Interested in a ServiceNow event built for developers? Registration for now[dev]26 is officially open!

Best way to make requests of a cat item visible only to a specific assignment group and its members

MariaPravin
Tera Contributor

I want to make RITMS and tasks belonging to a specific catalog item visible to only one assignment group and it's members. It should be hidden from everyone else. This is due to privacy restrictions. What is the best way to do this? Is there a way to do this without touching ACLs or creating a custom role?

3 REPLIES 3

AndersBGS
Tera Patron

Hi @MariaPravin 

 

Yes there is - I would suggest that you could look into data filtration rule which is the exact purpose. It should be available OOTB.

 

If my answer has helped with your question, please mark my answer as the accepted solution and give a thumbs up.

Best regards
Anders

Rising star 2024
MVP 2025
linkedIn: https://www.linkedin.com/in/andersskovbjerg/

IbrarA
Kilo Sage

Hi @MariaPravin 

Hiding records from people is what ACLs are for, so there isn't a clean way around them here. You can skip the custom role though.

The catch is that ACLs grant access rather than take it away. A normal read ACL won't remove what the existing ACLs on sc_req_item already allow, so people carry on seeing the records. That thread is a good example, they built one with a custom role and it made no difference: https://www.servicenow.com/community/developer-forum/hide-visibility-of-ritm-and-sctask-of-1-catalog...

Use a Deny Unless read ACL on sc_req_item instead. That decision type runs first and blocks anything failing its condition, and nothing else can hand the access back. Your condition would be that the item isn't this one, or the user is in that group, which gs.getUser().isMemberOf() covers. Then repeat it on sc_task.

https://www.servicenow.com/docs/r/platform-security/access-control/acl-denial-behavior.html

 

Thanks

ibrar

Aditya_hublikar
Giga Sage

Hello @MariaPravin ,

 

For true privacy, the best approach is to use ACLs. UI filters, Client Scripts can hide RITMs/tasks from the UI, but users may still access them directly.

You can avoid creating a custom role by creating a Read ACL that checks:

  • RITM/Task belongs to the specific Catalog Item
  • User is a member of the required Assignment Group

For example:

Specific Catalog Item + User is member of Group => Allow access
Otherwise => Deny access

As per my understanding , without ACLs, there is no reliable way to enforce this privacy requirement.

 

If this helps you then mark it as helpful and accept as solution.

Regards,

Aditya