---
sourceDocument: Zurich ServiceNow AI Platform Administration
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/platform-administration

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich ServiceNow AI Platform Administration

ft:clusterId :

    - platadm

bundleId :

    - platadm

workflow :

    - Platform


---

# Create a role

# Create a role {#ariaid-title1}

Release version: Zurich  
Updated July 31, 2025  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read  
Create a role to control access to features and capabilities in applications and modules. The new role doesn't have access to any application or module until you add other roles to it, or add it to the appropriate applications
and modules.

## Before you begin

Role required: admin

## About this task

After access has been granted to a role, all groups or users assigned to the role are granted the access. Roles can contain other roles, and any access granted to a role is granted to any role that contains it.

For a complete list of the roles included with the base instance, see [Base system roles](https://www.servicenow.com/docs/bqYfH6PuUGdef7IBat7u6A "Administrators can assign one or more base system user roles to grant access to base system platform features and applications.")  
Warning:  
If your organization hasn't manually allocated user-based subscriptions before,subscription assignments are based on user roles and the kind of access each role permits. Creating, customizing, and assigning roles can have subscription usage impact. For more information about how roles are evaluated for subscription assignment, see [Automatic subscription assignment](https://www.servicenow.com/docs/nqUmUL8ybe5gUQTn0eegmg "If your organization has never manually allocated user-based subscriptions before, entitlements are automatically assigned based on user roles and ACL access. Reviewing how roles are evaluated for automatic subscription assignment can help you make decisions about which roles users should have.").

Move this action to the background so you aren't waiting when adding a number of group members by adding the system property glide.ui.schedule_slushbucket_save_for_group_roles. Set the system property to
true. The system user is used to create records or update existing ones since the action is running in the background.

## Procedure

1. Navigate to AllUser AdministrationRoles and create a record.
2. Complete the form.  
   {#t_CreateARole__table_cgz_hzf_xq__entry__2}

   | Field | Description |
   |-|-|
   | Name | Enter a name for the role. |
   | Requires Subscription | Indicates whether users with this role require a subscription to stay in compliance. Yes :   Measured-role that requires a subscription. You can allocate subscriptions to users with this role by adding one or more groups to a product subscription. To learn more, see [Managing per-user subscriptions in Subscription Management](https://www.servicenow.com/docs/6Y0rGt6Pjt5vbvGqSqwMoA "Manage your per-user subscription allocations using Subscription Management."). No :   Not a measured-role. Unspecified :   Neither |
   | Application | Select the application that contains this record. |
   | Elevated privilege | A role that requires elevated privilege can't be assigned to a user at login by the system. Instead, a user must manually elevate privileges to receive the elevated role. Select this option to mark this role as required to elevate it to high security. See [Elevated privilege roles](https://www.servicenow.com/docs/access?context=c_ElevatedPrivilege&version=zurich&pubname=zurich-platform-security&ft:locale=en-US) for more information. |
   | Description | Select the roles to delegate to the group member. |
   [ ]

   {#t_CreateARole__table_cgz_hzf_xq}
* **[Grant a role access to applications and modules](https://www.servicenow.com/docs/fJsMD7LtIeOzG10KUsPmCQ)**   
  Roles control access to features and capabilities in applications and modules. You add a role to an application or module to enable the role to grant access to the application or module for all users with the role.
* **[Assign a role to a group](https://www.servicenow.com/docs/k_BiAe10FC_bwT4KzXs~JA)**   
  You can assign a role to a group to grant access to applications and modules to group members.
* **[Assign a role to a user](https://www.servicenow.com/docs/P0jZfGFxvWEPzQ8FpcUv3Q)**   
  A user inherits roles from all groups to which they belong. You can also assign roles directly to a user. Whenever a user is assigned a new role, it only takes effect after logging in with a new session.
* **[Add a role to an existing role](https://www.servicenow.com/docs/mSYLZZWrEC6B_GhbzwgAQQ)**   
  When you add a new role to an existing role for a user, the user inherits the access that is granted by the new role.
* **[Create a group role](https://www.servicenow.com/docs/fsmYoBOAOKNh~_4XG8LUSA)**   
  Create a group role to control access to features and capabilities in applications for all members in a group.

*[\>]: and then


