GRC: Entity Based Access for AI assets

  • Release version: Zurich
  • Updated March 12, 2026
  • 2 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of GRC: Entity Based Access for AI assets

    The GRC: Entity Based Access (EBA) application in the Zurich release provides granular data-level security for AI asset records within the AI Risk and Compliance application. It ensures that sensitive AI risk and compliance data is accessible only to authorized users based on business entities such as departments, regions, or business units. This approach enhances compliance and confidentiality by controlling visibility of linked records while keeping core entities visible to all users.

    Show full answer Show less

    Key Features

    • Entity-Based Access Control: Restricts access to AI asset-related data based on entity membership rather than just roles, enabling fine-tuned data segregation.
    • Access to AI Risk and Compliance Data: Authorized users can access risks, controls, issues, indicators, AI asset tasks, attestations, and risk assessments linked to AI assets.
    • Entity Visibility: Entities remain visible to all users, but linked records are only visible to those with appropriate permissions.
    • Supported Tables: Access applies to key AI asset tables including AI system, AI system entity mapping, and AI system tasks.
    • Configurable Entity Classes and Types: Entities created with AI assets are assigned classes (e.g., AI system, AI model) which must be configured to apply access restrictions correctly.
    • Bulk Access Management: Provides a guided utility to set access restrictions on existing records efficiently.
    • Automated Access Rules: Enables configuration of entity-based record access rules to automatically restrict access for new records.

    Configuration and Usage

    • Install the GRC: Entity Based Access application to enable these capabilities.
    • Enable or disable entity-based access properties to control access for AI asset-associated objects.
    • Configure entity classes and types appropriately for linked objects to enforce access controls.
    • Use the entity-based record access update utility for bulk updating access restrictions on existing records.
    • Set up entity-based record access rules to automate access restrictions on new data.

    Practical Implications for ServiceNow Customers

    By implementing the GRC: Entity Based Access for AI assets, customers can securely manage sensitive AI governance data with precise control, ensuring compliance with internal policies and regulatory requirements. This solution helps maintain data confidentiality while supporting necessary visibility for operational efficiency. It is essential to configure entity classes and access rules carefully to align with organizational structure and security needs.

    The GRC: Entity Based Access application enables you to segregate data on the AI asset records to ensure that only authorized users can access sensitive AI Risk and Compliance data while maintaining visibility into core entities. Entity-based access administrators can use this application to set up secure, controlled access to various AI assets and its related objects.

    GRC: Entity Based Access for AI assets

    Entity-Based Access (EBA) is a security feature designed to provide granular, data-level access control within AI Risk and Compliance application. Unlike role-based access control, EBA decides which records a user can access based on business entities such as departments, regions, or business units. This approach ensures that sensitive information is only accessible to authorized users, aligning with organizational compliance and confidentiality requirements.

    AI Risk and Compliance managers can access risks, controls, related entities, issues, indicators, AI asset tasks, risk assessments, attestations, and AI assets data through entity-based access. Entities themselves stay visible to all users, while visibility of linked records is limited to authorized users.

    When a user is qualified based on these configurations and has the minimum required roles, they have access to the following tables:
    • AI system [sn_grc_ai_gov_ai_system]
    • AI system entity [sn_grc_ai_gov_ai_system_entity_map]
    • AI system task [sn_grc_ai_gov_ai_system_task]

    Configure GRC: Entity Based Access

    The following tasks must be performed to enable and use GRC: Entity Based Access for the AI asset records.
    1. Install the GRC: Entity Based Access application. For more information, refer to Install the Entity Based Access application.
    2. Enable or disable the entity-based Access properties to control access to the objects that are associated with an AI asset. For more information, refer to Set up Entity Based Access properties.
    3. Configure an entity class for a linked object by using the GRC: Entity Based Access application. For more information, refer to Configure an entity class for a linked object.
      Note:
      Entities created with an AI asset are assigned an entity class such as AI system, AI model, dataset, or MCP server, depending on their category. To apply access restrictions to these entities, you must configure the appropriate entity class settings.
    4. Configure an entity type by using the GRC: Entity Based Access application. For more information, refer to Configure an entity type for a linked object.
    5. Set access restrictions for the existing records in bulk by using the entity-based record access update utility guided-experience. For more information, refer to Set access restrictions using an entity based record access update utility.
    6. Configure entity-based record access rules on record types to apply access restrictions to new records automatically. For more information, refer to Configure entity-based record access rules.
      Note:
      Three records are provided by default, each with specific field configurations. The AI Asset record (sn_grc_ai_gov_ai_system) includes Analyst and Business owner as user fields, and Analyst Group as a group field. For AI Asset task (sn_grc_ai_gov_ai_system_task), you can find Assigned to and Watch list as user fields. The Related Entity record (sn_grc_ai_gov_ai_system_entity_map) doesn’t have any user or group fields configured by default.