<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Restrict RITM visibility in SOW but allow full visibility in ESC in Service Operations Workspace forum</title>
    <link>https://www.servicenow.com/community/service-operations-workspace/restrict-ritm-visibility-in-sow-but-allow-full-visibility-in-esc/m-p/3439844#M3358</link>
    <description>&lt;P&gt;I’m still searching without success for a way… the ideal solution would be to identify and apply the user/agent’s UI Context (SOW, ESC,...) as a condition in the ACLs.&amp;nbsp;&lt;STRONG&gt;But since ACLs are executed on the server side, I believe that’s not possible &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Given that limitation, with ACLs I can restrict agents in the group so they can only see tickets from the categories they are allowed to manage, as well as their own tickets as end users.&lt;/LI&gt;&lt;LI&gt;But these ACLs apply to all user interfaces, both SOW and ESC.&lt;UL&gt;&lt;LI&gt;It’s not ideal, because in SOW they can see the inner workings of how other support groups manage their tickets&lt;/LI&gt;&lt;LI&gt;This gap can be minimized by hiding fields with client scripts… but it’s annoying and not very scalable/maintainable.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;U&gt;NOTE:&lt;/U&gt; I’m surprised not to find an effective/quick way to limit the visibility of certain agents inside the workspaces while keeping their permissions intact as end users in Employee Center. I’d say this must be a common problem, for example for specific agents handling confidential topics or HR cases.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I’ll share anything I find if I discover a workable solution.&lt;/P&gt;</description>
    <pubDate>Fri, 28 Nov 2025 14:45:08 GMT</pubDate>
    <dc:creator>Daniel_san</dc:creator>
    <dc:date>2025-11-28T14:45:08Z</dc:date>
    <item>
      <title>Restrict RITM visibility in SOW but allow full visibility in ESC</title>
      <link>https://www.servicenow.com/community/service-operations-workspace/restrict-ritm-visibility-in-sow-but-allow-full-visibility-in-esc/m-p/3438309#M3346</link>
      <description>&lt;P&gt;Hi everyone,&lt;BR /&gt;I need a group/role of agents to:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;In &lt;STRONG&gt;SOW&lt;/STRONG&gt; (Service Operations Workspace) or the &lt;STRONG&gt;Classic UI&lt;/STRONG&gt;, only be able to see and manage the&amp;nbsp;&lt;STRONG&gt;sc_req_items&lt;/STRONG&gt; of a certain category.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Using an &lt;STRONG&gt;ACL&lt;/STRONG&gt; applied to the group/role, I can easily restrict visibility based on the &lt;STRONG&gt;sc_req_items&amp;nbsp;&lt;/STRONG&gt;category.&lt;/LI&gt;&lt;LI&gt;But that &lt;STRONG&gt;ACL&lt;/STRONG&gt; also applies in &lt;STRONG&gt;ESC&amp;nbsp;&lt;/STRONG&gt;(Employee Center) which prevents the members of the group from being able to view their own &lt;STRONG&gt;sc_req_items &lt;/STRONG&gt;in &lt;STRONG&gt;ESC&lt;/STRONG&gt;.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;In &lt;STRONG&gt;ESC&lt;/STRONG&gt;, members of that group/role should still be able to view their &lt;STRONG&gt;sc_req_items&lt;/STRONG&gt; as users, regardless of the tickets' category.&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Any ideas or advice?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Nov 2025 13:22:01 GMT</pubDate>
      <guid>https://www.servicenow.com/community/service-operations-workspace/restrict-ritm-visibility-in-sow-but-allow-full-visibility-in-esc/m-p/3438309#M3346</guid>
      <dc:creator>Daniel_san</dc:creator>
      <dc:date>2025-11-26T13:22:01Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict RITM visibility in SOW but allow full visibility in ESC</title>
      <link>https://www.servicenow.com/community/service-operations-workspace/restrict-ritm-visibility-in-sow-but-allow-full-visibility-in-esc/m-p/3439844#M3358</link>
      <description>&lt;P&gt;I’m still searching without success for a way… the ideal solution would be to identify and apply the user/agent’s UI Context (SOW, ESC,...) as a condition in the ACLs.&amp;nbsp;&lt;STRONG&gt;But since ACLs are executed on the server side, I believe that’s not possible &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Given that limitation, with ACLs I can restrict agents in the group so they can only see tickets from the categories they are allowed to manage, as well as their own tickets as end users.&lt;/LI&gt;&lt;LI&gt;But these ACLs apply to all user interfaces, both SOW and ESC.&lt;UL&gt;&lt;LI&gt;It’s not ideal, because in SOW they can see the inner workings of how other support groups manage their tickets&lt;/LI&gt;&lt;LI&gt;This gap can be minimized by hiding fields with client scripts… but it’s annoying and not very scalable/maintainable.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;U&gt;NOTE:&lt;/U&gt; I’m surprised not to find an effective/quick way to limit the visibility of certain agents inside the workspaces while keeping their permissions intact as end users in Employee Center. I’d say this must be a common problem, for example for specific agents handling confidential topics or HR cases.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I’ll share anything I find if I discover a workable solution.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Nov 2025 14:45:08 GMT</pubDate>
      <guid>https://www.servicenow.com/community/service-operations-workspace/restrict-ritm-visibility-in-sow-but-allow-full-visibility-in-esc/m-p/3439844#M3358</guid>
      <dc:creator>Daniel_san</dc:creator>
      <dc:date>2025-11-28T14:45:08Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict RITM visibility in SOW but allow full visibility in ESC</title>
      <link>https://www.servicenow.com/community/service-operations-workspace/restrict-ritm-visibility-in-sow-but-allow-full-visibility-in-esc/m-p/3441379#M3385</link>
      <description>&lt;P&gt;I finally managed to achieve it using several &lt;STRONG&gt;Before Query Business Rules&lt;/STRONG&gt;, which allow identifying the UI context using the following (in the example, to identify SOW or UI Classic for sc_req_items):&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="100%"&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; var&lt;/SPAN&gt;&lt;SPAN&gt; glideURI = gs.action.getGlideURI();&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;var&lt;/SPAN&gt;&lt;SPAN&gt; url = glideURI.toString();&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;if&lt;/SPAN&gt;&lt;SPAN&gt; (url.indexOf(&lt;/SPAN&gt;&lt;SPAN&gt;'api/now/uxf'&lt;/SPAN&gt;&lt;SPAN&gt;) &amp;gt;= &lt;/SPAN&gt;&lt;SPAN&gt;0&lt;/SPAN&gt;&lt;SPAN&gt; || url.indexOf(&lt;/SPAN&gt;&lt;SPAN&gt;'sc_req_item.do?'&lt;/SPAN&gt;&lt;SPAN&gt;) &amp;gt;= &lt;/SPAN&gt;&lt;SPAN&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;) {&amp;nbsp;&lt;BR /&gt;( .......)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;SPAN&gt;&lt;BR /&gt;With that information, it becomes easy to add other conditions based on the agent’s specific role, the RITMs categories... applied only to the needed contexts.&amp;nbsp;It’s not as effective as restricting access with ACLs… but it more or less does the job &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 02 Dec 2025 11:27:24 GMT</pubDate>
      <guid>https://www.servicenow.com/community/service-operations-workspace/restrict-ritm-visibility-in-sow-but-allow-full-visibility-in-esc/m-p/3441379#M3385</guid>
      <dc:creator>Daniel_san</dc:creator>
      <dc:date>2025-12-02T11:27:24Z</dc:date>
    </item>
  </channel>
</rss>

