Paty Montesinos
ServiceNow Employee
Options
- Subscribe to RSS Feed
- Mark as New
- Mark as Read
- Bookmark
- Subscribe
- Printer Friendly Page
- Report Inappropriate Content
2 hours ago
Stop Redacting by Hand. Let AI Do the Heavy Lifting. Introducing: Redaction Agent for SmartDocs
GA August 2026
Table of Contents
- What is the Redaction Agent?
- Who this is built for - and why they'll care?
- The business outcomes
- The strategic "why"
- How to activate it
- Get your first value in under 5 minutes
- Use case 1: a legal counsel's workspace
- Use case 2: Third-party risk assessment review
- Want more control over how it works for your org?
SmartDocs and Doc to Voice Hub
Want to see all of our other articles and blogs related to SmartDocs, Doc to Voice, and Redaction Agent?
Check out the SmartDocs and Doc to Voice hub: https://www.servicenow.com/community/servicenow-ai-platform-blog/smartdocs-and-doc-to-voice-hub/ba-p...
You can copy the link above and share it!
The problem we all know too well
If you've ever had to prep a contract, an incident report, or a FOIA request for external release, you know the drill: scroll through page after page hunting for SSNs, phone numbers, pricing terms, names — anything that shouldn't leave the building. Manually.
For legal, compliance, and public sector teams, this isn't a minor annoyance — it's a real liability:
- Hours lost to line-by-line manual review of every document before it can be shared
- Inconsistent redaction because reviewers apply judgment differently, document to document, person to person
- No defensible audit trail — when a regulator or FOIA request asks "who redacted what, and why?", most teams don't have a good answer
- Bottlenecked sharing — sensitive documents sit in review queues instead of moving through the business
This is exactly the friction SmartDocs was built to remove, and it's why the Redaction Agent exists.
Family Release: Zurich
Release: ZP5+
Roles Required: Any workspace role as long as the SmartDocs skill is configured to the table where you will be viewing the attached document.
Plugin dependencies: ServiceNow Otto for Platform, ServiceNow Otto for Document Management
What is the Redaction Agent?
The Redaction Agent is an AI-powered capability inside SmartDocs that automatically detects and securely redacts sensitive information from documents before they're shared, processed, or acted on. It doesn't just pattern-match for obvious things like emails and phone numbers — it understands document context well enough to flag regulated, confidential, and business-critical data, and it applies policy-driven redaction codes with precision and consistency.
Core capabilities:
- Automatic sensitive content detection — emails, phone numbers, dates, names, and other regulated data
- AI-suggested redaction codes mapped to your compliance requirements (think FOIA exemptions, PII categories, trade secret designations)
- Customizable data patterns and codes — your organization's rules, not a generic template
- Full document preview before anything is saved
It runs through ServiceNow Otto in Document Management, powered by the Smart Documents skill.
Who this is built for - and why they'll care?
Personas: Legal Counsel, Compliance Officers, Investigators, FOIA Administrators, Records Managers, Document Administrators, Paralegals
Value proposition: turn hours of manual, risk-laden redaction into minutes of AI-assisted, audit-ready work — without leaving the document viewer.
The business outcomes
This isn't a "nice to have" productivity tweak — it's directly tied to risk reduction and speed:
- 60–80% reduction in manual redaction labor
- Eliminates the liability of misdirected sensitive data
- Minutes instead of hours to get a document ready for secure sharing
- Audit-ready compliance trails, every time, automatically
- Supports regulatory frameworks like ISCAP, FOIA, and the Privacy Act
- Drives broader adoption of collaborative document workflows across the org
The strategic "why"
SmartDocs' broader vision is turning static files into intelligent, in-flow assets — no more 40-page PDFs, Ctrl+F, and work grinding to a halt while someone reads. The Redaction Agent is a key pillar of that: it's part of SmartDocs' expansion into AI agents for document-centric workflows, and it sharpens ServiceNow's differentiation specifically in regulated industries — legal, public sector, and financial services — where document governance isn't optional.
What makes it different from "just another redaction tool":
- It lives inside the document viewer, in the flow of work — no tab-switching, no exporting to a separate redaction app
- It pairs AI detection with human override — you stay in control, the AI just removes the grunt work
- It builds in attribution and audit logging by default, not as an afterthought
- Redaction codes are customizable and compliance-aligned — not generic black boxes
How to activate it
Before you dive in, make sure you have:
- The Smart Documents skill configured and activated on your target table
- Write access to the parent record that contains the attachment
- Write access to the document you want to redact
A few things to know up front: it currently supports PDF only, up to 20 pages or 500,000 characters, and it can't redact converted attachments (e.g., a Word doc converted to PDF for preview) — only the original PDF.
Get your first value in under 5 minutes
Here's the fastest path to seeing it work:
- Open a record on a table with Smart Documents enabled (Incident, Change Request, HR document, etc.) and open the attached PDF in the document viewer.
- Click "Ask Otto" and select Redact Document Content — or type a specific ask like "redact all emails."
- Review the detected sensitive content — the system surfaces a list with content types identified.
- Select the items you want to redact (multi-select supported) and hit Submit.
- When prompted, say yes to AI-suggested redaction codes — the system maps each item to a code based on content type and your compliance rules.
- Verify the codes — this is your quality gate. AI suggestions are based on content analysis and might not be perfectly accurate, so confirm each one matches your actual compliance requirement.
- Need to adjust? Click into the highlighted area to add/remove codes (you can assign multiple codes to one item), then save.
- Preview the redacted document before committing.
- Save — for attachments, a new redacted attachment is created and linked to the parent record; for documents, a new published version is created and the original is retired.
That's it — from raw document to compliant, redacted, audit-logged output, without ever leaving the viewer.
Use case 1: a legal counsel's workspace
A Legal Counsel uploads a contract to a Legal record — it contains confidential pricing terms and personal identifiers.
They open the document and trigger the Redaction Agent.
The agent auto-detects and highlights potential redaction zones — an SSN here, a pricing clause there, a name elsewhere.
The counsel reviews each suggestion, accepting most and overriding a couple that don't apply.
They assign regulatory codes — PII for the identifiers, CONFIDENTIAL or a trade-secret code for the pricing.
They add a justification note explaining the redaction rationale.
The system logs every change with attribution — who redacted what, when, and why.
They export the redacted contract with the metadata embedded, ready to hand to compliance for an audit trail that actually holds up.
That entire flow — detection to defensible export — happens in one sitting, inside the document viewer, instead of a multi-day manual review cycle.
Use case 2: Third-party risk assessment review
A Compliance Officer is reviewing a vendor’s completed security and risk questionnaire, along with supporting documentation, before it is shared with an external auditor or regulator as part of a third-party risk review. The file includes a mix of sensitive content: vendor internal contact details, negotiated pricing and contract terms, and personal identifiers for employees named in incident-response sections.
The officer opens the vendor risk assessment PDF in the document viewer on a record where the Smart Documents skill is activated, then clicks Ask Otto → Redact Document Content — or asks directly, such as “redact all names and contact details.”
The Redaction Agent scans the document and surfaces detected items, including vendor employee names, email addresses, phone numbers, and embedded pricing terms. The officer selects the items relevant to the review — for example, redacting personal identifiers and negotiated commercial terms while leaving general risk-control language visible for the auditor.
They accept the AI-suggested redaction codes and verify each one against compliance requirements, such as PII-NAME and PII-EMAIL for personal identifiers and CONFIDENTIAL for commercial terms. For confidential terms, they add a justification note — for example, “commercial terms outside audit scope” — and the system logs the change with attribution.
Before saving, the officer previews the redacted assessment to confirm nothing sensitive slipped through. When they save and export, the redacted version is created as a new attachment or version linked to the vendor risk record, with metadata embedded for the audit trail.
Why this matters for TPRM: Vendor risk documentation is often shared with auditors, regulators, and sometimes the vendor itself, so redaction has to be both fast and defensible. Because TPRM teams manage recurring assessments across a vendor portfolio, a 60–80% reduction in manual redaction labor compounds quickly. And when a regulator asks why a data point was withheld, the audit-ready trail provides the justification note plus the who and when — all without exporting the assessment to a separate tool and re-uploading it.
Want more control over how it works for your org?
Admins with the platform_document_management_admin role can tune this to your organization's specific compliance needs:
- Customize data patterns: All > System Security > Data Privacy > Privacy Policy Advanced Configuration > Document Redaction-sn_doc_gen_ai > Select Data Patterns
- Manage redaction codes (add, modify, deactivate): All > Document Management Administration > Redaction Codes
One tip that pays off: the better your redaction code descriptions, the better the AI gets at suggesting the right one. "PII-EMAIL — Email addresses" beats a vague label every time.
Conclusion
The Redaction Agent takes one of the most tedious, risk-heavy parts of document handling — manual sensitive-data review — and turns it into an AI-assisted, human-verified, fully audited workflow, right inside the tools your legal, compliance, and records teams already use. Less time reading and redacting. More time doing the work that actually needs a human.
Have a document-heavy workflow that could use this? Drop your use case in the comments — we're actively gathering input to prioritize what's next on the SmartDocs roadmap.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.