Proposed process for handling unauthorized changes detected on CIs in CMDB

RohitJ432388693
Tera Contributor

I'm working on a process for handling unauthorized changes detected on Configuration Items (CIs) in ServiceNow and would appreciate feedback from those who have implemented something similar.

The objective is to ensure every unauthorized change is either:

  • formally approved after the fact (if acceptable), or

  • rolled back and properly documented.

My proposed workflow is as follows:

  1. An unauthorized change is detected on a CI.

  2. A Change record is automatically created (or the detected change is associated with one) and assigned to the Change Approver Group (CAG).

  3. A Change Task is created for the Change Approver Group to review the unauthorized change.

  4. The affected CI Owner is notified with the change details.

  5. The Change Approver Group reviews the change.

    • If approved: the change is retained, the Change is approved and closed.

    • If rejected: a task is assigned to the individual/team that performed the unauthorized change, instructing them to roll back the CI to its previous state.

  6. After rollback is completed, the Change Approver (and CI Owner, if appropriate) is notified.

  7. The Change record is then closed.

Would someone please advise if this is a good process?

What have you done in your org?

https://www.servicenow.com/docs/r/it-service-management/change-management/unauthorized-change-reques...

https://www.servicenow.com/community/cmdb-articles/video-servicenow-unauthorized-change-detection/ta...




0 REPLIES 0