---
sourceDocument: Zurich Customer Service Management
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/customer-service-management

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich Customer Service Management

ft:clusterId :

    - csm

bundleId :

    - csm

workflow :

    - Customer and Industry


---

# Roles installed with Customer Service Management

# Roles installed with Customer Service Management {#ariaid-title1}

* Release version: Zurich
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 8 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Roles installed with Customer Service Management

The Customer Service Management (CSM) application uses a structured role system to control access, maintain data security, and manage relationships between internal users (such as agents and managers) and external users (such as customers, partners, and consumers).
This role architecture supports both Business-to-Business (B2B) and Business-to-Consumer (B2C) models, ensuring appropriate access levels across different types of user interactions within your ServiceNow instance.
Show full answer Show less  

## Primary Roles

CSM provides primary roles categorized as internal (assigned to organization employees) and external (assigned to customers, partners, or consumers). These roles enable users to perform specific tasks based on their business functions, such as case management, account administration, or consumer support. The primary roles include:

* **Internal Roles:** Customer Service Agent, Customer Service Manager, Consumer Service Agent.
* **External Roles:** Customer, Customer Administrator, Customer Case Manager, Partner, Partner Administrator, Consumer.

These roles are based on core base roles from the Customer Service Base Entities plugin, providing foundational permissions and access controls.

## Role Descriptions and Capabilities

Each role carries distinct responsibilities and access rights, for example:

* **Customer Service Agent:** Handles case creation, editing, and resolution for customers and partners.
* **Customer Service Manager:** Manages agents and groups with additional permissions like approval of requests.
* **Customer Role:** Allows customers to create and manage their cases and view assets.
* **Partner Roles:** Enable partners to manage cases related to their accounts and customer accounts they serve.
* **Consumer Roles:** Support consumers in managing their cases and viewing purchased products.

Additional specialized roles provide granular access such as case contributors, task agents, contact managers, project managers, and de-escalation requesters, among others.

## Internal vs External Roles and Security

Internal roles are for employees and managers using CSM to support customers, while external roles grant portal access to customers, partners, and consumers. Every user must have at least one role to ensure proper access control and security separation between internal and external users. This structure helps prevent unauthorized access and allows tailored access levels per user type.

## Custom Roles and Role Management

ServiceNow administrators can create custom roles or adjust existing roles using script includes and extension points to fit unique business needs. It is important to regularly review role assignments, especially for external users, to maintain compliance with security policies and business requirements. Additional tools and knowledge base articles assist in managing and correcting external user role assignments.

## ServiceNow Customer Benefits

* Enables clear segregation of duties between internal staff and external users, maintaining data security.
* Supports multiple business models (B2B, B2C) with role structures tailored to each.
* Provides flexibility to assign granular access rights for case handling, account management, and project oversight.
* Facilitates secure self-service portals for customers, partners, and consumers with controlled access.
* Allows customization of roles to match specific organizational workflows and security requirements.  
The Customer Service Management application uses roles to provide access to information,
identify internal and external users, maintain data security, and establish different types of
relationships between users.

## Primary roles {#r_RolesInstalledWithCustomerService__section_obn_1cr_3mb}

Customer Service Management provides several primary roles that support the following business models:

* Business-to-business (B2B): With this business model, you can support accounts and contacts. Additionally, you can create relationships and account teams to support your customers.
* Business-to-consumer (B2C): With this business model, you can support individual consumers.
{#r_RolesInstalledWithCustomerService__ul_cj3_1rt_mmb}

These roles ensure access to data while maintaining data security for different types of
business relationships.  
{#r_RolesInstalledWithCustomerService__table_ql1_rw4_rkb__entry__2}

| Internal Roles | External Roles |
|-|-|
| Business-to-business (B2B) * sn_customerservice_agent * sn_customerservice_manager {#r_RolesInstalledWithCustomerService__ul_tsw_5w4_rkb} | Business-to-business (B2B) Customer * sn_customerservice.customer * sn_customerservice.customer_admin * sn_customerservice.customer_case_manager {#r_RolesInstalledWithCustomerService__ul_iln_cx4_rkb} |
| Business-to-consumer (B2C) * sn_customerservice.consumer_agent * sn_customerservice_manager {#r_RolesInstalledWithCustomerService__ul_eg5_yw4_rkb} | Business-to-business (B2B) Partner * sn_customerservice.partner * sn_customerservice.partner_admin {#r_RolesInstalledWithCustomerService__ul_xcz_fx4_rkb} |
|   | Business-to-consumer (B2C) sn_customerservice.consumer |
[Table 1. CSM primary roles]

{#r_RolesInstalledWithCustomerService__table_ql1_rw4_rkb}For details about these roles, see [CSM roles and
descriptions](https://www.servicenow.com/docs/XJC~8V_7JvR8SOVfRMskCw#r_RolesInstalledWithCustomerService__section_p5t_gcr_3mb) below.

## Internal and external roles {#r_RolesInstalledWithCustomerService__section_dz3_vqj_w5b}

Customer Service Management includes both internal and external user roles.

* Internal roles are assigned to users within your organization. These roles are for agents and managers using the Customer Service Management application to support customers.
* External roles are assigned to users outside your organization. These roles are for customers, customer partners, and consumers using the self-service portals.
{#r_RolesInstalledWithCustomerService__ul_w4z_fbr_3mb}

With these roles, you can give both internal users and external users access to your
instance. This role structure gives you the flexibility to provide different levels of
access to different users. As an additional security measure, every user must have at least
one role so that the instance can distinguish between internal and external users.

## Base roles {#r_RolesInstalledWithCustomerService__section_ug3_vqj_w5b}

The primary roles available in Customer Service Management are based on the following base roles:

* sn_esm_agent
* sn_esm_admin
* sn_esm_partner
* sn_esm_partner_admin
* sn_esm_user
* sn_esm_user_admin
{#r_RolesInstalledWithCustomerService__ul_zn1_prj_w5b}

For more information about these roles, see [Roles
installed with the Customer Service Base Entities plugin](https://www.servicenow.com/docs/XJC~8V_7JvR8SOVfRMskCw#r_RolesInstalledWithCustomerService__section_uff_bbj_x2b) below.

For more information about the CSM primary role structure and included roles, see [CSM roles and descriptions](https://www.servicenow.com/docs/XJC~8V_7JvR8SOVfRMskCw#r_RolesInstalledWithCustomerService__section_p5t_gcr_3mb) below.

## Explicit roles {#r_RolesInstalledWithCustomerService__section_pbn_1cr_3mb}

You may have business requirements that change the use of these roles. In addition, the
[Explicit Roles in CSM](https://www.servicenow.com/docs/4TH5XD7b55iQBpJ7Twl0fg "You can give both internal users and external users access to your instance. However, you might not want both types of users to have the same level of access. To provide added security, every user must have at least one role so that the instance can distinguish between internal and external users.") feature may assign both internal and
external roles to external users. It is important to regularly review user role assignments
to ensure that they are set according to your business requirements.  
For more information about reviewing and updating user role assignments, see:

* [KB0829930](https://support.servicenow.com/kb_view.do?sysparm_article=KB0829930)
* [Fix external user role
  assignments](https://www.servicenow.com/docs/JsHSHhgVI6lxPQYMv8On9w "You may have external users (contacts or consumers) on your instance that have been assigned internal roles. If so, you can use the Customer Service Management guided setup to evaluate and correct these role assignments as needed.")
{#r_RolesInstalledWithCustomerService__ul_lsw_ktj_w5b} .

## CSM roles and descriptions {#r_RolesInstalledWithCustomerService__section_p5t_gcr_3mb}

{#r_RolesInstalledWithCustomerService__table_fch_3kk_w5b__entry__3}

| Role title \[name\] | Description | Contains roles |
|-|-|-|
| Customer service agent \[sn_customerservice_agent\] | An agent who assists customers and partners with questions, issues, and problems. This user creates cases, views and edits cases, and works with customers and subject matter experts to resolve cases. A customer service agent typically supports a specific set of products across one or more communication channels. An agent can belong to one or more agent groups. | * knowledge * chat_admin * sn_customerservice.deescalation_requester * timecard_user * template_editor * sn_esm_agent * sn_shn.editor * domain_expand_scope {#r_RolesInstalledWithCustomerService__ul_zxx_zpb_kt} Note: The sn_esm_agent role contains the cmdb_read role. |
| Customer service manager \[sn_customerservice_manager\] | Customer service agent with the additional responsibility for managing agents or agent groups and overriding agent actions. | * sn_customerservice_agent * timecard_manager * timecard_approver * skill_admin * sn_app_cs_social_social_profile_user * sam * sn_customerservice.consumer_agent * asset * sn_shn.admin * sn_publications.approver * contract_manager * sn_app_cs_social_log_user * awa_manager * sn_majorissue_mgt.major_issue_manager * email_client_quick_message_author * workspace_admin * skill_model_user * sn_templated_snip.template_snippet_writer * approver_user Note: For customers upgrading to Xanadu, the approver_user role replaces the approval_admin role. Users with the customer service manager role can approve the approval requests that are assigned to them. * notify_view Note: The notify_view role is added to the sn_customerservice_manager role only when the Chat Zoom Connector application is installed. {#r_RolesInstalledWithCustomerService__ul_qhw_hxx_kt} |
| Consumer service agent \[sn_customerservice.consumer_agent\] | An agent who assists consumers with questions, issues, and problems. This user creates, views, and edits cases and works with consumers to resolve cases. An agent typically supports a specific set of products across one or more communication channels. An agent can belong to one or more agent groups. | * sn_esm_agent * chat_admin * sn_shn.editor * template_editor * knowledge {#r_RolesInstalledWithCustomerService__ul_ltf_zr4_vw} |
| Customer \[sn_customerservice.customer\] | Customer role for researching questions, issues, or problems. Customers can create cases and view and edit existing cases for themselves. They can also view a list of assets belonging to their accounts. | * sn_esm_user * snc_external {#r_RolesInstalledWithCustomerService__ul_k2n_2xx_kt} |
| Customer administrator \[sn_customerservice.customer_admin\] | Administrator role for a customer account. This user has access to data within the account. | * sn_customerservice.customer * sn_esm_user_admin {#r_RolesInstalledWithCustomerService__ul_ush_rzx_kt} |
| Customer case manager \[sn_customerservice.customer_case_manager\] | Customer role for managing the cases in an account and any related child accounts. The customer case manager role includes the privileges of the customer role and adds the following privileges: * Create a case on behalf of another contact in the account. * View a list of cases belonging to the account. * Edit cases belonging to the account. {#r_RolesInstalledWithCustomerService__ul_icw_lgc_qcb} Note: The customer case manager role is not automatically added to the sn_customerservice.contact_role_assignment system property. To expose this role to customer and partner administrators, navigate to Customer ServiceAdministrationProperties and add it to this property. | sn_customerservice.customer |
| Partner \[sn_customerservice.partner\] | Partner who is serving customer accounts. A partner can create a case for their own account or on behalf of a customer account. A partner can view and edit all of the cases that they have created: * For their own account. * On behalf of customer accounts that they are related to. {#r_RolesInstalledWithCustomerService__ul_ng2_3nv_ylb} Note: If you are establishing a new relationship between a partner and a customer, the partner or partner admin does not have access to historic cases created for the customer. This is because the historic cases do not have the Partner or Partner Contact fields populated on the Case form. | * sn_customerservice.customer * sn_esm_partner {#r_RolesInstalledWithCustomerService__ul_zb3_11y_kt} |
| Partner administrator \[sn_customerservice.partner_admin\] | Administrator role for a partner account. The partner administrator can do the following: * Access the data within the partner account. * Access the data created by the contacts in their company in the customer account. * Manage users for the partner account and for customer accounts. * View all of the cases created by a partner. {#r_RolesInstalledWithCustomerService__ul_yfh_2sv_ylb} | * sn_customerservice.partner * sn_customerservice.customer_admin * sn_esm_partner_admin {#r_RolesInstalledWithCustomerService__ul_npw_k1y_kt} |
| Consumer \[sn_customerservice.consumer\] | Consumer role for researching questions, issues, or problems. Consumers can create cases and view and edit existing cases for products that they have purchased. They can also view a list of their products. | * sn_esm_user * snc_external {#r_RolesInstalledWithCustomerService__ul_upb_3r4_vw} |
[Table 2. Primary CSM roles]

{#r_RolesInstalledWithCustomerService__table_fch_3kk_w5b}  
{#r_RolesInstalledWithCustomerService__table_bxx_zpb_kt__entry__3}

| Role title \[name\] | Description | Contains roles |
|-|-|-|
| Case contributor editor \[sn_customerservice.case_contributor_editor\] | This role provides limited write access to the fields on the Case form. It provides limited write access to those cases for which the user already has read access provided by another role. Limited write access is available for the following fields: * Work notes * Additional comments * Attachments * State or stage changes * Contributor users * Contributor groups * Watchlist * Work notes list {#r_RolesInstalledWithCustomerService__ul_xwt_gdd_smb} |   |
| Case contributor viewer \[sn_customerservice.case_contributor_viewer\] | This role provides read-only access to all of the tables associated with a case. With this role, a user can view the information in the related lists for a case if: * The user has been added to the Contributor User field or the Contributor Group field on the Case form. * The user has read-only access to cases through another role, such as the case viewer role (sn_customerservice.case_viewer) or the case task agent role (sn_customerservice.case_task_agent). {#r_RolesInstalledWithCustomerService__ul_hrm_q3j_3nb} With this role, a user can access the following modules in CSM Agent Workspace:All tasks I participate in | * sn_shn.user * wm_read {#r_RolesInstalledWithCustomerService__ul_npb_njj_3nb} |
| Case task agent \[sn_customerservice.case_task_agent\] | This role provides access to case tasks and related case information. A user with this role can work on the following case tasks: * Tasks that are assigned to the user or to the user's assignment groups. * Tasks that have been created by the user. {#r_RolesInstalledWithCustomerService__ul_oft_jyc_smb} With this role, the user can: * View and update assigned case tasks. * Create case tasks and assign those tasks to other users. * View and update created case tasks. * Add work notes, comments, and attachments to case tasks. * Update the status of case tasks. * Perform additional actions from a case task such as sending email. {#r_RolesInstalledWithCustomerService__ul_alj_pyc_smb} With this role, users have read-only access to customer information for the case: * Account and contact records (for B2B cases) * Consumer and household records (for B2C cases) * Service organization records (business location cases) {#r_RolesInstalledWithCustomerService__ul_u1n_j2d_smb} | * sn_customerservice.customer_data_viewer * sn_customerservice.csm_workspace_user * sn_customerservice.case_contributor_editor {#r_RolesInstalledWithCustomerService__ul_mqg_1mb_3nb} |
| Case task viewer \[sn_customerservice.case_task_viewer\] | This role provides read-only access to all case task records. Note: When combined with the case viewer role (sn_customerservice.case_viewer), a user can access all customer service cases and all case tasks. |   |
| Case viewer \[sn_customerservice.case_viewer\] | This role provides read-only access to all cases. |   |
| Contact manager \[sn_customerservice.contact_manager\] | User who can manage contacts. |   |
| Customer project manager \[sn_customerservice.projectmanager\] | A user who creates and manages projects for customer accounts. * Creates new projects. * Sets up project tasks and resource plans. * Identifies customer contacts who have access to projects and project tasks. * Assigns and manages tasks and dependencies. {#r_RolesInstalledWithCustomerService__ul_wk1_qfv_rkb} Note: This role is added with the Customer Project Management plugin (com.snc.csm_ppm) | sn_customerservice.customer_data_viewer |
| Customer project stakeholder \[sn_customerservice.projectstakeholder\] | A user who is responsible for activities that require viewing customer project details and project tasks. Note: This role is added with the Customer Project Management plugin (com.snc.csm_ppm) |   |
| Data viewer \[sn_customerservice.customer_data_viewer\] | User with read-only access to customer data entities such as: * Install base items * Contracts * Entitlements * Accounts, contacts, and account team members * Assets * Consumers * Sold product {#r_RolesInstalledWithCustomerService__ul_zx1_ncn_fkb} |   |
| De-escalation requester \[sn_customerservice.deescalation_requester\] | User who can deescalate a case or account when the cause of the escalation is resolved. | sn_customerservice.escalation_requester |
| Escalation requester (sn_customerservice.escalation_requester) | User who can request an escalation for a case or account. | sn_customerservice.consumer_agent |
| Proxy case creator \[sn_customerservice.proxy_case_creator\] | Users with the proxy case creator role can create customer service cases directly from community questions created by contacts or consumers |   |
| Proxy contact \[sn_customerservice.proxy_contact\] | Role that enables employees to create cases for customer accounts and contacts. Employees can also be proxy case contacts on behalf of customers. Assign this role to employees in your company who are not fulfillers or do not have other CSM-specific roles. Users with this role can: * Create customer service cases using a record producer. * Add work notes and comments to any case. * Update the watch list of any case. {#r_RolesInstalledWithCustomerService__ul_a3y_ndr_3mb} Note: The CSM Extension for Proxy Contacts (com.snc.csm_proxy_contacts) plugin adds this role. |   |
| Workspace user \[sn_customerservice.csm_workspace_user\] | This role provides access to case tasks from the following modules in CSM Agent Workspace: * My Case Tasks * My Group's Case Tasks {#r_RolesInstalledWithCustomerService__ul_e5f_bdc_3nb} Users can also: * Use Agent Assist to search for knowledge articles (if the User Criteria is set to provide access to knowledge). * Create email (if the user has write access to the record and the email_composer role). * View response templates (if response templates have been configured for the record. {#r_RolesInstalledWithCustomerService__ul_ig1_ldc_3nb} Note: By default, this role is added to the case task agent role (sn_customerservice.case_task_agent). |   |
[Table 3. Additional CSM roles]

{#r_RolesInstalledWithCustomerService__table_bxx_zpb_kt}

## Roles installed with the Customer Service Base Entities plugin {#r_RolesInstalledWithCustomerService__section_uff_bbj_x2b}

The following roles are installed with the Customer Service Base Entities plugin.  
{#r_RolesInstalledWithCustomerService__table__csm_base_entities_plugin_roles__entry__2}

| Role | Contains roles |
|-|-|
| Service management agent \[sn_esm_agent\] | * assignment_workbench * wm_read * cmdb_read * agent_schedule_user * interaction_agent {#r_RolesInstalledWithCustomerService__ul_vxb_cbj_x2b} |
| Service management partner \[sn_esm_partner\] | sn_esm_user |
| Service management user admin \[sn_esm_user_admin\] | sn_esm_user |
| Service management admin \[sn_esm_admin\] | None |
| Service management user \[sn_esm_user\] | * snc_external * sn_apptmnt_booking.appointment_booking_user {#r_RolesInstalledWithCustomerService__ul_ocp_dcj_x2b} |
| Service management partner admin \[sn_esm_partner_admin\] | * sn_esm_user_admin * sn_esm_admin {#r_RolesInstalledWithCustomerService__ul_xxy_kcj_x2b} |
| Role for REST APIs related to CSM web services \[csm_ws_integration\] | snc_internal |
[Table 4. Customer Service Base Entities roles]

{#r_RolesInstalledWithCustomerService__table__csm_base_entities_plugin_roles}
* **[Internal user data](https://www.servicenow.com/docs/eX92fLEQ0sgBadVO6aLAqw)**   
  Internal user data includes information about the users who are internal to your organization, such as managers, agents, and other employees. Internal users can also belong to user groups.
* **[Business Stakeholder for Customer Service Management](https://www.servicenow.com/docs/gv14cWTvuUPgrx6HJS39XA)**   
  Business Stakeholder for Customer Service Management includes plugins and roles that provide access to business stakeholder features.
* **[Explicit Roles in CSM](https://www.servicenow.com/docs/4TH5XD7b55iQBpJ7Twl0fg)**   
  You can give both internal users and external users access to your instance. However, you might not want both types of users to have the same level of access. To provide added security, every user must have at least one role so that the instance can distinguish between internal and external users.
* **[Provide external users access to a table](https://www.servicenow.com/docs/wEeOA7FJEAVchh3r27FuTQ)**   
  To enable users with only the snc_external role to access the list view of a table, you must create a series of ACLs.
* **[Creating custom user roles](https://www.servicenow.com/docs/WmBM6uyA8kthCdf3UnQZEg)**   
  System administrators can create custom roles or modify the access of existing roles by using script includes and extension points/instances.

**Related concepts**   

* [Fix external user role assignments](https://www.servicenow.com/docs/JsHSHhgVI6lxPQYMv8On9w "You may have external users (contacts or consumers) on your instance that have been assigned internal roles. If so, you can use the Customer Service Management guided setup to evaluate and correct these role assignments as needed.")

*[\>]: and then


