Restrict Visibility of Incidents to Assignment Groups Using ACLs

kishoreareg
Tera Contributor

We are considering implementing ACL-based access controls to restrict visibility of Incident records assigned to the following assignment groups:

  • PSO-PLATFORMS-SOC-L1
  • PSO-PLATFORMS-SOC-L2

The requirement is that Incident records assigned to these groups should be accessible and visible only to members of the respective SOC assignment groups (and any authorized security administrators). All other users across the organization should be prevented from viewing or accessing these incidents. We are looking to achieve this requirement primarily through ServiceNow ACLs and would like to understand the recommended approach and best practices for implementation.

1 REPLY 1

Ankur Bawiskar
Tera Patron

@kishoreareg 

if you use ACLs then the users will get the Security Constraint message

better to use ACL + Query BR combination for this

Remember there is OOTB query BR on incident and you can enhance that one as per your requirement

AnkurBawiskar_0-1786161680521.png

 

💡 If my response helped, please mark it as correct and close the thread 🔒— this helps future readers find the solution faster! 🙏

Regards,
Ankur
Certified Technical Architect  ||  10x ServiceNow MVP  ||  ServiceNow Community Leader