Skip to content
Release: Australia · Updated: 2026-05-26 · Official documentation · View source

Vault tools and metrics

Learn about the tools and metrics ServiceNow Vault uses to protect and discover sensitive data.

ServiceNow Vault integrates with several tools to provide you with a cohesive overview of your sensitive data security. You can hover over a widget to get further insight on the reported data. Select the Go to button on any tool to go to its respective page.

Know your data

ServiceNow Vault uses Data Discovery and Data Classification help you understand and know your data.

ToolMetricDescription
DiscoveryUse Data Discovery to run a discovery scan to look for data patterns that might be sensitive data. Once discovered, data can then be reviewed or classified for further protection and management.Discovered dataOccurrences of sensitive data across tables in your instance, categorized by sensitive data pattern type.
Discovery statusCurrent state of all discovered sensitive data patterns, including new findings pending review, classified, or marked as ignored.
Discovered attachmentsTotal sensitive data occurrences in attachments across tables in your instance.
ClassificationData Classification creates data classes and helps organize your data into data classes for better management. Classified data can be protected at the class level.Classifiable dataTables or columns that can be classified.
Classified dataDictionary entries, tables, or columns that are classified.

Protect your data

ServiceNow Vault uses data anonymization, cloud encryption, field encryption, log export, and zero trust access to help secure and protect your data.

ToolMetricDescription
AnonymizationAnonymize data by data class with different anonymization techniques to preserve data patterns but remove sensitive data. Useful for sanitizing instances for development or removing specific user data because of rights to be forgotten. Default real-time protection policies are available from this card and are applied in addition to any existing policies. For more information, see Default policies and configurations in ServiceNow Vault.Existing dataAll classified data per workflow that is anonymized or not.
Real time dataNumber of successful real-time calls to anonymize sensitive data as it enters the platform, by channel.
Anonymization run timesHow long scheduled user- or data-based jobs ran in hours for existing data.
Cloud Encryption with Key ManagementSecurely protect sensitive data in encrypted storage for your data using block encryption, along with enhanced key management.Active cloud keyTotal rotations of the active cloud key.Note: To view this data, you need the Key Management Framework admin role (sn_kmf.admin or sn_kmf.cryptographic_manager).
 Key rotationTime elapsed between each rotation of active keys on your instance. Bar height measures how long a key was used before rotation.Note: To view this data, you need the Key Management Framework admin role (sn_kmf.admin or sn_kmf.cryptographic_manager).
Field EncryptionSecurely protect sensitive data while providing access for authorized users. Useful for increasing protections from bad actors.Encrypted fields classification statusClassification status of all data protected with Field Encryption.
Classes protected with Field EncryptionThe proportion of classified data protected withField Encryption.
Active encryption keysNumber of active Field Encryption keys in your instance. Ideally, the number of active keys matches the number of classifications.Note: To view this data, you need the Key Management Framework admin role (sn_kmf.admin or sn_kmf.cryptographic_manager) and the security_admin role.
Exploring Log Export Service (LES)Forward your instance's logs to external analytics tools to monitor data patterns. New users can activate default configurations from this card. For more information, see Default policies and configurations in ServiceNow Vault.  
Zero Trust Access (ZTA)Continuous authentication while accessing classified sensitive data in real time. Default step-up authentication policies are available for Vault customers. For more information, see Default policies and configurations in ServiceNow Vault.Continuous Authentication classification statusNumber of classifications that are protected due to the Continuous Authentication policies.
Classes protected with Continuous authenticationNumber of classes protected with continuous authentication, categorized by class.

Monitor your data

The AI Insights section within ServiceNow Vault helps you keep track of activities that may indicate potential threats or data leaks.These activities are generated from channels such as Now Assist and Virtual Agent, as well as database tables configured with real-time discovery. This insight can help you prioritize your data protection strategies more effectively. Select View tool metrics to see the underlying metrics.

MetricChart ComponentDescription
User entering sensitive dataIn tables with real-time discoveryThe number of users whose sensitive data entries were detected in database tables configured with real-time discovery.
In channelsThe number of users whose sensitive data entries were detected within channels such as Now Assist or Virtual Agent.
Channels with sensitive dataChannel bars (x-axis)Stacked bars representing each channel where sensitive data was detected, broken down by data patterns. The data pattern legend displays the color code for each pattern. They may include driver license numbers, financial information, and personal identifiers.
Occurrences of sensitive data (y-axis)The count of sensitive data instances detected per channel.
Tables with sensitive data found through real-time discoveryTable bars (x-axis)Stacked bars representing each database table where sensitive data was detected, broken down by data patterns.
Occurrences of sensitive dataThe count of sensitive data instances detected per table.

All ServiceNow Vault tools

Parent Topic:ServiceNow Vault console dashboard