Welcome to Community Week 2025! Join us to learn, connect, and be recognized as we celebrate the spirit of Community and the power of AI. Get the details  

When "Explicit Roles" plugin is activated standalone, sys_attachment records related to records snc_external users can read are not available

mandle
Mega Guru

 

Environment Details:

  1. "Explicit Roles" plugin is activated by ServiceNow standalone from Customer Service Management
  2. User has been granted snc_external role.
  3. kb_knowledge record is in a kb_knowledge_base where User Criteria "Can Read" is set to allow users with snc_external to read articles in that Knowledge Base.
  4. kb_knowledge record has 1 or more attachments.

Issue:

Attachments cannot be downloaded for these snc_external users.

What are the SAFE AND SECURE adjustments that need to be made to sys_attachment Access Controls?

Note: This instance does have Kingston HRSD but not Kingston CSM in use.

 

READ ACLS on sys_attachment that fail

One of them is for attachments to sc_cart so that's not an issue.
This one does seem to be the issue: https://somekingstoninstance.service-now.com/nav_to.do?uri=sys_security_acl.do?sys_id=0bcf23740a6a38d400c7e02590038464

 

find_real_file.png

1 ACCEPTED SOLUTION

Sarup,

Good news. HI determined there was no risk to add the "snc_external" role to this sys_attachment ACL:
https://someinstance.service-now.com/nav_to.do?uri=sys_security_acl.do?sys_id=0bcf23740a6a38d400c7e0...

Once we added "snc_external" to the ACL then users with the snc_external role is able to download or view attachments to records they are allowed to read.

Thanks for your help!

View solution in original post

5 REPLIES 5

Sarup,

Good news. HI determined there was no risk to add the "snc_external" role to this sys_attachment ACL:
https://someinstance.service-now.com/nav_to.do?uri=sys_security_acl.do?sys_id=0bcf23740a6a38d400c7e0...

Once we added "snc_external" to the ACL then users with the snc_external role is able to download or view attachments to records they are allowed to read.

Thanks for your help!