Roles installed with customer access management
Summarize
Summary of Roles installed with customer access management
Customer Access Management in ServiceNow Australia release utilizes functional and granular roles to control user access to cases, sold products, install base, and related entities. These roles help establish secure and precise relationships between users and customer service management (CSM) entities, ensuring authorized parties have appropriate access while maintaining data security.
Show less
Granular roles define specific permissions on individual entities, while functional roles bundle multiple granular roles to enable meaningful, broader actions. This role structure allows you to create tailored access policies that improve operational efficiency and enhance the customer experience.
Key Features
- Functional Roles: Comprised of multiple granular roles to support complex access requirements across multiple entities. Examples include Case Authorized Contact, Sold Product Authorized Contact, and Install Base Authorized Contact roles.
- Granular Roles: Provide fine-grained read or write access to cases, sold products, install base records, related parties, and installed products. They form the building blocks of functional roles.
- Role Assignments: Functional roles link specific collections of granular roles to define access rules for various CSM entities, enabling flexible and secure user permissions.
- Plugin Dependencies: Some roles require specific ServiceNow plugins, such as Customer Service [com.sncustomerservice] and Install Base Management [com.snc.installbase], to enable their associated permissions.
Practical Role Examples and Their Access Capabilities
- Case Authorized Contact/Consumer/Contributor: Access to add comments, attachments, accept/reject solutions, receive notifications, close cases, and update tasks related to cases.
- Sold Product Authorized Contact/Consumer: Permission to view sold products and install base items, create and access related cases, and manage service catalog requests.
- Install Base Authorized Contact/Consumer/Contributor/Member: Ability to view install base and related sold products, manage related cases, and create cases when related to the same account.
- Install Base Service Organization and Account Roles: Enable members or contacts to view and manage cases for install base records they are related to.
Why This Matters
This role framework enables ServiceNow customers to finely control who can view or modify customer-related data and cases. By assigning the correct combination of granular and functional roles, customers can enforce security policies, delegate responsibilities effectively, and ensure relevant users have access to the right information to support and resolve customer issues efficiently.
Next Steps for Customers
- Identify the appropriate functional roles needed for your user base based on their job responsibilities.
- Assign granular roles to functional roles to customize permissions as necessary.
- Ensure required plugins are installed to support the roles you intend to use.
- Leverage these roles to implement secure, role-based access control in your Customer Service Management environment.
Customer access management uses different functional and granular roles to establish relationships between users and entities. The granular and functional roles help provide user access to information and maintain data security.
Functional and granular roles overview
Functional and granular roles help provide authorized related parties access to the case, and provide additional contacts or additional consumers access to the sold product.
Granular roles provide access to cases, sold product, and related entities. One or more granular roles can be bundled together as a functional role to perform a meaningful action. Linking multiple granular roles to a functional role enables you to build your own access rules by applying the functional and granular roles for various Customer Service Management (CSM) entities.
A granular model helps to protect data by granting the required level of access to the relevant CSM entities. With this functionality, each role is associated with a set of privileges or responsibilities that determine your access to certain information. You can set granular policies that authorize individuals to do their jobs efficiently and effectively, which helps to improve the customer experience.
Roles and descriptions
Functional roles are a set of granular roles that are required to perform a function that requires access on multiple entities. The following table lists the functional roles for customer access management.
| Role title [name] | Plugins required | Description | Contains roles |
|---|---|---|---|
| Case Authorized Contact [sn_customerservice.case_authorized_contact] |
Customer Service [com.sn_customerservice] |
This role provides access to add additional comments and attachments, accept or reject a solution, receive notifications on case updates, close a case, and update case tasks. | sn_customerservice.case_write_granular |
| Case Authorized Consumer [sn_customerservice.case_authorized_consumer] |
Customer Service [com.sn_customerservice] |
This role provides access to add additional comments and attachments, accept or reject a solution, receive notifications on case updates, close a case, and update case tasks. | sn_customerservice.case_write_granular |
| Case Authorized Contributor [sn_customerservice.case_authorized_contributor] |
Customer Service [com.sn_customerservice] |
This role provides access to add additional comments and attachments, accept or reject a solution, receive notifications on case updates, close a case, and update case tasks. | sn_customerservice.case_write_granular |
| Sold Product Authorized Contact [sn_install_base.sold_product_authorized_contact] |
Customer Service Install Base Management [com.snc.install_base] |
This role provides access to view sold product and associated install base items, create cases, and access cases that are related to the sold product. Also, this role provides access to sold product related parties, affected install base items, and manage service catalog requests from the sold product. |
|
| Sold Product Authorized Consumer [sn_install_base.sold_product_authorized_consumer] |
Customer Service Install Base Management [com.snc.install_base] |
This role provides access to view sold product and associated install base items, create cases, and access cases related to the sold product. Also, this role provides access to sold product related parties, affected install base items, and manage service catalog requests from the sold product. |
|
| Install Base Authorized Contact [sn_install_base.install_base_authorized_contact] |
Customer Service Install Base Management [com.snc.install_base] |
This role provides the contact access to view the install base and its associated sold products when added as a related party. Additionally, it enables the contact to create and manage cases for the related install base records. Creation of case is only enabled if the contact and install base belong to the same account. |
|
| Install Base Authorized Consumer [sn_install_base.install_base_authorized_consumer] |
Customer Service Install Base Management [com.snc.install_base] |
This role provides the consumer access to view the install base and its associated sold products when added as a related party. Additionally, it enables you to create and manage cases for the related install base records. |
|
| Install Base Authorized Contributor [sn_install_base.install_base_authorized_contributor] |
Customer Service Install Base Management [com.snc.install_base] |
This role provides the internal user to view the install base and its associated sold products when added as a related party. Additionally, it enables you to create and manage cases for the related install base records. |
|
| Install Base Authorized Member [sn_install_base.install_base_authorized_member] |
Customer Service Install Base Management [com.snc.install_base] |
This role provides the service organization member to view the install base and its associated sold products when added as a related party. Additionally, it enables you to create and manage cases for the related install base records. |
|
| Install Base Authorized Account | Customer Service Install Base Management [com.snc.install_base] |
Provides access to all the contacts of the account to view the install base and its associated sold products when added as a related party. Additionally, it enables the contact to create and manage cases for the related install base records. Creation of case is only enabled if contact and install base belongs to same account. |
|
| Install Base Service Organization | Customer Service Install Base Management [com.snc.install_base] |
Provides access to all the members of service organization to view the install base and its associated sold products when added as a related party. Additionally, it enables you to manage cases for the related install base records. |
|
The following table lists the granular roles for customer access management.
| Role title [name] | Plugin required | Description | Contains roles |
|---|---|---|---|
| Sold Product Read [sn_install_base.sold_product_read_granular] |
Customer Service Install Base Management
[com.snc.install_base] |
This role provides granular read access to the sold product. | None |
| Sold Product Contact
Read [sn_install_base.sold_product_contact_read_granular] |
Customer Service Install Base Management
[com.snc.install_base] |
This role provides granular read access to related parties of the sold product. | None |
| Sold Product Contact
Write [sn_install_base.sold_product_contact_write_granular] |
Customer Service Install Base Management
[com.snc.install_base] |
This role provides granular write access to related parties of the sold product. | sn_install_base.sold_product_contact_read_granular |
| Sold Product Consumer
Read [sn_install_base.sold_product_consumer_read_granular] |
Customer Service Install Base Management
[com.snc.install_base] |
This role provides granular read access to additional consumers of the sold product and sold product-related parties. | None |
| Sold Product Consumer
Write [sn_install_base.sold_product_consumer_write_granular] |
Customer Service Install Base Management
[com.snc.install_base] |
This role provides granular write access to additional consumers of the sold product and sold product-related parties. | sn_install_base.sold_product_consumer_read_granular |
| Case Read [sn_customerservice.case_read_granular] |
Customer Service [com.sn_customerservice] |
This role provides granular read access to the case. | None |
| Cases Create [sn_customerservice.case_create_granular] |
Customer Service [com.sn_customerservice] |
This role provides granular create access to the case. | sn_customerservice.case_read_granular |
| Case Write [sn_customerservice.case_write_granular] |
Customer Service [com.sn_customerservice] |
This role provides granular write access to the case. |
|
| Case Related Party Write
[sn_customerservice.case_related_party_write_granular] |
Customer Service [com.sn_customerservice] |
This role provides granular write access to case-related parties. | None |
| Install Base Read [sn_install_base.install_base_read_granular] |
Customer Service Install Base Management
[com.snc.install_base] |
This role provides granular read access to the install base. | None |
| Install Base Related Party
Read [sn_install_base.install_base_related_party_read_granular] |
Customer Service Install Base Management
[com.snc.install_base] |
This role provides granular read access to install base related party records. | None |
| Install Base Related Party
Write [sn_install_base.install_base_related_party_write_granular] |
Customer Service Install Base Management
[com.snc.install_base] |
This role provides granular write access to install base related party records. | [sn_install_base.install_base_related_party_read_granular] |
| Installed Product
Read [sn_install_base.installed_product_read_granular] |
Customer Service Install Base Management
[com.snc.install_base] |
This role provides granular read access to the installed product. | None |