Roles installed with customer access management

  • Release version: Australia
  • Updated March 12, 2026
  • 5 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Roles installed with customer access management

    Customer Access Management in ServiceNow Australia release utilizes functional and granular roles to control user access to cases, sold products, install base, and related entities. These roles help establish secure and precise relationships between users and customer service management (CSM) entities, ensuring authorized parties have appropriate access while maintaining data security.

    Show full answer Show less

    Granular roles define specific permissions on individual entities, while functional roles bundle multiple granular roles to enable meaningful, broader actions. This role structure allows you to create tailored access policies that improve operational efficiency and enhance the customer experience.

    Key Features

    • Functional Roles: Comprised of multiple granular roles to support complex access requirements across multiple entities. Examples include Case Authorized Contact, Sold Product Authorized Contact, and Install Base Authorized Contact roles.
    • Granular Roles: Provide fine-grained read or write access to cases, sold products, install base records, related parties, and installed products. They form the building blocks of functional roles.
    • Role Assignments: Functional roles link specific collections of granular roles to define access rules for various CSM entities, enabling flexible and secure user permissions.
    • Plugin Dependencies: Some roles require specific ServiceNow plugins, such as Customer Service [com.sncustomerservice] and Install Base Management [com.snc.installbase], to enable their associated permissions.

    Practical Role Examples and Their Access Capabilities

    • Case Authorized Contact/Consumer/Contributor: Access to add comments, attachments, accept/reject solutions, receive notifications, close cases, and update tasks related to cases.
    • Sold Product Authorized Contact/Consumer: Permission to view sold products and install base items, create and access related cases, and manage service catalog requests.
    • Install Base Authorized Contact/Consumer/Contributor/Member: Ability to view install base and related sold products, manage related cases, and create cases when related to the same account.
    • Install Base Service Organization and Account Roles: Enable members or contacts to view and manage cases for install base records they are related to.

    Why This Matters

    This role framework enables ServiceNow customers to finely control who can view or modify customer-related data and cases. By assigning the correct combination of granular and functional roles, customers can enforce security policies, delegate responsibilities effectively, and ensure relevant users have access to the right information to support and resolve customer issues efficiently.

    Next Steps for Customers

    • Identify the appropriate functional roles needed for your user base based on their job responsibilities.
    • Assign granular roles to functional roles to customize permissions as necessary.
    • Ensure required plugins are installed to support the roles you intend to use.
    • Leverage these roles to implement secure, role-based access control in your Customer Service Management environment.

    Customer access management uses different functional and granular roles to establish relationships between users and entities. The granular and functional roles help provide user access to information and maintain data security.

    Functional and granular roles overview

    Functional and granular roles help provide authorized related parties access to the case, and provide additional contacts or additional consumers access to the sold product.

    Granular roles provide access to cases, sold product, and related entities. One or more granular roles can be bundled together as a functional role to perform a meaningful action. Linking multiple granular roles to a functional role enables you to build your own access rules by applying the functional and granular roles for various Customer Service Management (CSM) entities.

    A granular model helps to protect data by granting the required level of access to the relevant CSM entities. With this functionality, each role is associated with a set of privileges or responsibilities that determine your access to certain information. You can set granular policies that authorize individuals to do their jobs efficiently and effectively, which helps to improve the customer experience.

    Roles and descriptions

    Functional roles are a set of granular roles that are required to perform a function that requires access on multiple entities. The following table lists the functional roles for customer access management.

    Table 1. Functional roles
    Role title [name] Plugins required Description Contains roles
    Case Authorized Contact

    [sn_customerservice.case_authorized_contact]

    Customer Service

    [com.sn_customerservice]

    This role provides access to add additional comments and attachments, accept or reject a solution, receive notifications on case updates, close a case, and update case tasks.

    sn_customerservice.case_write_granular

    Case Authorized Consumer

    [sn_customerservice.case_authorized_consumer]

    Customer Service

    [com.sn_customerservice]

    This role provides access to add additional comments and attachments, accept or reject a solution, receive notifications on case updates, close a case, and update case tasks.

    sn_customerservice.case_write_granular

    Case Authorized Contributor

    [sn_customerservice.case_authorized_contributor]

    Customer Service

    [com.sn_customerservice]

    This role provides access to add additional comments and attachments, accept or reject a solution, receive notifications on case updates, close a case, and update case tasks.

    sn_customerservice.case_write_granular

    Sold Product Authorized Contact

    [sn_install_base.sold_product_authorized_contact]

    Customer Service Install Base Management

    [com.snc.install_base]

    This role provides access to view sold product and associated install base items, create cases, and access cases that are related to the sold product. Also, this role provides access to sold product related parties, affected install base items, and manage service catalog requests from the sold product.
    • sn_customerservice.case_authorized_contact
    • sn_install_base.sold_product_contact_read_granular
    • sn_install_base.sold_product_read_granular
    • sn_install_base.install_base_read_granular
    • sn_install_base.installed_product_read_granular
    Sold Product Authorized Consumer

    [sn_install_base.sold_product_authorized_consumer]

    Customer Service Install Base Management

    [com.snc.install_base]

    This role provides access to view sold product and associated install base items, create cases, and access cases related to the sold product. Also, this role provides access to sold product related parties, affected install base items, and manage service catalog requests from the sold product.
    • sn_customerservice.case_authorized_consumer
    • sn_install_base.sold_product_consumer_read_granular
    • sn_install_base.sold_product_read_granular
    • sn_install_base.install_base_read_granular
    • sn_install_base.installed_product_read_granular
    Install Base Authorized Contact

    [sn_install_base.install_base_authorized_contact]

    Customer Service Install Base Management

    [com.snc.install_base]

    This role provides the contact access to view the install base and its associated sold products when added as a related party. Additionally, it enables the contact to create and manage cases for the related install base records.​ Creation of case is only enabled if the contact and install base belong to the same account.
    • sn_customerservice.case_write_granular​
    • sn_install_base.install_base_related_party_write_granular​
    • sn_install_base.sold_product_read_granular
    • sn_install_base.install_base_read_granular
    • sn_install_base.installed_product_read_granular
    Install Base Authorized Consumer

    [sn_install_base.install_base_authorized_consumer]

    Customer Service Install Base Management

    [com.snc.install_base]

    This role provides the consumer access to view the install base and its associated sold products when added as a related party. Additionally, it enables you to create and manage cases for the related install base records.​
    • sn_customerservice.case_write_granular​
    • sn_install_base.install_base_related_party_write_granular​
    • sn_install_base.sold_product_read_granular
    • sn_install_base.install_base_read_granular
    • sn_install_base.installed_product_read_granular
    Install Base Authorized Contributor

    [sn_install_base.install_base_authorized_contributor]

    Customer Service Install Base Management

    [com.snc.install_base]

    This role provides the internal user to view the install base and its associated sold products when added as a related party. Additionally, it enables you to create and manage cases for the related install base records.​​
    • sn_customerservice.case_write_granular​
    • sn_install_base.install_base_related_party_write_granular​
    • sn_install_base.sold_product_read_granular
    • sn_install_base.install_base_read_granular
    • sn_install_base.installed_product_read_granular
    Install Base Authorized Member

    [sn_install_base.install_base_authorized_member]

    Customer Service Install Base Management

    [com.snc.install_base]

    This role provides the service organization member to view the install base and its associated sold products when added as a related party. Additionally, it enables you to create and manage cases for the related install base records.​
    • sn_customerservice.case_write_granular​
    • sn_install_base.install_base_related_party_write_granular​
    • sn_install_base.sold_product_read_granular
    • sn_install_base.install_base_read_granular
    • sn_install_base.installed_product_read_granular
    Install Base Authorized Account Customer Service Install Base Management

    [com.snc.install_base]

    Provides access to all the contacts of the account to view the install base and its associated sold products when added as a related party. Additionally, it enables the contact to create and manage cases for the related install base records. Creation of case is only enabled if contact and install base belongs to same account.
    • sn_customerservice.case_write_granular​
    • sn_install_base.install_base_related_party_write_granular​
    • sn_install_base.sold_product_read_granular
    • sn_install_base.install_base_read_granular
    • sn_install_base.installed_product_read_granular
    Install Base Service Organization Customer Service Install Base Management

    [com.snc.install_base]

    Provides access to all the members of service organization to view the install base and its associated sold products when added as a related party. Additionally, it enables you to manage cases for the related install base records.
    • sn_customerservice.case_write_granular​
    • sn_install_base.install_base_related_party_write_granular​
    • sn_install_base.sold_product_read_granular
    • sn_install_base.install_base_read_granular
    • sn_install_base.installed_product_read_granular

    The following table lists the granular roles for customer access management.

    Table 2. Granular roles
    Role title [name] Plugin required Description Contains roles
    Sold Product Read

    [sn_install_base.sold_product_read_granular]

    Customer Service Install Base Management

    [com.snc.install_base]

    This role provides granular read access to the sold product.

    None

    Sold Product Contact Read

    [sn_install_base.sold_product_contact_read_granular]

    Customer Service Install Base Management

    [com.snc.install_base]

    This role provides granular read access to related parties of the sold product.

    None

    Sold Product Contact Write

    [sn_install_base.sold_product_contact_write_granular]

    Customer Service Install Base Management

    [com.snc.install_base]

    This role provides granular write access to related parties of the sold product.

    sn_install_base.sold_product_contact_read_granular

    Sold Product Consumer Read

    [sn_install_base.sold_product_consumer_read_granular]

    Customer Service Install Base Management

    [com.snc.install_base]

    This role provides granular read access to additional consumers of the sold product and sold product-related parties.

    None

    Sold Product Consumer Write

    [sn_install_base.sold_product_consumer_write_granular]

    Customer Service Install Base Management

    [com.snc.install_base]

    This role provides granular write access to additional consumers of the sold product and sold product-related parties.

    sn_install_base.sold_product_consumer_read_granular

    Case Read

    [sn_customerservice.case_read_granular]

    Customer Service

    [com.sn_customerservice]

    This role provides granular read access to the case.

    None

    Cases Create

    [sn_customerservice.case_create_granular]

    Customer Service

    [com.sn_customerservice]

    This role provides granular create access to the case.

    sn_customerservice.case_read_granular

    Case Write

    [sn_customerservice.case_write_granular]

    Customer Service

    [com.sn_customerservice]

    This role provides granular write access to the case.
    • sn_customerservice.case_read_granular
    • sn_customerservice.case_create_granular
    Case Related Party Write

    [sn_customerservice.case_related_party_write_granular]

    Customer Service

    [com.sn_customerservice]

    This role provides granular write access to case-related parties.

    None

    Install Base Read

    [sn_install_base.install_base_read_granular]

    Customer Service Install Base Management

    [com.snc.install_base]

    This role provides granular read access to the install base.

    None

    Install Base Related Party Read

    [sn_install_base.install_base_related_party_read_granular​]

    Customer Service Install Base Management

    [com.snc.install_base]

    This role provides granular read access to install base related party records.​

    None

    Install Base Related Party Write

    [sn_install_base.install_base_related_party_write_granular]

    Customer Service Install Base Management

    [com.snc.install_base]

    This role provides granular write access to install base related party records.​

    [sn_install_base.install_base_related_party_read_granular​]

    Installed Product Read

    [sn_install_base.installed_product_read_granular]

    Customer Service Install Base Management

    [com.snc.install_base]

    This role provides granular read access to the installed product.

    None