Unable to Make "admin" Role Visible in sys_user_role List Despite ACL Access
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
3 weeks ago
Hi Team,
I'm facing an issue with visibility of the admin role record in the sys_user_role table and would appreciate any guidance.
User Account Information
I am testing with a local ServiceNow user that has the following roles:
- snc_internal
- itil
- report_user
Problem
When the user navigates to the sys_user_role list, they receive the following message:
"Number of rows removed from this list by Security constraints: 1"
The missing record appears to be the admin role.
Expected Behavior
I would like this user to be able to view the admin role record in the Roles list (read-only access is sufficient).
Troubleshooting Performed
1. Debug Security Rules
- Impersonated the user and enabled Debug Security Rules.
- Accessed the sys_user_role table.
- Interestingly, the admin role record was visible while debugging.
- After disabling debugging and accessing the list again as the same user, the admin record was no longer visible.
2. Custom Read ACL
- Created a custom role.
- Added a Read ACL on sys_user_role.
- Assigned the custom role to the user.
- The issue persisted.
3. Access Analyzer
- Used Access Analyzer on the specific admin role record.
- The analysis indicates that the user passes the Read operation and has access to the record.
Question
Has anyone encountered this behavior before?
Are there any out-of-box security constraints, query business rules, data filtration mechanisms, before-query rules, or platform-level restrictions that specifically prevent non-admin users from viewing the admin role record, even when ACL evaluation indicates read access is granted?
Any suggestions on additional areas to investigate would be greatly appreciated.
Thanks in advance!
#AccessControlList #ACL
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
3 weeks ago
but what's your business requirement?
Ankur
✨ Certified Technical Architect || ✨ 10x ServiceNow MVP || ✨ ServiceNow Community Leader
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
3 weeks ago
The user is trying to create a report on sys_user_has_role table to find the admin users and apply filter "role " == "admin".
From Condition filter user tries selcting Role is admin with reference popup list. but not listing admin role. but able to see other roles.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
3 weeks ago
@Ankur Bawiskar - Just now got to know that if we apply role.name == admin solves this puzzle :)\
Any other suggestion appreciated
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
3 weeks ago
may be it's restricted for non-admins to select that role.
I think this workaround should be fine as of now
💡 If my response helped, please mark it as correct ✅ and close the thread 🔒— this helps future readers find the solution faster! 🙏
Ankur
✨ Certified Technical Architect || ✨ 10x ServiceNow MVP || ✨ ServiceNow Community Leader
