---
sourceDocument: Xanadu Platform security
sourceDocumentLink: https://www.servicenow.com/docs/r/xanadu/platform-security

 Release :

    - xanadu

ft:locale :

    - en-US

ft:publication_title :

    - Xanadu Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Module access policy overview

# Module access policy overview {#ariaid-title1}

* Release version: Xanadu
* 
* Updated August 1, 2024
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Module access policies (MAPs) are access controls that you apply to your cryptographic modules. Use these access policies to decide which users and scripts can access data encrypted by a cryptographic module.

## Module access policies {#module_access_policy_overview__section_t31_w1y_4zb}

Note:  
A subscription is required to utilize the Column Level Encryption Enterprise functionality. See [Activate Column Level Encryption Enterprise](https://www.servicenow.com/docs/CtH4NL~Y5NvhC~XtWQ1ZdQ "With subscription to Column Level Encryption Enterprise, an admin can activate the com.glide.now.platform.encryption plugin.") for more information on Column Level Encryption Enterprise.

Module access policies are introduced with the Key Management Framework (KMF) in the base system.

Module access policies expand on the role-based designations that were provided with the encryption modules. Module access policies can be based on the following:  
* Basic (scope)
* Role
* System user
* Script
* Resource Exchange  
  Note:  
  See [Key Management Framework Resource Exchange](https://www.servicenow.com/docs/h~jDnqIBdyh7t~A0XQ_PCg "ServiceNow Resource Exchange is a KMF feature that gives you the capability to exchange resources between instances in a secure manner.") for details.
{#module_access_policy_overview__ul_vsb_qwp_kqb}

In a cryptographic module, you must configure the correct module access policies to permit access to encrypted data. Without a module access policy associated with a cryptographic module, encrypted data isn't visible to users
and associated fields and columns in lists display as empty.

In this example, the absence of a module access policy on the encrypted Short Description field hides the content from all users accessing the Incident table. With a module access policy in place, only users with a specific role
are able to see the encrypted data.  
Figure 1. Encrypted short descriptions with and without module access policies  
Note:  
The data in the column also appears empty to users without the correct role specified in the module access policy.

Refer to [Create a module access policy](https://www.servicenow.com/docs/TLgW1ph7I9G8pGSRDbEj5A "Create module access policies to decide which users and scripts can access data encrypted by a cryptographic module.") for setup.

## Autogen policies {#module_access_policy_overview__section_xjg_v1y_4zb}

Autogen policies are automatically system generated based on the default module access policy defined for the given cryptographic module. If there are no granular level policies defined when the system or a script tries to
access the given cryptographic module, these global policies are generated and applied.  
Important:  
Autogen policy rules aren't applied for scheduled jobs types, or field encryption modules (modules where the parent module is Column Level Encryption).
**Related concepts**   

* [Cryptographic module overview](https://www.servicenow.com/docs/OZjGewFntPbu5nwlboolSQ "Cryptographic modules are the centerpiece of (KMF). They define the specific cryptographic mechanisms used for cryptographic operations for a given use case.")
* [Cryptographic specification](https://www.servicenow.com/docs/rd3B_Us3bL~uh19AqWTukQ "The Cryptographic specification is the component that defines aspects of your cryptographic module, including its cryptographic purpose and which encryption algorithm to use.")
* [Module access policy visualization](https://www.servicenow.com/docs/_4H5c1YzVJ4b4TJT~tFhKA "Use module access policy visualization to view all relevant cryptographic module information on a single UI page.")
* [Module access policy debugger](https://www.servicenow.com/docs/BX4vU083pXpDKfxxMfBBUw "Use the module access policy debugger to review logging information and understand why your users are or aren’t granted access to an encryption context.")  
**Related tasks**   

* [Configure field encryption settings to select key type](https://www.servicenow.com/docs/Oj3GdjNfBdasVv1lnh3fqQ "Configure your field encryption settings to use ServiceNow supplied keys or your own customer-supplied keys (CSK) for encryption on the ServiceNow AI Platform.")
* [Create a cryptographic module](https://www.servicenow.com/docs/e7uHtVZdOrcU_PA0G4aFtg "Create a cryptographic module to define the mechanisms used for cryptographic operations. After you create the module, you create a cryptographic specification, where you define an algorithm for encryption and generates a key.")
* [Create a module access policy](https://www.servicenow.com/docs/TLgW1ph7I9G8pGSRDbEj5A "Create module access policies to decide which users and scripts can access data encrypted by a cryptographic module.")
* [Create a cryptographic module life-cycle policy](https://www.servicenow.com/docs/BGWhczFujOviSej229y4Bw "Create a cryptographic module life-cycle policy to place limits on cryptographic modules, such as how long the key is good for. Create policies to safeguard cryptographic modules by limiting their exposure.")  
**Related reference**   

* [Instance level keys in the Key Management Framework](https://www.servicenow.com/docs/hxut9EJ6UvwBhFbH8eQk9w "The Key Management Framework (KMF) architecture introduces a key structure built with security in mind. Using a Hardware Security Module (HSM), KMF uses envelope encryption to ensure that all platform keys under KMF management are protected through a chain of keys. Customer Data Encryption Keys (CDEKs) created by KMF are also included.")
* [Key Management Framework key lifecycle states](https://www.servicenow.com/docs/hhFxgSjjVZpHdqOk2R~LOg "KMF supports several cryptographic key lifecycle states through the enforcement of specific allowable actions. For example, only keys that are in the active state can be used fully for their intended cryptographic purpose. The following table provides further detail on the varying key lifecycle states.")
* [Roles installed with Key Management Framework](https://www.servicenow.com/docs/AuUBbnZrrf0p1AfCaARBtA#kmf-roles "The Key Management Framework (KMF) introduces specific roles for cryptographic module and key management-related configurations.")

