Locking RITM and REQ fields to fulfillers

DaveThibode
Tera Contributor

Good Day, when your fulfillers receive a task from an end user submitted Request, do you allow the fulfiller to go back and modify the original requests? in other words change data in it? such as the description or the requestor name? Our old system did not allow us to do that but in SN out of the box we can? What is the argument to either or?  We have a form managers submit to grant permission into different systems. If the fulfiller can modify the managers request, does it now become an security/audit issue? 

1 ACCEPTED SOLUTION

pratikjagtap
Giga Guru

Hi @DaveThibode ,

 

As an out-of-the-box behavior in ServiceNow, fulfillers with the appropriate roles can update certain fields on a Request or Requested Item. However, many organizations restrict edits to business-critical fields (such as the requestor, justification, or original description) to preserve audit integrity and meet security/compliance requirements.

For access requests, it's generally considered a best practice to treat the original manager's submission as immutable. If changes are required, they should be made through a controlled process (e.g., a new approval, amendment request, or additional audit comments) rather than modifying the original request. This helps maintain a clear audit trail and reduces the risk of unauthorized changes.

 

If my response helped, please hit the 👍Thumb Icon and accept the solution so that it benefits future readers.

 

Regards,
Pratik

View solution in original post

1 REPLY 1

pratikjagtap
Giga Guru

Hi @DaveThibode ,

 

As an out-of-the-box behavior in ServiceNow, fulfillers with the appropriate roles can update certain fields on a Request or Requested Item. However, many organizations restrict edits to business-critical fields (such as the requestor, justification, or original description) to preserve audit integrity and meet security/compliance requirements.

For access requests, it's generally considered a best practice to treat the original manager's submission as immutable. If changes are required, they should be made through a controlled process (e.g., a new approval, amendment request, or additional audit comments) rather than modifying the original request. This helps maintain a clear audit trail and reduces the risk of unauthorized changes.

 

If my response helped, please hit the 👍Thumb Icon and accept the solution so that it benefits future readers.

 

Regards,
Pratik