Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Platform security granular admin roles

Use granular admin roles to verify access management by assigning roles that define user permissions and responsibilities.

Tip: Use the search field to filter the granular admin role by entering keywords related to the role name or product.

ProductRole requiredRole description
Access Analyzeraccess\_analyzer\_adminRole required to access the Access analyzer to compare user records and access, simulate user access, and view access insights. To learn more, see Access Analyzer.
Adaptive Authenticationadaptive\_auth\_adminRole required to configure adaptive authentication policies. To learn more, see Adaptive authentication.
Authentication Factorsauth\_factors\_adminRole required to configure authentication for voice agent environments, with the factors that first identify the caller, then authenticate them before granting access.
API Access Policies, API Auth Scopes, Processor Access Policies- api\_service\_admin - adaptive\_auth\_policy\_adminRole required to enable users to configure non-oauth related functionality like REST or SOAP policies, inbound authentication profiles, token based auth, processors.
Custom URLcustom\_url\_adminRole required to configure custom URL, view datacenters jobs in read-only mode, and select portal and SSO records. To learn more, see Custom instance URLs.
E-signature with SSO- sso\_config\_admin - script\_include\_admin - ui\_page\_adminRole required to configure E-signature with SSO \(SAML or OIDC\) only and not required if using local database login. To learn more, see E-signature for Multi-Provider SSO.
Encryptionsecurity\_adminRole required to perform security operations as an admin.
Encryptionsn\_kmf.adminRole required to have admin and security admin access to be sn\_kmf.admin. Can assign sn\_kmf.cryptographic\_manager or sn\_kmf.cryptographic\_auditor role to other users and has read, write, and execution permissions for key operations.
Encryptionsn\_kmf.cryptographic\_auditorRole required to have read permission for key operations.
Encryptionsn\_kmf.cryptographic\_managerRole required to have read, write, and execution permissions for key operations.
Federated IDiamsync\_adminRole required to manage the Federated ID and read or write Federated ID related property. To learn more, see Global Identity.
Identity AI Agentai\_user\_adminRole required to manage AI user identities within the instance. They can create,edit,delete AI users, and assign or remove roles associated with them.
Identity AI Agentagent\_role\_config\_adminRole required to configure and manage AI agent access during agentic workflow execution. You can mask roles for AI agents using the Agent Access Role Configurations table helping protect sensitive data and enforce role-based restrictions.
Identity AI Agentagent\_role\_config\_viewerRole required to view existing records on the Agent Access Role Configurations table.
Identity and Access auditidentity\_access\_audit\_viewer It contains: - role\_viewer - group\_viewerRole required to view the User Trails, Group Trails, Role Trails, ACL Trails and Audit results.
Identity and Access auditsecurity\_adminRole required to:- Configure Retention Period, Configure Tables & Fields. - Change identity security audit feature property.
Identity Centeruser\_login\_history\_viewerRole required to view login history details in the Identity Center, including login timestamps, browser information,IP address, and login status. Supports security investigations by enabling filtered views of login actions and helps identify suspicious activity. To learn more, see Identity Center for users.
Identity Centerprivileged\_role\_config\_adminRole required to grants full access to manage role configurations in the Identity Center, including adding, deleting, creating, reading, and viewing reports in the sys_icenter_role_config table. To learn more, see Identity Metrics for administrators.
Identity Centerrole\_viewerRole required to only view the records in the sys_icenter_role_config table. To learn more, see Identity Center for users.
Instance operatorinstance\_operatorIt contains: - identity\_access\_audit\_viewer - user\_role\_history\_viewerRole required to manage perform specific role related operations and know about identity access audits.
Machine Identity Consolemi\_adminRole required to manage identities that interact with systems and data. To learn more, see Machine Identity Console.
Password policypassword\_policy\_adminRole required to configure password policy-related items. To learn more, see Local authentication
Role delegationrole\_delegator\_adminRole required for role delegation.
Rolesuser\_role\_history\_admin It contains: - user\_role\_history\_viewer - role\_viewerRole required to manage perform specific role related operations.
SCIMscim\_adminRole required to configure and manage SCIM provisioning, including creating customization properties, supported and extension schema, and ETL definitions for user and group data. To learn more, see System for Cross-domain Identity Management (SCIM).
SCIM custom schemascim\_config\_adminRole required to configure SCIM custom schema and system properties. To learn more, see SCIM customization properties and schemas.
SCIM Clientscim\_client\_config\_adminRole required to configure SCIM Client. To learn more, see SCIM Client.
SCIM Providerscim\_adminRole required to configure SCIM Provider. To learn more, see SCIM Provider.
Self-Register to ServiceNow instanceexternal\_user\_self\_registration\_adminRole required to on-board a large volume of external users to your instance. To learn more, see Self-register to ServiceNow instance.
ServiceNow Vaultsn\_vault\_console.vault\_console\_adminRole required to have a collection of Data Classification admin, Data Privacy admin, and CA Admin roles to execute a template flow and monitor sensitive data. To learn more, see Configuring ServiceNow Vault
ServiceNow Vaultsn\_vault\_console.vault\_console\_auditorRole required to have a collection of Data Discovery Auditor, Data Classification Auditor, Data Privacy Auditor, and Continuous Auth Auditor roles to view the policies and metrics related to ServiceNow Vault.
SSO \(SAML and OIDC\)- sso\_config\_admin - business\_rule\_admin - script\_include\_adminRole required to configure SSO configuration \(SAML or OIDC\). To learn more, see Multi-Provider single sign-on (SSO).
System OAuthoauth\_admin

Role required to configure all OAuth related functionality. To learn more, see OAuth Inbound and Outbound authentication.Note: You must assign the following roles for the following configurations:

  • The admin role for non out of the box properties.
  • The script_include_admin to change existing scripts (JWT, and so on).
Time limited roleuser\_adminRole required to assign a role to a user temporarily, usually if the user must perform a one-time action that is normally not permissible by their role.
User Impersonationuser\_impersonation\_history\_viewerRole required to see the user impersonation history table.
Security Centersn\_vsc.security\_center\_adminRole required to access Security Center consoles and tools. Users with this role can also create and manage security tasks.

Parent Topic:Granular admin roles