Interested in a ServiceNow event built for developers? Registration for now[dev]26 is officially open!

Can sys_audit_role be archived by changing no_archive=true to no_archive=false?

GASHOK
Tera Contributor

Hi Community,

We are using the OOB Audit Roles [sys_audit_role] table to track user role additions and removals.

In our instance, the Dictionary entry for sys_audit_role has the attribute:

no_archive=true

Because of this, the table is not available for standard ServiceNow Archive Rules.

 I would like to understand the following:

1)Is sys_audit_role officially supported for archiving?

2)What is the purpose of no_archive=true on this table?

3)What would happen if we changed it to no_archive=false?

4)Would changing this attribute allow us to create a standard Archive Rule for sys_audit_role?

5)Are there any known risks or upgrade/customization impacts from changing this OOB attribute?

6)If archiving sys_audit_role is not supported, what is the recommended ServiceNow approach for long-term retention of these audit records?

7)We are using the Zurich release and would prefer an OOB/supported solution rather than customizing the audit mechanism.

Any guidance or official documentation would be appreciated.


@Dr Atul - LNG 

 

2 REPLIES 2

Dr Atul - LNG
Tera Patron

Hi @GASHOK 

I don't have much idea about this,  so i asked AI and hope it provides some guidance 

 

 

Yes. I checked the ServiceNow Zurich documentation specifically and would frame the answers this way. One important distinction: ServiceNow's public Zurich documentation documents sys_audit_role as an OOB audit table and documents audit-retention controls, but I could not find a Zurich public document that explicitly states "sys_audit_role is supported for System Archive" or that documents no_archive=true on that table. So I would avoid presenting the latter as a formally documented ServiceNow support statement.

ServiceNow Zurich — answers

# Question ServiceNow Zurich answer
1 Is sys_audit_role officially supported for archiving? No documented OOB support found. ServiceNow documents sys_audit_role as the Audit Roles table used to track role changes, but the Zurich Data Archiving documentation does not identify it as a supported table for customer-created Archive Rules. ServiceNow's documented archiving use cases focus on core transactional tables and custom tables. (ServiceNow)
2 What is the purpose of no_archive=true on this table? no_archive=true is an OOB dictionary/table attribute that prevents the table from being processed by the normal ServiceNow archiving mechanism. In the case of sys_audit_role, this is consistent with ServiceNow treating it as a specialized/system audit table rather than a normal business-data table. However, I could not find a public Zurich document that explicitly explains the reason ServiceNow placed this attribute on sys_audit_role.
3 What happens if we change it to no_archive=false? You would be removing the table-level exclusion from the archive mechanism. That does not mean ServiceNow guarantees that archiving sys_audit_role is supported. It would merely make the table eligible from the perspective of that particular attribute. The archive engine could then potentially allow/create processing that ServiceNow has not documented as supported for this table.
4 Would changing it allow us to create a standard Archive Rule for sys_audit_role? Possibly from a technical/UI perspective, but this should not be interpreted as making the configuration OOB-supported. A standard Archive Rule moves records to an ar_ archive table and applies ServiceNow's archive processing. ServiceNow does not document sys_audit_role as a supported Archive Rule target in Zurich. (ServiceNow)
5 Risks / upgrade / customization impacts? Yes. I would consider changing it an OOB customization and therefore unsupported unless ServiceNow explicitly approves it for your use case. The attribute is part of the table/dictionary configuration, and ServiceNow states that dictionary entries define table behavior. An upgrade or application/plugin update could overwrite or change the OOB definition. More importantly, you would be moving a specialized audit table outside the lifecycle ServiceNow designed for it. (ServiceNow)
6 If archiving sys_audit_role isn't supported, what is the recommended OOB approach for long-term retention? Use ServiceNow's Audit Management / Audit Retention capability rather than modifying the table or archive mechanism. In Zurich, ServiceNow provides Audit Management Console → Retention to configure retention for audit data. This is the OOB mechanism ServiceNow documents for controlling audit-data retention. (ServiceNow)
7 Zurich + preference for OOB/supported solution I agree with that approach: do not change no_archive on sys_audit_role as the first solution. Keep the OOB table definition and use the supported audit-retention functionality. If the requirement is specifically “retain role-audit records for X years in an accessible archive”, rather than simply retaining/purging them, that is a different requirement and should be validated with ServiceNow Support because the Zurich public documentation does not describe a supported System Archive pattern for sys_audit_role.

The important point about sys_audit_role

ServiceNow explicitly documents this table in Zurich:

Audit Roles [sys_audit_role] displays changes to user roles.

It records information such as Changed by, Operation, Role, User, Granted by group, and Count after change. (ServiceNow)

It is also populated by the OOB role-auditing capability when the relevant property is enabled. ServiceNow documents the property:

glide.role_management.v2.audit_roles = true

for enabling role auditing with Contextual Security: Role Management V2. (ServiceNow)

That is important because this isn't simply an ordinary custom table containing business transactions. It is a platform audit mechanism.


What I would recommend for your Zurich instance

I would not do this:

sys_audit_role
    no_archive = false
        ↓
Create Archive Rule
        ↓
Archive to ar_sys_audit_role

That approach changes an OOB platform-table configuration in order to make it fit the generic Data Archiving framework.

Instead, use:

sys_audit_role
      ↓
OOB Role Auditing
      ↓
ServiceNow Audit Management / Audit Retention
      ↓
Configured retention period

ServiceNow's Zurich documentation specifically provides Audit Management Console → Retention for automating deletion of audit data according to the configured retention requirement. Records older than the configured duration are purged and cannot be restored. (ServiceNow)

So there are actually two different requirements:

A. "We need to keep role-audit records for 7 years."

→ Configure an appropriate audit retention period.

B. "We need to move role-audit records out of the primary table but still retain them for 7 years in an archive table."

→ This is not the same thing, and I would not implement it by changing no_archive=true without explicit confirmation from ServiceNow Support that sys_audit_role is supported for System Archive in Zurich.


Why I would be cautious about the no_archive change

ServiceNow's general Data Archiving documentation says that when an Archive Rule is activated, ServiceNow creates an ar_ table and moves qualifying records from the primary table into it. (ServiceNow)

But ServiceNow also has special handling/restrictions around system/audit tables. For example, the Zurich documentation explicitly says that certain internal/peripheral tables cannot be selected as related records for archive processing, including sys_audit, sys_audit_delete, and sys_audit_relation. (ServiceNow)

That doesn't explicitly say "sys_audit_role cannot be archived," so I would not overstate that conclusion. But it is a strong indication that ServiceNow treats audit/system tables differently from ordinary application tables.

Bottom line

My ServiceNow-supported recommendation for Zurich would be:

Do not change no_archive=true on the OOB sys_audit_role table. Do not create an Archive Rule by overriding that OOB attribute unless ServiceNow Support confirms that configuration is supported. Use the OOB Audit Retention capability for retention/purge requirements. If the requirement specifically calls for moving sys_audit_role data to an archive table for long-term retention, raise a ServiceNow Support case to obtain an explicit supported architecture for that requirement.

Official ServiceNow references

One qualification: ServiceNow's public Zurich documentation does not appear to explicitly document the rationale for the specific no_archive=true attribute on sys_audit_role, nor does it explicitly publish a statement saying "sys_audit_role is unsupported for Archive Rules." Therefore, for an audit/compliance decision, I would phrase those two points as “not documented as supported”, rather than claiming ServiceNow has explicitly declared them unsupported.

****************************************************************************************
Regards
Dr Atul G. - Learn N Grow Together ServiceNow Techno - Functional Trainer
LinkedIn: https://www.linkedin.com/in/dratulgrover
YouTube: https://www.youtube.com/@LearnNGrowTogetherwithAtulG
******************************************************************************************

daniel603ma
Mega Contributor

Hello,

sys_audit_role is OOB and explicitly marked no_archive=true, I’d treat that as an intentional platform design choice and seek ServiceNow confirmation before changing it; a supported retention strategy is much safer than altering the dictionary and risking upgrade or support issues.