Interested in a ServiceNow event built for developers? Registration for now[dev]26 is officially open!

Application Navigator/All Menu Configuration

senneitz
Tera Contributor

What is the best practice for configuring the Application Navigator (All Menu) for users?

We have come across varying answers from restricting by role to disabling or even deleting applications and modules. We would like some clarification about what the best practice would be, so we can provide a better experience to our users by removing unnecessary options from their All Menu.

 

Thank you.

1 ACCEPTED SOLUTION

TharaS657398130
Tera Guru

Hello,

My view is that the best practice is to keep the Application Navigator role-based rather than deleting or heavily modifying the OOTB applications and modules. First understand which users actually need the application and what roles they have, and then use those roles to control what they see in the All Menu. This keeps the user experience clean without changing the underlying OOTB configuration.

 

If a module is genuinely not required anywhere, disabling it can be considered, but I would avoid deleting OOTB application menus because it can create unnecessary customization and upgrade/maintenance issues.

Also, hiding something from the All Menu should not be treated as a security control — ACLs and roles should still control whether the user can actually access the data. 

Hope it helps!

View solution in original post

4 REPLIES 4

SVimes
Mega Sage

This is one of those questions where one size certain does NOT fit all. It is most certainly based on needs. I would add the caveat that OOTB applications / modules are typically intended to be accessed based on role assignment specifically, so understanding the application first would be helpful in determining the course of action you take. Outright deleting application menus is not a recommended approach unless you intend to customize the application menus entirely.

Sable Vimes - CSA | CAD | CIS-DF | CIS-ITSM

TharaS657398130
Tera Guru

Hello,

My view is that the best practice is to keep the Application Navigator role-based rather than deleting or heavily modifying the OOTB applications and modules. First understand which users actually need the application and what roles they have, and then use those roles to control what they see in the All Menu. This keeps the user experience clean without changing the underlying OOTB configuration.

 

If a module is genuinely not required anywhere, disabling it can be considered, but I would avoid deleting OOTB application menus because it can create unnecessary customization and upgrade/maintenance issues.

Also, hiding something from the All Menu should not be treated as a security control — ACLs and roles should still control whether the user can actually access the data. 

Hope it helps!

Hi Tera,

I'm on Sen's Team and I like your answer a lot and wanted to see what you would suggest for a scenario we may come across. 

 

So there's a number of OOB Application Menu's that don't get used by anyone. And the only role assigned to them is snc_internal which is granted to a lot of users and snc_internal contains other Application Menu's we'd like those users to keep. What would you suggest we did with the OOB Application Menu's that fit into this category?

albert64chase
Mega Contributor

Best practice is generally to restrict the Application Navigator based on user roles/responsibilities rather than deleting applications or modules. Use roles, menus, and responsibilities to expose only the functions users need, while keeping the underlying applications intact for future requirements and easier maintenance/upgrades. Avoid deleting or disabling seeded applications unless there is a specific security or functional reason; a role-based configuration provides a cleaner user experience without compromising system integrity.