---
sourceDocument: Australia Employee Service Management
sourceDocumentLink: https://www.servicenow.com/docs/r/employee-service-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Employee Service Management

ft:clusterId :

    - emplsm

bundleId :

    - emplsm

workflow :

    - Employee


---

# Manage HR roles

# Manage HR roles {#ariaid-title1}

Release version: Australia  
Updated March 12, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Manage HR roles

In the ServiceNow HR Service Delivery Scoped app, roles are crucial for controlling access to HR features and sensitive information.
Scoped HR roles ensure that only authorized HR staff and clients (such as employees, contractors, and alumni) can access HR cases, profiles, and related services.
Typically, users without an HR scoped role cannot view HR data, enhancing data security within your organization.
Show full answer Show less  
The **HR Administrator \[snhrcore.admin\]** role is central to managing these scoped roles and configuring the system. This role is included within the System Administrator \[admin\] role but should be carefully managed to restrict sensitive HR data access to the appropriate users.

## Key Roles and Their Functions

* **System Administrator \[admin\]:** Has full access to all system features and data. Can assign delegated developer roles and manage company-wide objects.
* **HR Administrator \[snhrcore.admin\]:** Assigns HR roles, manages HR cases and profiles (including sensitive data like salary), accesses HR dashboards and administration, and manages HR objects. It includes Lifecycle Admin when relevant plugins are active.
* **Delegated Developer \[delegateddeveloper\]:** When combined with HR Administrator, can manage and modify HR application components and structures, enabling platform administration tasks.
* **HR Profile Reviewer \[snhrcore.profilereader\]:** Allows viewing HR profiles without edit rights.

## Security Best Practices

* After configuration, remove the HR Administrator role from the System Administrator role to prevent unauthorized access to sensitive HR information.
* IT System Administrators can impersonate users but cannot access HR features unless they hold the appropriate HR scoped roles.
* Scheduled jobs related to HR require a user with the HR Administrator role to run correctly; adjust the "Run as" user accordingly.
* Complete all setup before removing roles to avoid disrupting system operations.

## Role Management and Configuration

* Only the HR Administrator can assign scoped HR roles.
* Roles may contain other roles, thereby granting inherited access.
* Minimum numbers of scoped admins per role are configurable via system properties to ensure operational coverage.
* Delegated Developer role should be added to HR Administrators for comprehensive platform management capabilities.

## Additional HR Access Controls

* **HR Groups:** Define groups of users sharing common job skills to streamline HR case and task assignments.
* **HR Skills Management:** Specify qualifications for HR staff to support automated case and task assignments based on skills.
* **Escalation Rules:** Set rules to automatically route HR cases between tiers based on agent workload and skills.
* **Client Roles:** Control employee access to HR functionalities and license HR services by location or group.

## Practical Outcomes for ServiceNow Customers

By effectively managing HR roles and adhering to best practices, organizations can:

* Protect sensitive HR data from unauthorized access.
* Ensure HR administrators have the appropriate permissions to configure and manage HR services.
* Enable efficient assignment and escalation of HR cases based on defined skills and roles.
* Maintain clear separation between IT administrators and HR data access to comply with security and privacy requirements.
* Support scalable HR service delivery through structured role and group management.  
Roles control access to features and capabilities in modules in the HR
application.

The HR Service Delivery Scoped app can help prevent users outside of the HR organization from accessing HR data.

Scoped roles for both HR case workers and HR clients (employees, contractors, alumni, and others) grant access to HR services. Users without an HR scoped role typically cannot view HR cases or HR profile information. For
information on all the roles installed with Case and Knowledge Management plugin, see [Components installed with Case and Knowledge Management](https://www.servicenow.com/docs/k5lpt3wbMfmw~t9tbpUBtg "Several types of components install with the activation of the Case and Knowledge Management plugin, including tables, user roles, and scheduled jobs.").

Only the HR Administrator \[sn_hr_core.admin\] can assign scoped HR roles.

To configure your system, you must log in as a System Administrator \[admin\]. The HR
Administrator \[sn_hr_core.admin\] role is contained in the System Administrator \[admin\] role.
The combination of these two roles allows a user to perform all tasks associated with
configuring your system.

After system configuration, ensure that only the HR Administrator \[sn_hr_core.admin\] role has access to sensitive information. Remove the HR Administrator role from System Administrator \[admin\] role to help prevent the System
Administrator from viewing sensitive HR information via forms, lists and UI.  
After granting access to a role, all the groups or users assigned to the role also have access. Roles can contain other roles, and grants access to any role that contains it.  
Note:  
IT System Administrators (admin) can still impersonate ServiceNow users. When impersonating a user with an HR scope-protected role, an admin cannot access features granted by that role unless the admin already possesses those HR scope-protected roles. For more information on impersonating a user, see [Impersonate a user](https://www.servicenow.com/docs/access?context=c_ImpersonateAUser&version=australia&pubname=australia-platform-administration&ft:locale=en-US).

## HR Performance Analytics {#c_ManageRoles__section_v5c_ch1_nsb}

To configure the Performance Analytics (PA) dashboard, assign the Performance Analytics Administrator \[pa_admin\] role to the HR Administrator \[sn_hr_core.admin\] role.  
Note:  
Only the System Administrator \[admin\] can assign PA roles to employees.
{#c_ManageRoles__table_alz_h4f_gw__entry__2}

| Role | Description |
|-|-|
| System Administrator \[admin\] | Also known as admin and IT admin. Within the global scope of the application, has access to all system features, functions, and data, regardless of security constraints. * Grant users with the delegated developer role \[delegated_developer\]. * Build export sets, move content between instances (development to production), and clone instances. * Run guided setup or modules to manage:Company-wide objects like user, departments, and locations. {#c_ManageRoles__ul_r2k_wqz_bx} |
| HR Administrator \[sn_hr_core.admin\] | This role can: * Assign users any of the HR roles. * View and access the HR Service Portal. * View, create, and edit HR cases in HR Case Management. * Access and create HR tasks inside an HR case using the Add Task related link. * View, create, and edit HR profiles including sensitive information like salary. * Create HR profiles and generate for multiple users through custom criteria. * Associate any user to HR roles, groups, and skills. * View and access HR Administration. * View and access HR Dashboards \& Reports. * Run Application View to manage: HR objects like HR roles and profiles. Note: When the Human Resources Scoped App: Core (com.sn_hr_core) and Lifecycle Events (com.sn_hr_lifecycle_events) plugins are active, the Lifecycle Admin (sn_hr_le.admin) role is part of HR Admin (sn_hr_core.admin). {#c_ManageRoles__ul_svj_r21_cx} |
| Delegated Developer \[delegated_developer\] | When added to the HR Administrator role, can: * Access, and manage HR objects like HR profile, cases, groups, roles, service catalog objects, and Service Portal. * Modify HR application-related objects like skills, Knowledge Base, chat, notifications, surveys, reports, integrations, and SC. * Modify application structures like tables, business rules, and client-side validation, {#c_ManageRoles__ul_xcd_kg1_cx} |
| User with HR role | There are specific HR roles that allow users access to specific areas of the system. For example, the HR profile reviewer \[sn_hr_core.profile_reader\] role can read profiles, but not edit them. |
[Table 1. Roles]

{#c_ManageRoles__table_alz_h4f_gw}

After system configuration, to help prevent the System Administrator from accessing sensitive information:

* Remove the HR Administrator \[sn_hr_core.admin\] role from System Administrator \[admin\].
  * The base system requires a user with the System Administrator role to run scheduled jobs. For details on HR scheduled jobs, see [Components installed with Case and Knowledge Management](https://www.servicenow.com/docs/k5lpt3wbMfmw~t9tbpUBtg "Several types of components install with the activation of the Case and Knowledge Management plugin, including tables, user roles, and scheduled jobs.").
  * To ensure the scheduled jobs run, change the user in the Run as field for each scheduled job to a user that has the HR admin role.  
    Note:  
    Changing the user allows the scheduled jobs to run, but only a user with the System Admin role can view and run a scheduled job on demand.
  * Change the scope of the application to Human Resources: Core application. For information on changing the scope, see [Contextual development edit
    messages](https://www.servicenow.com/docs/access?context=c_WarningMessages&version=australia&pubname=australia-application-development&ft:locale=en-US).
  * Reveal the Run as field. For information on revealing hidden fields on a form, see [Configuring the form
    layout](https://www.servicenow.com/docs/access?context=configure-form-layout&version=australia&pubname=australia-platform-administration&ft:locale=en-US).
  {#c_ManageRoles__ul_zzd_j2r_1fb}
* Log out and log back in to ensure that the changes take effect.  
  Note:  
  Ensure that you have completed setup before removing the HR Administrator role.

  Minimum number of scoped admins required
  :   System properties determine the minimum number (default is two) of scoped admins that must be active for an application.
  :   To list the properties, enter <kbd class="ph userinput">sys_properties.list</kbd> in the
      filter navigator and search for the property to configure.
  :   The list of system properties and what scoped admin can access:

  System properties
  :   {#c_ManageRoles__table_ac5_l31_nsb__entry__2}

      | Property Name | Scoped Admin |
      |-|-|
      | sn_hr_core.min_admin_count | HR admin \[sn_hr_core.admin\] |
      | sn_hr_ef.min_admin_count | Employee Document Management admin \[sn_hr_ef.admin\] |
      | sn_hr_integrations.min_admin_count | HR Integration Admin \[sn_hr_integrations.admin\] |
      | sn_hr_le.min_admin_count | HR Lifecycle Event Admin \[sn_hr_le.admin\] |
      | sn_hr_le_pa.admin_count | HR Lifecycle Event Performance Analytics Admin \[sn_hr_le_pa.admin\] |
      | sn_hr_pa.min_admin_count | HR Performance Analytics Admin \[sn_hr_pa.admin\] |
      | sn_hr_pj.min_admin_count | HR Parental Journey Admin \[sn_hr_le_pj.admin\] |
      | sn_hr_sp.min_admin_count | HR Service Portal Admin \[sn_hr_sp.admin\] |
      | sn_hr_va.min_admin_count | HR Virtual Agent Admin \[sn_hr_va.admin\] |
      | sn_templated_snip.min_admin_count | Response Template Admin \[sn_templated_snip.admin\] |
      | sn_hr_ws.min_admin_count | HR Agent Workspace Admin \[sn_hr_ws.admin\] |
      [Table 2. Properties]

      {#c_ManageRoles__table_ac5_l31_nsb}
{#c_ManageRoles__ul_fbj_kdb_1x}
* **[Remove HR Administrator role from IT System Administrators](https://www.servicenow.com/docs/hdw72iopvlGpRJHXdI1VJQ)**   
  Remove the HR Administrator role from IT System Administrator to prevent access to sensitive HR information.
* **[Add Delegated Developer to HR Administrator](https://www.servicenow.com/docs/bMFQlO94_EOj2hffWIm0FA)**   
  For an HR Administrator \[sn_hr_core.admin\] to perform some platform duties, the delegated developer role must be added.
* **[Manage HR Groups](https://www.servicenow.com/docs/KEufcA6veEsig5IhURPR8w)**   
  HR Groups are a set of users with common job skills.
* **[HR skills management](https://www.servicenow.com/docs/1DxmJhe2ycYtGV3s7E6ceQ)**   
  Your organization can define HR skills to establish the qualifications of HR staff. Skills can be included in the auto-assignment process used to assign HR agents to HR cases and tasks.
* **[Configure escalation rules for HR cases](https://www.servicenow.com/docs/47GPrDmwoa~uSsbXfFiFNg)**   
  Create escalation rules to automatically route HR cases from one tier to another based on agent skills and workload.
* **[Client roles](https://www.servicenow.com/docs/jEyyu7zegTieJQaLn1RlnQ)**   
  You can control what HR functionality that an employee can access using Client Roles. You can license all employees or provide HR services to users in a specific location or group.

