Some PDIs are currently unavailable, and PDI actions are paused. View the latest updates here. Read More

How are others maintaining Practice Area Leads with least‑privilege access?

Adam Robbins1
Mega Guru
How are others handling the ongoing maintenance of Practice Area Leads? I noticed the sn_lg_ops.request_config role, but from what I can tell it allows users to make configuration changes directly in production. In our environment, we follow a least‑privilege model, and configuration changes are expected to flow through a formal change control process before moving to prod. I’m curious how others have balanced this requirement with the need to maintain Practice Area Leads efficiently.
1 ACCEPTED SOLUTION

Tanushree Maiti
Tera Patron

Hi @Adam Robbins1 ,

 

Any configurational change in Production or Sub -production Admin only does. Admin is also having this sn_lg_ops.request_config  role.

 

 

As per ServiceNow documentation : Components installed with Legal Request Management 

 

Table (Practice Area Lead) installed with Legal Request Management

Practice Area Lead

[sn_lg_ops_m2m_practice_area_lead]

Stores practice area leads for different practice areas.

 

Role who  has access on Practice Area lead Table configuration

Legal Configurator

[sn_lg_ops.legal_config]

Provides access to configure data such as practice area, category, and legal matter templates. It doesn’t provide access to the transactional data of legal requests and matters.
  • sn_lg_contracts.contracts_config
  • sn_lg_forensics.forensics_config
  • sn_lg_investigate.config
  • sn_lg_ops.request_config
  • sn_lg_matter.matter_config

 

Request Administrator

[sn_lg_ops.request_admin]

Provides administrative access to the Legal Request module with full access to data.
  • sn_lg_ops.legal_catalog_admin
  • sn_lg_ops.request_config
  • sn_lg_ops.request_manager

 

 

On Record level (Transactional data) , these roles have access

Request Manager

[sn_lg_ops.request_manager]

Provides access to all transactional data of legal requests and permission to assign requests.

sn_lg_ops.request_fulfiller

Request Configurator

[sn_lg_ops.request_config]

Provides access to configure data such as a practice area and category, and manage record producers through Catalog Builder. It does not provide access to the transactional data of legal requests.
  • catalog_builder_editor
  • catalog_editor
  • connection_admin
  • email_client_quick_message_author
  • sla_manager
  • sn_lg_ops.legal_assignment_rules_admin
  • sn_lg_ops.legal_notification_admin
  • sn_lg_ops.legal_user
  • sn_lg_stock_cp.stock_config
  • sn_templated_snip.template_snippet_writer
Legal Manager

[sn_lg_ops.legal_manager]

Provides access to all transactional data of legal requests and matters and permission to assign owners for requests and matters.
  • sn_lg_coi.coi_fulfiller
  • sn_lg_ops.legal_event_manager
  • sn_lg_ops.request_manager
  • sn_lg_matter.matter_manager
Legal Configurator

[sn_lg_ops.legal_config]

Provides access to configure data such as practice area, category, and legal matter templates. It doesn’t provide access to the transactional data of legal requests and matters.
  • sn_lg_contracts.contracts_config
  • sn_lg_forensics.forensics_config
  • sn_lg_investigate.config
  • sn_lg_ops.request_config
  • sn_lg_matter.matter_config
Please Accept the solution if it assisted you with your question & Mark this response as Helpful.
Regards
Tanushree Maiti
ServiceNow Technical Architect
LinkedIn: https://www.linkedin.com/in/tanushreemaiti

View solution in original post

1 REPLY 1

Tanushree Maiti
Tera Patron

Hi @Adam Robbins1 ,

 

Any configurational change in Production or Sub -production Admin only does. Admin is also having this sn_lg_ops.request_config  role.

 

 

As per ServiceNow documentation : Components installed with Legal Request Management 

 

Table (Practice Area Lead) installed with Legal Request Management

Practice Area Lead

[sn_lg_ops_m2m_practice_area_lead]

Stores practice area leads for different practice areas.

 

Role who  has access on Practice Area lead Table configuration

Legal Configurator

[sn_lg_ops.legal_config]

Provides access to configure data such as practice area, category, and legal matter templates. It doesn’t provide access to the transactional data of legal requests and matters.
  • sn_lg_contracts.contracts_config
  • sn_lg_forensics.forensics_config
  • sn_lg_investigate.config
  • sn_lg_ops.request_config
  • sn_lg_matter.matter_config

 

Request Administrator

[sn_lg_ops.request_admin]

Provides administrative access to the Legal Request module with full access to data.
  • sn_lg_ops.legal_catalog_admin
  • sn_lg_ops.request_config
  • sn_lg_ops.request_manager

 

 

On Record level (Transactional data) , these roles have access

Request Manager

[sn_lg_ops.request_manager]

Provides access to all transactional data of legal requests and permission to assign requests.

sn_lg_ops.request_fulfiller

Request Configurator

[sn_lg_ops.request_config]

Provides access to configure data such as a practice area and category, and manage record producers through Catalog Builder. It does not provide access to the transactional data of legal requests.
  • catalog_builder_editor
  • catalog_editor
  • connection_admin
  • email_client_quick_message_author
  • sla_manager
  • sn_lg_ops.legal_assignment_rules_admin
  • sn_lg_ops.legal_notification_admin
  • sn_lg_ops.legal_user
  • sn_lg_stock_cp.stock_config
  • sn_templated_snip.template_snippet_writer
Legal Manager

[sn_lg_ops.legal_manager]

Provides access to all transactional data of legal requests and matters and permission to assign owners for requests and matters.
  • sn_lg_coi.coi_fulfiller
  • sn_lg_ops.legal_event_manager
  • sn_lg_ops.request_manager
  • sn_lg_matter.matter_manager
Legal Configurator

[sn_lg_ops.legal_config]

Provides access to configure data such as practice area, category, and legal matter templates. It doesn’t provide access to the transactional data of legal requests and matters.
  • sn_lg_contracts.contracts_config
  • sn_lg_forensics.forensics_config
  • sn_lg_investigate.config
  • sn_lg_ops.request_config
  • sn_lg_matter.matter_config
Please Accept the solution if it assisted you with your question & Mark this response as Helpful.
Regards
Tanushree Maiti
ServiceNow Technical Architect
LinkedIn: https://www.linkedin.com/in/tanushreemaiti