---
sourceDocument: Zurich Platform security
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/platform-security

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# External roles in self-registration

# External roles in self-registration {#ariaid-title1}

Release version: Zurich  
Updated July 31, 2025  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read  
To prevent inadvertently providing access to external users, you can assign the
snc_external role to all external users.

External users that self-register must be assigned the snc_external role, which has the least
privileges. The snc_external role indicates that the user is external to your organization and
should not have any access to resources unless explicitly allowed through ACLs for the
snc_external role or additional roles that inherit the snc_external role.  
By default, users with the snc_external role cannot access:

* Tables without the role that inherits the snc_external role or the public role.
* Non-record type resources, such as processors and UI pages without the snc_external role or a role that inherits the snc_external role.
* Platform Analytics dashboards.
{#external-roles-self-registration__ul_vjt_dc1_tlb}

Beginning with the Paris release, you must enable an exclude-list property to enforce the
explicit assignment of snc_external roles. For information about enabling the property, see [Prevent future internal role assignments for external users](https://www.servicenow.com/docs/access?context=fix-csm-external-user-roles-task4&version=zurich&pubname=zurich-customer-service-management&ft:locale=en-US).

