---
sourceDocument: Xanadu Platform security
sourceDocumentLink: https://www.servicenow.com/docs/r/xanadu/platform-security

 Release :

    - xanadu

ft:locale :

    - en-US

ft:publication_title :

    - Xanadu Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Roles installed with Key Management Framework

# Roles installed with Key Management Framework {#ariaid-title1}

* Release version: Xanadu
* 
* Updated May 20, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

The Key Management Framework (KMF) introduces specific roles for cryptographic module
and key management-related configurations.
Important:  
KMF roles are required to use the Key Management Framework. Users without KMF roles are not able to access lists, tables, and modules used to configure key management.

To assign the KMF admin role, you must have the admin, security_admin, and sn_kmf.admin roles. Use the KMF admin role to assign other KMF roles. For details on
assigning KMF roles, see [Assign KMF roles](https://www.servicenow.com/docs/AuUBbnZrrf0p1AfCaARBtA#assign-kmf-roles "Assign KMF roles to admins, who in turn can assign other KMF roles.").

The sn_kmf.admin role is also required to modify any group record that includes the sn_kmf.cryptographic_manager role. This requirement applies to all updates to the group record, not
only to role assignment operations.

**Related concepts**   

* [Cryptographic module overview](https://www.servicenow.com/docs/OZjGewFntPbu5nwlboolSQ "Cryptographic modules are the centerpiece of (KMF). They define the specific cryptographic mechanisms used for cryptographic operations for a given use case.")
* [Module access policy overview](https://www.servicenow.com/docs/5sr41ReBxS5vVeECDWx8pA "Module access policies (MAPs) are access controls that you apply to your cryptographic modules. Use these access policies to decide which users and scripts can access data encrypted by a cryptographic module.")
* [Cryptographic specification](https://www.servicenow.com/docs/rd3B_Us3bL~uh19AqWTukQ "The Cryptographic specification is the component that defines aspects of your cryptographic module, including its cryptographic purpose and which encryption algorithm to use.")
* [Module access policy visualization](https://www.servicenow.com/docs/_4H5c1YzVJ4b4TJT~tFhKA "Use module access policy visualization to view all relevant cryptographic module information on a single UI page.")
* [Module access policy debugger](https://www.servicenow.com/docs/BX4vU083pXpDKfxxMfBBUw "Use the module access policy debugger to review logging information and understand why your users are or aren’t granted access to an encryption context.")  
**Related tasks**   

* [Configure field encryption settings to select key type](https://www.servicenow.com/docs/Oj3GdjNfBdasVv1lnh3fqQ "Configure your field encryption settings to use ServiceNow supplied keys or your own customer-supplied keys (CSK) for encryption on the ServiceNow AI Platform.")
* [Create a cryptographic module](https://www.servicenow.com/docs/e7uHtVZdOrcU_PA0G4aFtg "Create a cryptographic module to define the mechanisms used for cryptographic operations. After you create the module, you create a cryptographic specification, where you define an algorithm for encryption and generates a key.")
* [Create a module access policy](https://www.servicenow.com/docs/TLgW1ph7I9G8pGSRDbEj5A "Create module access policies to decide which users and scripts can access data encrypted by a cryptographic module.")
* [Create a cryptographic module life-cycle policy](https://www.servicenow.com/docs/BGWhczFujOviSej229y4Bw "Create a cryptographic module life-cycle policy to place limits on cryptographic modules, such as how long the key is good for. Create policies to safeguard cryptographic modules by limiting their exposure.")  
**Related reference**   

* [Instance level keys in the Key Management Framework](https://www.servicenow.com/docs/hxut9EJ6UvwBhFbH8eQk9w "The Key Management Framework (KMF) architecture introduces a key structure built with security in mind. Using a Hardware Security Module (HSM), KMF uses envelope encryption to ensure that all platform keys under KMF management are protected through a chain of keys. Customer Data Encryption Keys (CDEKs) created by KMF are also included.")
* [Key Management Framework key lifecycle states](https://www.servicenow.com/docs/hhFxgSjjVZpHdqOk2R~LOg "KMF supports several cryptographic key lifecycle states through the enforcement of specific allowable actions. For example, only keys that are in the active state can be used fully for their intended cryptographic purpose. The following table provides further detail on the varying key lifecycle states.")

## KMF admin \[sn_kmf.admin\] {#ariaid-title2}

Assigns roles to other users to perform operations around the ServiceNow Key Management Framework.

### Contains Roles {#kmf-roles-1__section-feature-role-contains-roles}

List of roles contained within the role.

None.

### Groups {#kmf-roles-1__section-feature-role-groups}

List of groups this role is assigned to by default.

None.

### Special considerations {#kmf-roles-1__section-feature-role-considerations}

Important:  
Avoid granting an admin role when more specialized roles are available.

* This role is assigned via the process shown in [Assign KMF roles](https://www.servicenow.com/docs/AuUBbnZrrf0p1AfCaARBtA#assign-kmf-roles "Assign KMF roles to admins, who in turn can assign other KMF roles.").
* You must have this role to assign  KMF roles, and in addition can perform all the capabilities of the KMF cryptographic manager.
{#kmf-roles-1__ul_pts_t14_cyb}

## KMF cryptographic manager \[sn_kmf.cryptographic_manager\] {#ariaid-title3}

Create, read, and update operations on cryptographic modules (association of keys to cryptographic usage and algorithm configurations) and module access policies. Also, KMF cryptographic managers can perform key management
(generate, rotate, revoke) and life cycle operations.

### Contains Roles {#kmf-roles-2__section-feature-role-contains-roles}

List of roles contained within the role.

None.

### Groups {#kmf-roles-2__section-feature-role-groups}

List of groups this role is assigned to by default.

None.

### Special considerations {#kmf-roles-2__section-feature-role-considerations}

None.

## KMF cryptographic auditor \[sn_kmf.cryptographic_auditor\] {#ariaid-title4}

View cryptographic module information, key metadata, and life cycle-related details, as well as module access policy (MAP) information.

### Contains Roles {#kmf-roles-3__section-feature-role-contains-roles}

List of roles contained within the role.

None.

### Groups {#kmf-roles-3__section-feature-role-groups}

List of groups this role is assigned to by default.

None.

### Special considerations {#kmf-roles-3__section-feature-role-considerations}

None.

## KMF cryptographic integrator \[sn_kmf.cryptographic_integrator\] {#ariaid-title5}

Integrate Key Management Framework with external keystores or systems.

### Contains Roles {#kmf-roles-4__section-feature-role-contains-roles}

List of roles contained within the role.

None.

### Groups {#kmf-roles-4__section-feature-role-groups}

List of groups this role is assigned to by default.

None.

### Special considerations {#kmf-roles-4__section-feature-role-considerations}

None.

## KMF cryptographic operator \[sn_kmf.cryptographic_operator\] {#ariaid-title6}

Access part of the ServiceNow
Key Management Framework key lifecycle: renewal, rotation, revocation.

### Contains Roles {#kmf-roles-5__section-feature-role-contains-roles}

List of roles contained within the role.

None.

### Groups {#kmf-roles-5__section-feature-role-groups}

List of groups this role is assigned to by default.

None.

### Special considerations {#kmf-roles-5__section-feature-role-considerations}

None.

## Assign KMF roles {#ariaid-title7}

Assign KMF roles to admins, who in turn can assign other KMF roles.

### Before you begin

Role required: admin and security_admin

You must elevate to the security_admin role before assigning the KMF admin role. For instructions, see
[Elevate to a privileged
role](https://www.servicenow.com/docs/nNQmUCblDaySoDX~ve4X9Q "The base system admin can elevate to a privileged role to have access to the features of High Security Settings.")

### Procedure

1. Elevate to the security admin role.
2. Navigate to User AdministrationUsers and select the user you want to be the KMF admin.
3. Verify that the user already has the admin and security_admin roles.  
   If not, select Edit under the Roles related list and add admin and security _admin.
4. Navigate to System SecurityKey Management Administration.
5. Select the user that you want to be KMF admin in the Available Users column and move them to the Selected User(s) column.  
6. Select Save.
7. Navigate to User AdministrationUsers and select the user you just gave the sn_kmf.admin role to.  
   The user has the sn_kmf.admin role in the Roles related list, and can assign other KMF roles.

### What to do next

If you have the KMF admin role, follow these steps for assigning other KMF roles:  
1. Navigate to User AdministrationUsers and select the user you want to have another KMF role, such as KMF Cryptographic Manager.
2. In the Roles related list, select Edit and select the KMF roles you want to assign the users. All KMF roles start with `sn_kmf`.

{#assign-kmf-roles__ol_lp3_zfh_m4b}

*[\>]: and then


