin access for Deployment Pipeline.
App Governancesn\_pipeline.pipeline\_adminRole required to have feature admin access for Pipeline.
Application Vulnerability Responsesn\_vul.app\_sec\_managerRole required for security managers. It is also required for application owners who manage penetration test assessment requests. By default, this role contains granular roles for third-party integration configuration and is required for full read, write, and delete permission on all AVR records and rules.
Alumni Centersn\_asc.adminRole required to create and manage profiles and features related to an alumni.
Audit, History and Journalaudit\_adminProvides write and delete access to sys\_audit. Manual record modifications should be avoided. For bulk deletions, use system jobs rather than direct deletion.
Authenticationadaptive\_auth\_policy\_adminRole required to configure adaptive authentication policies and filters, as well as update or delete those created by the role. Additionally, policies and filters created by other users and default configurations are available in read-only mode.
Authenticationadpative\_auth\_adminRole required to access and modify Adaptive Authentication configurations, including creating and adjusting policies, managing policy contexts, and configuring filter criteria. Additionally, users can enable or disable adaptive authentication policies as needed. The role also grants access to modify Multi-Factor Authentication \(MFA\) settings, enabling users to enforce MFA and adjust MFA factor policies.
Authenticationcustom\_url\_adminRole required to configure new custom URLs for the instance, as well as to delete or modify existing custom URL configurations.
Authenticationpassword\_policy\_adminRole required to configure and manage the password policies in the instance. Users with this role can create, manage, and enable or disable existing and new password policies.
Authenticationsso\_config\_adminRole required to access all configurations related to Single Sign-On authentication within the instance. Grants the capability to create and modify feature configurations for SSO SAML, OIDC, Digest, and Certificate-Based Authentication in the instance.
Authenticationuser\_authn\_adminRole required to access and modify all user login-specific configurations, such as Single Sign-On \(SSO\), Account Recovery, Adaptive Authentication, MFA, and Password Policy.
Authentication Factorsauth\_factors\_adminRole required to configure authentication for voice agent environments, with the factors that first identify the caller, then authenticate them before granting access.
Career Conversationssn\_egd\_act.adminRole required to configured all Career Conversations features, including auto closure of conversations and setting up integrations with Microsoft Outlook.
CMDB Adminsn\_cmdb\_adminRole required to configure the application and to create, read, write, and delete records in tables. Provides the highest level of access to tools and UIs within CMDB Workspace and other store apps such as CMDB Coverage, including full access to the Configuration item \[cmdb\_ci\] table. A CMDB Admin, for example, can set policies in the CI Class Manager and application service requirements. CMDB Admin can also modify default config records under the default identifier or the default identifier itself.
Code Assist Experiencebackground\_script\_adminRole required to manage background scripts.
Code Assist Experiencenow\_assist\_code\_adminRole required to manage the Now Assist for code generation settings in system\_properties.
Code Assist Experiencenow\_assist\_code\_rag\_adminRole required to manage the Retrieval for code generation app.
Collaborative Work Managementsn\_cwm.cwm\_adminRole required to update Collaborative Work Management \(cwm\) properties and reports.
Configuration Compliancesn\_vulc.adminRole required for full read, write, and delete permission on all Configuration Compliance records and rules.
Container Vulnerability Responsesn\_vul\_container.vulnerability\_adminRole required for complete access to the Container Vulnerability Response \(CVR\) application and its records. Role required to configure third-party integrations and rules in Container Vulnerability Response.
Contract Management Prosn\_cm\_core.contract\_adminRole required for administrative access to Contracts Core and underlying data.
Contract Management Pro - Contract Workspacesn\_cm\_workspace.adminRole required to change the Contract Workspace for Contract Management Pro to fit into the business or user requirements.
Contract Management Pro - Contracts Dashboardsn\_cm\_pa.pa\_adminRole required to activate and configure the Analytics Pack for Contract Management Pro application.
Contract Management Pro - Now Assist in Contract Managementsn\_cm\_gen\_ai.ai\_contract\_adminRole required for administrative access to the Now Assist in Contract Management application.
Cloud Accelerate-Cloud Workspacesn\_itom\_cam.cw\_adminRole required to provision cloud accounts, add an unmanaged cloud account and update cloud account details.
Cloud Accelerate-CSCsn\_cmp.cloud\_service\_user.root\_adminRole required to manage stacks and resource filters.
Cloud Accelerate - CSCsn\_cmp.cloud\_adminRole required to setup Google Cloud Platform and Microsoft Azure Cloud on Cloud Services Catalog, setup cloud accounts for VMware, Specify the credentials that CSC Terraform Connector, work with stacks, view Cloud Service Requests in Cloud Admin Portal, view and utilize the Cloud Root Cause Analysis reports, debug and troubleshoot Cloud API Trail, create custom tags for cloud resources, Store the Azure service principal credentials in the instance.
Cloud Accelerate - CPGsn\_cmp.cmp\_root\_adminRole required to create scan schedules, CI finder mapping, policies by using condition builder, flows, or script, a policy set, resource collectors and view the dashboard and audit issue reports to run remediation and scan configurations.
Creator Studiosn\_creatorstudio.configuration\_adminRole required to provide admin privileges for the Creator Studio. The roles contains the following Creator Studio granular admin roles:- sn\_creatorstudio.task\_admin - sn\_creatorstudio.app\_configurator - sn\_creatorstudio.reports\_viewer
Creator Studiosn\_creatorstudio.task\_adminRole required to grant users access to change several fields on the Request Task table or a table that extends Request Task.This role contains the following:- Table-level access for sn\_creatorstudio\_task: Create, Write, Delete - Field-level access for: - sn\_creatorstudio\_task.request\_type, which enables you to change the associated form - sn\_creatorstudio\_child\_task.parent, which enables you to change the parent table for any subtask tables created from a task activity added to an app's playbook.
CSM - CRM Foundationentitlement\_adminRole required to access the entitlement table.
CSM - Case Managementsn\_csm\_case\_type.config\_adminRole required to create, view, update and delete records in the Case type \[`sn_case_type`\]​ table.
CSM - Case Managementsn\_customerservice.case\_adminRole required to create, view, update and delete records in the Customer Service Case \[`sn_customerservice_case`\]​ table.
CSM - Case Managementsn\_case\_line.adminRole required to create, view, update and delete records in the Case Line \[`sn_case_line`\]​ table.
CSM - Case Managementsn\_csm\_case\_digest.adminRole required to delete record in the Case Digest \[`sn_csm_case_digest_task`\] table​. ​Also, can create, view, update and delete records in the Case Digest Configuration \[`sn_csm_case_digest_config`\]​ table.
CSM - Case Managementsn\_task\_plan.adminRole required to create, view, update and delete records in the Task Plan tables.​
CSM - Case Managementsn\_complaint.adminRole required to create, view, update and delete records in the Complaint tables.​
CSM - Case Managementsn\_onboarding.adminRole required to create, view, update and delete records in the Onboarding tables.​
CSM - Case Managementsn\_csm\_ppm.adminRole required to create, view, update and delete records in the Project Portfolio Management tables.​
CSM - Case Managementsn\_action\_status.adminRole required to create, view, update and delete records in the Action Status tables.​
CSM - Case Managementsn\_uib\_dyn\_rel\_rec.adminRole required to create, view, update and delete records in the UIB Dynamic Related Records tables.​
CSM - Case Managementsn\_cs\_sm.adminRole required to create, view, update and delete records in the Customer Service with Service Management tables.​
CSM - CRM Foundationsales\_agreement\_adminRole required to have full access to all sales agreement tables.
CSM - CRM Foundationservice\_contract\_adminRole required to have full access to all contract tables.
CSM - CRM Foundationsn\_crm\_customer\_access\_management\_adminRole required to have admin access to customer access management configuration tables, including related party configurations, responsibility definitions, and responsibility access configurations.
CSM - CRM Foundationsn\_crm\_escalation\_adminRole required to have admin access to all escalations and related configuration tables.
CSM - CRM Foundationsn\_crm\_foundation\_adminRole required to have admin access to CRM configurations, including escalations, query rules, and customer access management. It also contains sn\_crm\_foundation\_data\_manager role.
CSM - CRM Foundationsn\_cs\_queryrules.adminRole required to have admin access to all query rules.
CSM - CRM Foundationsn\_install\_base.install\_base\_adminRole required to have granular admin access for Install base and related features.
CSM - CRM Foundationsn\_l2c\_core.adminRole required to have full access to Lead to Cash Core metadata tables, modules, and application.
CSM - CRM Foundationsn\_prm.enterprise\_partner\_adminRole required to have admin access for partner relationship management.
CSM - CRM Foundationsn\_crm\_sequence.adminRole required to give full access to sequence records and its related data.
CSM - CRM Foundationsn\_l2c\_core.adminRole required to have full access to Lead to Cash Core metadata tables, modules, and application.
CSM - CRM Foundationsn\_tmt\_core.adminRole required to have full access to Sales and Service Core API tables.
CSM - Omnisn\_openframe.adminRole required to have granular admin access to Open frame tables and properties.
CSM - Self Serviceactsub\_adminRole required to access Subscription and Activity Feed Framework related tables and modules.
CSM - Self Servicesn\_communities.adminRole required to access Communities related tables and modules.
CSM - Self Servicesn\_csm\_ec.ec\_adminRole required to have granular admin access for engagement messenger tables and Rest APIs.
CSM - Self Servicesn\_csm\_walkup.walkup\_adminRole required to access CSM Walkup Experience tables and modules.
CSM - Self Servicesn\_embeddable\_core.emb\_adminRole required to have granular admin access for web embeddables admin experience.
CSM - Self Servicesn\_ext\_usr\_reg\_adminRole required to have granular admin access for External user registration.
CSM - Self Servicesn\_gamification.adminRole required to access Gamification related tables and modules.
CSM - Self Servicesn\_otp\_support\_util\_adminRole required to have granular admin access for OTP Support Util.
CSM - Base Entitiescsm\_adminRole required to access to all CSM features and data.
CSM - Base Entitiessn\_res\_shaper.adminRole required to perform create, update, and delete operations for the Resolution Shaper Config table \(sys\_resolutionshaper\_config\).
CSM - Customer Centralsn\_customer\_central\_adminRole required to access all Customer Central features and data.
Customer Success Managementsn\_acct\_lc.customer\_success\_application\_adminRole required to have granular admin access for customer success management tables and server-side access.
Data Streaminghermes\_adminRole required to have access for all Hermes related configuration and maintenance.
Data Streamingidr\_adminRole required to have access for all IDR related configuration and maintenance.
Data Streamingdata\_mgmt\_tools\_adminRole required to enable administrators to perform basic Data Management tasks.
Digital End-User Experiencesn\_dex.adminRole required to manage user access to DEX, manage the applications that are being monitored, and handle onboarding or offboarding-related tasks. Used also to troubleshoot any issues that arise within the application.
Document Intelligenceplatform\_ml\_di.admin, sn\_docintel.adminRole required to have granular admin access for Document Intelligence \(docintel\) capabilities.
Document Managementdocument\_adminRole required to manage system properties, security ACLs, and security ACL roles. Manage PDF generation, document conversion and document viewer BASE SYSTEM plugins.
Document Managementplatform\_document\_management\_adminProvides access to perform Create, Read, Update and Delete operations to the Documents, references, versions, lists and list entry tables.
Employee Center Outlook Add-insn\_outlook\_addin.outlook\_addin\_setupRole required to set up and manage the Employee Center Outlook Add-in, including access to the sn\_outlook\_addin.portal.suffix system property, modules, UI actions, and app application files.
Employee Center Prosn\_hr\_sp.esc\_adminRole required to have read and write access to the feedback task table, Employee Center version 37 onwards.
Employee Profilesn\_employee.adminRole required to create and manage employee profiles.
Encryptionsecurity\_adminRole required to perform security operations as an admin.
Encryptionsn\_kmf.adminRole required to have admin and security admin access to be sn\_kmf.admin. Can assign sn\_kmf.cryptographic\_manager or sn\_kmf.cryptographic\_auditor role to other users and has read, write, and execution permissions for key operations.
Enterprise Architecturesn\_apm.apm\_adminRole required to administer Enterprise Architecture features and configurations
Event Managementevt\_mgmt\_adminRole required to have full access to configure Event Management, including event rules, field mapping, alert management rules, and more.
External Content Connectorssn\_ext\_conn.xcc\_adminRole required for management of external content connector configuration settings. Can create, read, update, and delete connectors, schedule and run connector crawls, and view crawl logs and analytics.
Flow Designer UIflow\_adminRole required to have admin access for all flow designer tables.
Flow Enginesflow\_adminRole required to work with backend tables of flow\_designer.
FSC-Accounts Payable Invoice Processingsn\_ap\_apm.adminRole required to have admin access for Accounts Payable Invoice Processing.
FSC-Accounts Payable Invoice Processingsn\_ap\_apm.invoice\_tolerance\_adminRole required to configure tolerances in Accounts Payable Invoice Processing.
FSC-Accounts Payable Invoice Processingsn\_ap\_cm.adminRole required to have admin access for Invoice case management.
FSC - Finance Case Managementsn\_fin\_ops.adminRole required to access all the features and capabilities of Finance Case Management, including Finance Operations workspace.
FSC - Integrationssn\_fcms\_intg.adminRole required to have administrative access for the ERP Integration Framework, inheriting sn\_fcms\_intg.integration\_user and granting admin-level access to manage integration configurations, data, and operations.
FSC - Purchase Order Managementsn\_poem\_core.adminRole required to have admin access for Purchase Order Management.
FSC - SLOsn\_slm.adminThis role provides full administrative access to manage supplier-related processes and includes elevated permissions such as`sn_slm.manager`, `decision_table_admin`,`sn_fin.supplier_payment_info_write`,`sn_vdr_risk_asmt.vendor_assessor`, and`sn_shop.shopper`. Users who need complete control over supplier management, vendor assessments, payment information, and related workflows across the SLM application.
FSC - SLOsn\_kpi.adminProvides full administrative access to manage and configure all aspects of the KPI Framework, including creating, editing, deleting KPIs, and configuring KPI definitions.
FSC - SPOsn\_fin.finance\_adminRole required to generate fiscal and accounting periods.
FSC - SPOsn\_shop.procurement\_administratorRole required to access the primary data and administration sections of the Purchase Automation module.
FSC - SPOsn\_shop.shopping\_hub\_adminRole required to access all modules of the Source-to-Pay Common Architecture application.
FSC - SPOsn\_spend\_psd.psd\_adminRole required to configure and make changes to system properties, such as creating request types and categories.
FSC - SPOsn\_spend\_sdc.adminRole required to access Service Task and Service Request tables, which extends to Procurement Case Management, as well as other infrastructure that forms the foundation of Finance and Supply Chain Workflows products.
FSM - Plan Scheduledynamic\_scheduling\_adminRole required to perform administration configuration for Dynamic Scheduling Application.
FSM - Plan Schedulesn\_task\_recommend.task\_rec\_adminRole required to have granular admin access for Intelligent Task Recommendations \(sn\_task\_recommend\) plugin.
FSM - Plan Scheduletimecard\_adminRole required to have write access to all time cards, otherwise users only have access to their own timecards.
FSM - Plan Schedulesn\_task\_grouping.adminRole required to have admin access for Task Grouping Feature.
FSM - Plan Schedulewm\_adminRole required to have admin access for Work Order Management users.
Gen AI Controllerglobal\_genai\_adminRole required to have access to certain GenAI tables that are hosted in the global domain.
Grants Managementsn\_gsm\_grnt\_mgmt.grant\_adminRole required to provide delegated admin access to the Grants Management application.
GRCsn\_rec\_pg\_vertical.adminRole required to have admin access for Record - vertical.
GRC - AI Risk and Compliance Managementsn\_ai\_case\_mgmt.ai\_case\_adminRole required to have admin access for AI Case Management.
GRC - AI Risk and Compliance Managementsn\_grc\_ai\_gov.ai\_risk\_and\_compliance\_adminRole required to have admin access for AI Risk and Compliance Management.
GRC - AI Risk and Compliance Managementsn\_privacy.adminRole required to be responsible for configuring privacy management solution as a Privacy Admin.
GRC - Corp Compliancesn\_audit.adminRole required to have admin access for Audit related plugins.
GRC - Corp Compliancesn\_compliance.adminRole required to have admin access for GRC Compliance related plugins.
GRC - Corp Compliancesn\_grc.adminRole required to have admin access for GRC core-related plugins.
GRC - Corp Compliancesn\_grc\_advanced.evidence\_adminRole required to access Evidence-related objects as a feature role.
GRC - Corp Compliancesn\_grc\_reg\_change.it\_adminRole required to have IT admin access for GRC: reg change management plugin and set up integrations with third-party regulatory intelligence providers.
GRC - Corp Compliancesn\_grc\_taxonomy.taxonomy\_adminRole required to have admin access for GRC: Taxonomy.
GRC - Formula buildersn\_fb\_connected.adminRole required to have admin access for formula builder application.
GRC - Operational resiliencesn\_oper\_res.adminRole required to create and delete some operational resilience activities.
GRC - Operational resiliencesn\_oper\_res.irm\_opres\_adminRole required to create and delete both operational resilience activities and IRM activities.
HRSD - Case and Knowledge Managementsn\_hr\_core.adminRole required to have full HR administrator access — can configure all HR settings, assign roles, and access all HR data.
HRSD - Case and Knowledge Managementsn\_hr\_er.adminRole required tohave full administrator access to ER module configuration, case management, and setup.
HRSD - Case and Knowledge Managementsn\_em.adminRole required to access and configure all areas within Evidence Management.
HRSD - Case and Knowledge Managementsn\_interview\_temp.adminRole required to access, read, create, and edit interview question templates, template tags, and Employee Relations properties.
HRSD - Case and Knowledge Managementsn\_hr\_ef.adminRole required to assign EDM roles, search, read, create, or update employee documents, and manage administration including retention periods, retention policies, security policies, and document types
HRSD - Case and Knowledge Managementsn\_sp\_admin\_ws.adminRole required to access workspace and see a consolidated view of the demand and consumption of services offered to customers.
HRSD - Case and Knowledge Managementsn\_hr\_ra.adminRole required to configure HR related Recommended Context tables to show different recommendations in HR Agent
HRSD - Employee Journey Managementsn\_ja.adminRole required to create and manage all Journey Accelerator components, tables, and data.
HRSD - Employee Journey Managementsn\_hr\_le.adminRole required to create, manage, and add users to groups within Lifecycle Events. Can access: - Guided Setup - Manage Owner Groups - Manage Roles - LE UI Configuration - Onboarding Executive Dashboard - Onboarding Executive View
HRSD - Employee Journey Managementsn\_hr\_le\_pa.adminLifecycle Events Performance Analytics Admin role for the scoped application. - Access and modify the Lifecycle Events PA content packs. - Edits Performance Analytics properties. - Accesses Admin Console. - Launch Dependency Assessment.
HRSD - Employee Journey Managementsn\_jny.adminRole required to create and manage all Journey designer and Journey Accelerator configurations and features.
HRSD-Employee Journey Managementsn\_ja.adminRole required to create and manage all Journey Accelerator components, tables, and data.
HRSD-Employee Journey Managementsn\_hr\_le.adminRole required to create, manage, and add users to groups within Lifecycle Events. Can access: - Guided Setup - Manage Owner Groups - Manage Roles - LE UI Configuration - Onboarding Executive Dashboard - Onboarding Executive View
HRSD-Employee Journey Managementsn\_hr\_le\_pa.adminLifecycle Events Performance Analytics Admin role for the scoped application. - Access and modify the Lifecycle Events PA content packs. - Edits Performance Analytics properties. - Accesses Admin Console. - Launch Dependency Assessment.
HRSD-Employee Journey Managementsn\_jny.adminRole required to create and manage all Journey designer and Journey Accelerator configurations and features.
HRSD - Hiring Experiencessn\_ta\_hiring\_core.adminRole required to have super admin access to the Hiring Experiences environment.
HRSD - Hiring Experiencessn\_ta\_tp.talent\_profile\_adminRole required to have admin access to set up Talent Profile.
HRSD - Talent Experiencesn\_egd\_core.adminRole required to have admin access for talent development core.
HRSD - Talent Experiencesn\_egd\_shared\_lib.adminRole required to have admin access for the shared library across HR.
HRSD - Talent Experiencesn\_hr\_lm.adminRole required to track HR license usage by customer as an admin.
HRSD - Talent Experiencesn\_td\_na.adminRole required to have admin access for Now Assist for talent.
Health and Safetysn\_ohs\_im.adminRole required to have admin access for Health and Safety applications.
Identityagent\_role\_config\_adminRole required to access and modify Agent role configurations \(role masking\).
Identitymi\_adminRole required to have admin access for Machine Identity Console. It's a high privilege as it contains other admin roles, assign carefully.
Identityprivileged\_role\_config\_adminRole required to configure which roles are designated as privileged in the system.
Identityrole\_delegator\_adminRole required to have admin access for Role delegation feature.
Identityscim\_client\_config\_adminRole required to access and modify SCIM client configurations.
Identityscim\_config\_adminRole required to access and modify SCIM provider-related configurations such as SCIM extension schema and SCIM system properties.
IH Coreconnection\_adminRole required to have access to Connections \[sys\_connection\] and Credentials \[discovery\_credentials\] table.
IH Corecredential\_adminRole required to have access to Credentials \[discovery\_credentials\] table.
IH Coreih\_process\_sync\_adminRole required to create, edit, or delete Process Sync related tables.
Industrial Connected Workforcesn\_icw.application\_adminRole required to have application admin access for Industrial Connected Workforce.
Inbound web servicesweb\_service\_adminRole required for administrative access to create Scripted REST and GraphQL operations.
Inbound web servicesweb\_service\_configuration\_adminRole required to manage Web Service configurations for REST, GraphQL, and SOAP services, including behavior and security settings. To learn more, see Web Service configurations.
Industry Bankingsn\_appss.adminRole required to create, update, delete, and read request types, inputs, outputs, and definitions.
Industry Bankingsn\_bom.adminRole required to have access to all the banking data entities, plus admin privileges as the banking admin.
Industry Bankingsn\_bom.service\_definition\_adminRole required to have full access to the service definition records as the FSO service definition admin.
Industry Bankingsn\_bom\_clo\_b2b.adminRole required to have access to all Business customers' life-cycle operations data and admin privileges.
Industry Bankingsn\_bom\_clo\_b2c.adminRole required to have access to all personal customers life-cycle operations data and admin privileges related to personal customers life-cycle operations.
Industry Bankingsn\_bom\_compl.adminRole required to have access to all complaint operations data and admin privileges as the Financial Services Complaint Admin.
Industry Bankingsn\_bom\_credit\_asmt.adminRole required to have access to all credit assessment data and admin privileges.
Industry Bankingsn\_bom\_credit\_card.adminRole required to have access to all credit card service tasks and admin privileges.
Industry Bankingsn\_bom\_deposit\_b2b.adminRole required to have access to all Business Deposit Operations data and admin privileges.
Industry Bankingsn\_bom\_deposit\_b2c.adminRole required to have access to all personal deposit operations data and admin privileges.
Industry Bankingsn\_bom\_fraud.adminRole required to have access to all Fraud Operations data and admin privileges.
Industry Bankingsn\_bom\_kyc.adminRole required to have access to all Business KYC operations data and admin privileges.
Industry Bankingsn\_bom\_loan.b2c\_adminRole required to have access to all loan operations data and admin privileges.
Industry Bankingsn\_bom\_loan\_b2b.adminRole required to have access to all Business loan operations data and admin privileges.
Industry Bankingsn\_bom\_pa.adminRole required to have access to all the banking data entities as the performance analytics admin, plus admin privileges.
Industry Bankingsn\_bom\_payment.adminRole required to have access to all payment operations data and admin privileges.
Industry Bankingsn\_bom\_po.adminRole required to have admin privileges.
Industry Bankingsn\_bom\_remote.adminRole required to have access to all remote data and admin privileges as the FSO Remote Tables and Lookup Admin.
Industry Bankingsn\_bom\_treasury.adminRole required to have access to all treasury operations data and admin privileges related to treasury operations.
Industry Bankingsn\_data\_sec.adminRole required to have access to the Tokenizer Resource Configuration table and admin privileges.
Industry Bankingsn\_doc\_processor.adminRole required to have access to all document entities and admin privileges.
Industry Bankingsn\_evnt\_inq.adminRole required to have admin access for Event Inquiry.
Industry Bankingsn\_fso\_intg\_friss.adminRole required to manage the flows for FRISS integration.
Industry Bankingsn\_fso\_intg\_jha.adminRole required to manage the flows for JHA integration.
Industry Bankingsn\_ins\_claim.adminRole required to have access to all Insurance Claims Core tables and admin privileges.
Industry Bankingsn\_ins\_claim\_cml.adminRole required to have access to all Commercial claim operations data and admin privileges.
Industry Bankingsn\_ins\_claim\_indl.adminRole required to have access to all Individual Life claim operations data and admin privileges.
Industry Bankingsn\_ins\_claim\_pers.adminRole required to have access to all Personal claim operations data and admin privileges.
Industry Bankingsn\_ins\_gen\_claim.adminRole required to have access to all Insurance claims operations data and admin privileges.
Industry Bankingsn\_ins\_group\_life.adminRole required to have access to all Group Life and Disability Servicing data and admin privileges.
Industry Bankingsn\_ins\_group\_uw.adminRole required to have access to all Group Life and Disability Underwriting operations data and admin privileges.
Industry Bankingsn\_ins\_indiv\_life.adminRole required to have access to all Individual Life Servicing operations data and admin privileges.
Industry Bankingsn\_ins\_indiv\_uw.adminRole required to have access to all individual life insurance underwriting operations data and admin privileges.
Industry Bankingsn\_ins\_policy\_b2b.adminRole required to have access to all Commercial policy operations data and admin privileges.
Industry Bankingsn\_ins\_policy\_b2c.adminRole required to have admin access for Personal lines policy cases.
Industry Bankingsn\_ins\_siu.adminRole required to have access to all SIU data and admin privileges.
Industry Bankingsn\_ins\_underwrite.adminRole required to have access to all insurance underwriting operations data and admin privileges.
Industry Bankingsn\_ins\_uw\_b2b.adminRole required to have access to all Insurance commercial underwriting operations data and admin privileges.
Industry Bankingsn\_jha\_spoke.adminRole required to have admin access for JHA.
Industry Bankingsn\_payment\_card.adminRole required to create, read, write, and delete Payment Card records.
Industry Bankingsn\_req\_criteria.adminRole required to have access to all the service request criteria data entities as the admin.
Information Request Playbooksn\_gsm\_info\_req.adminRole required to provide delegated admin access to the Information Request Playbook application.
IntegrationHub - Finance and Operations Spokesn\_ms\_fin\_ops\_spk.adminRole required to have admin access for the Microsoft Dynamics 365 for Finance and Operations Spoke.
IntegrationHub - Finance and Operations Spokesn\_onedrive\_spoke.Microsoft\_OneDrive\_AdminRole required to have admin access for the Microsoft Dynamics 365 for Finance and Operations Spoke.
IntegrationHub - Finance and Operations Spokesn\_uipath\_spoke.uipath\_adminRole required to have admin access for UiPath spoke tables.
ITAMasset\_licensing\_adminRole required to have granular admin access for ITAM licensing capabilities.
ITAMasset\_recommendation\_adminRole required to have granular admin access for Recommendations capabilities.
ITAMasset\_system\_adminRole required to have granular admin access for Asset management capabilities.
ITAMasset\_task\_adminRole required to have access to create and delete for asset task table.
ITAMcontract\_system\_adminRole required to have granular admin access for Contract capabilities.
ITAMprocurement\_system\_adminRole required to have granular admin access for Procurement capabilities.
ITAM - CCMsn\_cld\_intg\_core.cloud\_integrations\_adminRole required to configure Billing Download jobs and Price Sheet Download jobs.
ITAM - CCMsn\_cld\_intg\_core.readRole required to give access to all the persons for a specific table \(this is strictly for internal purpose and won’t be exposed to the customer\).
ITAM - CCMsn\_cld\_spend\_core.spend\_adminRole required to have access to spend dashboards and tables.
ITAM - CCMsn\_clin\_core.insights\_adminRole required to have complete access to whole application as a super user and access to modify scripts and flows.
ITAM - EAMsn\_eam.enterprise\_adminRole required to have access to entire enterprise application.
ITAM - EAMasset\_aia\_adminRole required to have access to ITAM agents capabilities.
ITAM - EAMasset\_integration\_adminRole required to have access to integration capabilities.
ITAM - HAMasset\_aia\_adminRole required to have access to ITAM agents capabilities.
ITAM - HAMasset\_integration\_adminRole required to have access to integration capabilities.
ITAM - HAMsn\_hamp.ham\_system\_adminRole required to have granular admin access for Advanced Shipment Notification \(ASN\).
ITAM - SAMsam\_adminRole required to have access to the entire Software Asset Management application.
ITAM - SAMsam\_integratorRole required to create and manage SaaS integration profiles.
ITOM - Agent Frameworkagent\_client\_collector\_adminRole required to have admin privileges for management of the agent client collector store application.
ITOM - CAsn\_\_itom\_ccg.adminRole required to have admin access for Cloud Configuration Governance set of apps.
ITOM - Cloud Configuration Governancesn\_cmp.cloud\_root\_adminRole required to have admin access for Cloud Provisioning and Governance set of Apps.
ITOM - Cloud Configuration Governancesn\_itom\_cam.cw\_adminRole required to have admin access for Cloud Workspace Application.
ITOM - Certificate Inventory and Managementsn\_disco\_certmgmt.pki\_adminRole required to have granular admin access for Certificate Inventory and Management.
ITOM - Certificate Inventory and Managementsn\_disco\_firewall.firewall\_adminRole required to change non-standard attributes \(not present in the original firewall\) for a firewall record like, status, purpose, etc. The attributes present in the firewall are immutable.
ITOM - Certificate Inventory and Managementsn\_itom\_licensing.adminRole required to configuration access for ITOM/OT SU Licensing.
ITOM - Tag Governancesn\_itom\_tag.tag\_governance\_adminRole required to have granular configuration access for Tag Governance.
ITOM - Discoverydiscovery\_adminRole required to access the "Discovery" and "Discovery Definition" applications to configure, monitor, and run Discovery operations.
ITOM - Leapsn\_itom\_leap.leap\_adminRole required to have admin access to leap application, enabling users to activate skills and create artifacts.
ITOM - Leap Agentsn\_itom\_leap.leap\_agentRole required to access the LEAP menu from the Service Operations Workspace and trigger LEAP executions.
ITOM - Leap Ansible Agent Workersn\_itom\_leap.leap\_ansible\_agent\_workerRole required for Ansible Discovery Agent and Execution Agent to access Ansible Automation Platform integration features.
ITOM - Leap Ansible Mapping Readsn\_itom\_leap.ansible\_mapping\_readRole required to read step-to-job mappings for Ansible automation integration.
ITOM - Leap Ansible Mapping Writesn\_itom\_leap.ansible\_mapping\_writeRole required to create and update step-to-job mappings for Ansible automation integration \(LEAP Admin only\).
ITSM - FEsn\_sow\_admin.sn\_sow\_adminRole required to oversee service operations workspace-related configurations as `sn_sow_admin` and help customer admin to configure product features and maintain organizational policies.
ITSM - Incident Managementsn\_incident\_adminRole required to configure all Incident Management features including incident management properties.
ITSM - Major Incident Managementsn\_mim\_adminRole required to configure all Major Incident Management features including major incident properties and trigger rules.
ITSM - Incident Communications Managementsn\_iam\_adminRole required to configure all Incident Communications Management features including creating, editing, or canceling incident communication plan, communication task, and managing contact information. Additionally, this role can administrate all Incident Communications Management capabilities.
ITSM - Contact Managementsn\_contact\_adminRole required to configure all Contact Management features including creating and editing contact definitions, contact responsibilities, configuration of MI users, recipient lists, and groups.
ITSM - Task Communications Managementsn\_tcm\_adminRole required to configure all Task Communications Management features including communication plans and tasks.
ITSM - Task Outagesn\_task\_outage\_adminRole required to configure all Task Outage features including the mapping between the Task \[task\] table and the Outage \[cmdb\_ci\_outage\] table.
ITSM - Change Managementsn\_change\_adminRole required to configure Change Management features and system properties.
Journey Acceleratorsn\_ja.adminRole required to create and manage all Journey Accelerator components, tables, and data.
Journey Designersn\_jny.adminRole required to create and manage all Journey designer and Journey Accelerator configurations and features.
Key Management Frameworksn\_kmf.adminRole required to assigns roles to other users to perform operations around the ServiceNow Key Management Framework.
Knowledge managementknowledge\_AdminRole required to have admin access for Knowledge management.
Lifecycle Eventssn\_hr\_le.adminRole required to create, manage, and add users to groups within Lifecycle Events.
Localization Frameworklocalization\_adminRole that manages the Localization Framework application. This role is also used in Localization Workspace.
LSD - Legal Request Managementsn\_lg\_ops.legal\_adminRole required for administrative access to all legal apps and the underlying data.
LSD - Legal Request Managementsn\_lg\_ops.request\_adminRole required for administrative access to the Legal Request module with full access to data.
LSD - Legal Request Managementsn\_lg\_ops.legal\_assignment\_rules\_adminRole required for administrative access to the Assignment Rules module in legal apps.
LSD - Legal Request Managementsn\_lg\_ops.legal\_catalog\_adminRole required for administrative access to the Catalog administration module in legal apps.
LSD - Legal Request Managementsn\_lg\_ops.legal\_notification\_adminRole required for administrative access to the Notifications module in legal apps to configure email notifications.
LSD - Legal Matter Managementsn\_lg\_matter.matter\_adminRole required for the administrative access to legal matters and the underlying data.
LSD - Legal Content Reviewsn\_lg\_cont\_review.adminRole required for administrative access to the Legal Content Review feature and its underlying data.
LSD - Legal Digital Forensicssn\_lg\_forensics.forensics\_adminRole required for administrative access to the Legal Digital Forensics app and full access to the underlying data.
LSD - Legal Investigationssn\_lg\_investigate.adminRole required for administrative access to the Legal Investigations app and full access to the underlying data.
LSD - Legal Simple Privacysn\_lg\_simple\_priva.privacy\_adminRole required for administrative access to the Legal Simple Privacy app and full access to the underlying data.
LSD - Gifts and Entertainment Compliancesn\_lg\_gifts.gifts\_adminRole required for administrative access to the Gifts & Entertainment app and full access to the underlying data.
LSD - Legal Conflict of Interestsn\_lg\_coi.coi\_adminRole required for administrative access to the Legal Conflict of Interest app and full access to the underlying data.
LSD - Legal Hold Notificationsn\_Ig\_hold.legal\_hold\_adminRole required for administrative access to the Legal Hold Notification app and full access to the underlying data.
LSD - Now Assist for Legal Service Deliverysn\_lg\_gen\_ai.adminRole required for administrative access to the Now Assist for Legal Service Delivery application.
LSD - Contract Management Pro for Legal Service Deliverysn\_lg\_cnt.contract\_adminRole required for administrative access to the Contract Management Pro for Legal Service Delivery app and full access to the underlying data.
LSD - Advanced Work Assignment for Legal Service Deliverysn\_lg\_awa.adminRole required for administrative access to the Advanced Work Assignment for for Legal Service Delivery applications.
LSD - Legal Counsel Centersn\_lg\_cf\_workspace.adminRole required to change the Legal Counsel Center Workspace for Legal Request Management to fit into the business or user requirements.
LSD - External Legal Service Centersn\_lg\_ext\_portal.ext\_adminRole required for administrative access to the External Legal Service Centre application and full access to underlying data.
LSD - Legal and Contracts Common Utilitiessn\_lco\_cmn.adminRole required for administrative access to Legal and Contracts Common Utilities records.
Mobilemobile\_adminRole required to configure mobile applications.
Notificationemail\_adminRole required to perform resend email and reprocess inbound email functionality.
Notificationemail\_bounce\_adminRole required to administer email bounce functionality.
Notificationemail\_digest\_adminRole required to monitor email digest.
Notificationnotification\_adminRole required to configure notifications.
Notificationnotification\_category\_adminRole required to configure notification category.
Notificationnotification\_classification\_adminRole required to configure notification classification.
Notificationportal\_notification\_pref\_adminRole required to configure sys\_recipient\_user\_mapping table.
Notificationpush\_adminRole required to manage push notifications.
Notificationsmime\_certificate\_adminRole required to administer SMIME public certificate.
Notifynotify\_setup\_adminRole required to configure Notify features and system properties.
Now Assist - CSMsn\_customerservice\_agentRole required to enable Now Assist for CSM Gen AI skills for customer service agents. It grants access to all Now Assist for CSM skills such as Generate Resolution Notes, Case Summarization, and Chat Summarization.
Now Assist - CSMsn\_customerservice.consumer\_agentRole required to enable Now Assist for CSM Gen AI skills for customer service agents. It grants access to all Now Assist for CSM skills such as Generate Resolution Notes, Case Summarization, and Chat Summarization.
Now Assist for HR Service Deliverysn\_hr\_gen\_ai.adminRole required to configure and manage Now Assist for HR Service Delivery.
Now Assist for HR Service Deliverysn\_hr\_ai\_agents.adminRole required to configure and manage the HR Service Delivery AI Agent collection.
Now Assist for HR Service Deliverysn\_hr\_aia\_voice.adminRole required to configure and manage voice agents in the HR Service Delivery AI Agent collection.
Now Assist - TMTsn\_tmt\_agentic\_ai.app\_adminRole required to manage the Telecommunications Media and Technology AI agent collection.
Now Assist for Vulnerability Responseaia-adminRole required for administrative access to Now Assist for Vulnerability Response.
On-Call Schedulingsn\_on\_call\_adminRole required to configure On-Call Scheduling features and system properties.
Operational Technology - CMDBcmdb\_ot\_adminRole required to manage all OT CMDB tables and records as an admin.
Operational Technology - ISAcmdb\_ot\_isa\_adminRole required to manage all ISA Equipment Model records and Equipment Model Template records as an admin.
Operational Technology - Industrial Process Healthot\_health\_adminRole required to have admin access to Industrial process health application and related functions.
Operational Technology - Subnet Mappingsn\_ot\_amazing\_adminRole required to manage OT Subnet Mapping records in 'ot\_subnet\_mapping' table and OT Subnet Mapping properties as an admin.
Operational Technology - Change Managementsn\_ot\_change\_adminRole required to have admin access to the OT Change Management Application and related functions.
Operational Technology - Incident Managementsn\_ot\_incident\_adminRole required to have admin access to the OT Incident Management Application and related functions.
Operational Technology - Vulnerability Integrationsn\_otvr.integration\_adminRole required to have admin access for OT Vulnerability Integration application.
Operational Technology - Risk Score Calculator applicationsn\_risk\_score\_calc.adminRole required to have admin access to Risk Score Calculator application and related functions.
Outlook Actionable Messages integrationoam\_adminRole required to access and manage Outlook Actionable Messages configurations, including system properties and OAM definitions.
Password policypassword\_policy\_adminRole required to configure password policy-related items.
Password Resetpassword\_reset\_adminRole required to configure Password Reset features and system properties.
Platformsource\_control\_adminRole required to perform all source control functionality.
Platformupdate\_set\_adminRole required to create, delete, and manage Update Sets.
Platformcds\_client\_adminRole required to have admin access for client-side framework of Canonical Data Services \(CDS\).
Platformcluster\_node\_adminRole required to have admin access for instance node and cluster configuration \(VNCC\) related tables.
Platformnds\_adminRole required to have admin access for Normalization Data Services.
PlatformnormalizerRole required to have admin access for Field Normalization feature.
Platform Server - Side Scriptingscript\_include\_adminRole required to have granular access to sys\_script\_include.
Platform Server - Side Scriptingsys\_es\_latest\_script\_adminRole required to have granular access to sys\_es\_latest\_script.
Platform Server - Side Scriptingsysevent\_script\_action\_adminRole required to have granular access to sysevent\_script\_action\_admin.
Platform Data Fabricdf\_connection\_adminRole required to establish connection to available data sources as a connection admin, and manage access to these connections for data steward users.
Platform Deployment Analyzerdeployment\_analyzer\_adminRole required to access Deployment Analyzer tables to set up and see results for Deployment Analyzer. Doesn’t have access to create script includes.
Platform Dev Sandboxsandbox\_managerRole required to manage the life-cycle of all developer sandboxes as a Sandbox Manager.
Platform Event Processingevents\_adminRole required to be a System Events administrator involved in the events processing feature of the system.
Platform ISMresponse\_header\_adminRole required to have read, write, create, delete, and list\_edit access for records in HTTP Response Header table \(sys\_response\_header\).
Platform Schedulerapp\_resource\_quota\_adminRole required to configure and manage Application Resource Quotas plugin.
Platform Schedulerbusiness\_calendar\_adminRole required to configure and manage plugins and features related to business calendars \(com.glide.business\_calendars, com.glide.business\_calendars.scheduled\_jobs\).
Platform Schedulersystem\_scheduler\_adminRole required to configure and manage scheduler-related plugins and features \(com.glide.system\_scheduler, com.snc.automation, com.snc.automation\_time\_zone, com.glide.stats.scheduler\) and access Scheduled Jobs dashboard in System Events and Jobs Dashboard plugin \(com.sn\_async\_dashboard\).
Plato Predictive Intelligenceml\_adminRole required to have access to create and retrain classification, similarity, and clustering models.
Playbookplaybook.adminRole required to have Playbook Admin access. Contains pd\_content\_author, pd\_operator, pd\_trigger\_author, pd\_author, playbook.localization, and pd\_cancel.
Proactive Promptssn\_pp.adminRole required to create and manage all Proactive Prompts configurations and features.
Process Miningsn\_process\_mining\_adminRole required to have admin access only for Process Mining workspace and can do certain actions limited to process mining only.
Public Sector Digital Servicessn\_gsm.adminRole required to provide delegated admin access to scoped applications built on the Public Sector Digital Services platform.
Role delegationrole\_delegator\_adminRole required for role delegation.
Rolesuser\_role\_history\_adminRole required to manage perform specific role related operations.
Retailsn\_retail.ro\_adminRole required to create retail organization and add members to the organization.
SBOMsn\_sbom\_core.adminRole required to create, read, edit data, and upload Software Bill of Materials \[SBOMs\]. This role is required for access to the SBOM Core modules in your instance. It inherits the roles from the Data Model for SBOM application.
Searchais\_adminRole required to administrate and configure AI Search functionality. Includes Search Applications, Search Profiles, Search Sources, Indexed Sources, and Properties necessary for administrating and configuring AI Search.
Searchts\_adminRole required to administrate and configure text search on an instance, enabling adjusting of ts\_weights and viewing or changing properties necessary for Text Search Administration.
Search UXais\_adminRole required to migrate admin ACLs to a more granular role for ai-search-admin, semantic\_search, com.glide.search.analytics, com.glide.search.signal\_data, and com.glide.signals.
Security Centersn\_vsc.security\_center\_adminRole required to have admin access for Security center store application.
Security Operations - Data Loss Preventionsn\_dlir.adminRole required for administrative access to the Data Loss Prevention application.
Security Operations - Security Incident Response integrationssn\_si.ingestion\_profile\_adminRole required to configure the plugin and to create, edit, delete, and maintain ingestion profiles. - Microsoft Azure Sentinel integration - Splunk Enterprise Security Event Ingestion integration - Splunk Enterprise Event Ingestion integration - Cortex XSIAM by Palo Alto Networks - Microsoft Defender integration - CrowdStrike Next-Gen SIEM integration
Security Operations - Security Incident Responsesn\_si.adminRole required for administrative access to the Security Incident Response application.
Security Operations - Now Assist for Security Incident Responsesn\_si.adminRole required for administrative access to the Now Assist for Security Incident Response application.
Security Operations - Threat Intelligence Security Centersn\_sec\_tisc.adminRole required for administrative access to the Threat Intelligence Security Center application.
Security Posture ControlSPC Admin GroupGroup required for full read and write access to all the records for Security Posture Control, including licensing information. Granular roles for this group include: \[sn\_sec\_caasm.analyst, sn\_sec\_caasm.caasm\_security\_admin, and sn\_sec\_spc\_core.configure\].
Service Applicant Informationsn\_svc\_appl\_info.adminRole required to provide delegated admin access to the Service Applicant Information application.
Service Applicant Program Managementsn\_svc\_appl\_pgm\_mg.adminRole required to provide delegated admin access to the Service Applicant Program Management application.
Service Catalogcatalog\_adminRole required to manage the Service Catalog application, including catalogs, categories, and items, but not including scripting functions available to administrators.
Service Graph ConnectorsadminRole required to install and upgrade Service Graph Connectors, including API Service Graph Connectors. Admin users can create a connection, configure connection properties, monitor connections and data imports, run background scripts, and provide access to tables in the global scope.
Service Graph Connectorssn\_cmdb\_int\_util.sgc\_adminRole required to create, update, and delete connections, configure connectors using the guided setup, and read and write system properties.
Service Graph Connectorscmdb\_inst\_adminRole required to read all Service Graph Connector application modules, read and write system properties, and read records that are owned by other applications and are related to the functionality of Service Graph Connectors. Users with this role can create, update, and delete custom tables, scheduled imports, and data sources.
Service Level Managementsla\_adminRole required to configure Service Level Management features and system properties.
ServiceNow Studiosn\_udc.adminRole required to - Manage all ServiceNow Studio system properties, settings, and configurations. - Manage roles and permissions specific to ServiceNow Studio. - Configure the experience switcher roles across Creator Studio, ServiceNow Studio, and ServiceNow IDE.
ServiceNow Studiosn\_prfrd\_tables.adminRole required to configure preferred tables in your instance for Table Builder.
ServiceNow Vaultsn\_vault\_console.vault\_console\_adminRole required to have a collection of Data Classification admin, Data Privacy admin, and CA Admin roles to execute a template flow and monitor sensitive data. To learn more, see Configuring ServiceNow Vault
ServiceNow Vaultsn\_vault\_console.vault\_console\_auditorRole required to have a collection of Data Discovery Auditor, Data Classification Auditor, Data Privacy Auditor, and Continuous Auth Auditor roles to view the policies and metrics related to ServiceNow Vault.
ServiceNow for Teams – Coresn\_now\_teams.adminRole required to manage ServiceNow for Teams configurations, including system properties, Virtual Agent configuration, manifest settings, UI actions, and table-level ACLs.
Skills Foundationsn\_skills\_int.adminRole required to configure system settings with complete access to all the Skills Foundation features and functionality related to the employee.
Skills Foundationsn\_skills\_int.job\_arch\_adminRole required to view, create, update, remove, and configure the job architecture data.
Smart Operationssn\_smartops.adminRole required to serve as the Super Admin for Smart Operations. Has full privileges to perform all CRUD \(Create, Read, Update, Delete\) operations across Smart Operations tables, APIs, and data brokers.
Social Benefits Playbooksn\_gsm\_soc\_bnfts.adminRole required to provide delegated admin access to the License and Permit Playbook application.
System Engineering Coreopenstack\_adminRole required to have full administrative access to OpenStack compute, storage, and network.
System Engineering Corevcenter\_adminRole required to have full administrative access to vCenter: VMs, clusters, storage, and hosts.
System Logs \(Log Entry\)syslog\_adminProvides create/write access to Log Entry \(syslog\) records. The previous admin role ACL bindings on the syslog table are deleted and replaced with these new granular roles.
Talent Feedbacksn\_tf.adminRole require to manage and configure all Talent Feedback modules.
Task Miningsn\_tm\_core.adminRole required to have admin access for Process mining application.
Third-party risk managementsn\_vdr\_risk\_asmt.vendor\_risk\_adminRole required to have admin access for third-party risk management.
Transaction Part Metrics Logstxn\_part\_metrics\_adminProvides create, write, and delete access to the syslog\_transaction\_part\_metrics table. The previous admin role ACL bindings on this table are deleted and replaced with these new granular roles. New ACLs for all five operations \(read, create, write, delete, report\_view\) are introduced, each gated by the appropriate new role.
TSOM Visibilitytsom\_visibility\_adminRole required to manage the operational tasks for the TSOM Visibility application.
TSOM Assurancetsom\_assurance\_adminRole required to manage the operation tasks \(includes administration\) for the TSOM Assurance.
UI Builderui\_builder\_adminRole required to have admin access for UI Builder.
Usage Analyticsusage\_adminRole required to have admin access for usage analytics.
Universal Requestsn\_uni\_req.ur\_adminRole required to setup and configure Universal Request.
Universal Tasksn\_uni\_task.adminRole required to have full administrator access to Universal Task — configure task types, templates, and settings.
Universal Tasksn\_uni\_task.emp\_form\_adminRole required to manage employee forms.
Usage Insightsanalytics\_adminRole required to have admin access for Usage Insights.
User Experience-Scopesn\_cda.analytics\_adminRole required to have access to User Experience resources as Scope app admin.
Vulnerability Responsesn\_vul.vulnerability\_adminRole required for complete access to the Vulnerability Response \(VR\) application and its records. Users with this role configure all VR applications and rules and can install third-party integrations.