Skip to content
Release: Australia · Updated: 2026-04-23 · Official documentation · View source

Agentic AI security and governance

Now Assist AI agents operate securely within the boundaries you define. Layered controls govern who can invoke each agent, what data it can access, how interactions are monitored, and how your organization retains oversight.

Deploying AI agents introduces security considerations that go beyond standard platform hardening. Agents act autonomously, invoke tools, access data, and make decisions on behalf of users. This requires controls at every layer: who can invoke an agent, what it can access once running, how its actions are logged, and what catches harmful or unintended behavior at runtime.

Now Assist is built on the ServiceNow AI Platform security model. AI agents are subject to the same ACL enforcement, role-based access controls, and domain separation that govern all platform activity. The controls in these sections extend that foundation with capabilities specific to agentic AI. These include identity classification for AI users, role masking to enforce least-privilege during tool execution, and runtime guardrails through Now Assist Guardian. Readiness assessment tools help verify your instance is prepared before agents go to production.

AI security concepts

AI security products

  • Permissions-based access control
    Use Agent Role Inheritance, identity types, and granular roles to verify your AI agents have only the permissions they need, and can act only within their intended boundaries.
  • Data protection
    Learn how ServiceNow security tools such as the Key Management Framework, Field Encryption, and Data Classification work to keep your data secure.
  • Agent traceability and monitoring
    Learn how to use tools like AI Control Tower to track, monitor, and report on your AI assets.
  • Governance and admin safeguards
    Find guidance on preparing your instance for AI deployment, maintaining domain separation, and reducing risk across your Now Assist implementation.
  • AI threat protection
    Learn how Now Assist helps defend against AI-specific threats including offensive content, prompt injection, and sensitive subject detection using Now Assist Guardian.
  • External AI agent security
    Learn how to monitor and govern AI agents from external providers, with visibility into third-party data flows and assurances that sensitive data stays properly isolated across your AI ecosystem.
  • Now Assist Guardian
    Now Assist Guardian is built on the ServiceNow Small Language Model (SLM) and monitors generative AI interactions to detect offensive content, prompt injection attacks, and sensitive topics.
  • Create and secure an AI agent in Now Assist
    Plan, build, secure, test, and deploy a Now Assist AI agent.