Using CPQ user access management
Summarize
Summary of Using CPQ user access management
This guide explains how ServiceNow customers can manage access to the ServiceNow CPQ Admin interface using the User Access utility. It enables administrators to grant or remove admin rights, control access levels for users, and troubleshoot common access issues. Managing access ensures only authorized users can perform administrative tasks, while others have end-user permissions for configuration activities.
Show less
Key Features
- User Access Utility: Accessible via
Admin > Utilities > User Access, this interface lists all users with their current access levels displayed in tooltips. - Access Levels:
- ADMIN: Full admin rights to create and modify blueprints, fields, rules, and other configurations.
- ENDUSER: Permission to create configurations but no administrative capabilities; suitable for sales users and partners.
- CSV Import and Export: Admins can export a sample CSV file, edit user access levels (adding or removing admin rights), and import changes to update multiple users efficiently.
- Individual User Editing: Clicking on a username opens an edit window where admin access can be toggled on or off for that user.
- Access Control Defaults: Existing users initially have both ADMIN and ENDUSER access; new users start with ENDUSER access only and require explicit admin access assignment.
- Enabling the Utility: The User Access utility must be enabled via a ServiceNow support request.
Troubleshooting and Additional Considerations
- If users see an "unknown error" message when accessing CPQ Admin, verify that admin access is enabled for their account by an existing admin.
- Users may need to restart their browser, clear cache, or remove CPQ session cookies after access changes.
- When importing user data via CSV, ensure usernames match the case sensitivity of the system records; for Salesforce integrated environments, usernames should be lowercase.
- Users are created upon first accessing a CPQ instance and authenticating via the authorization provider.
Manage access to the ServiceNow CPQ Admin interface. Grant or remove admin rights and troubleshoot access issues.
The User Access utility allows managing access to selected areas of ServiceNow CPQ Admin. Admin users have full admin access unless their access level is modified via CSV import.
ServiceNow CPQ Admins can control access to the ServiceNow CPQ Admin interface by granting admin access only to specific users. All existing users have admin access, which can be adjusted to end-user access as needed. New users automatically receive end-user access and need to be explicitly granted admin access by a user with admin access.
Setting up user access
Admin users can modify access via CSV upload (Admin > Utilities > User Access)
The User Access window displays the users currently in the system. To view a user's access, move the cursor over the user. The access is displayed in a tooltip.
To add, change, or delete users, create a CSV file and import the file into Admin Assist.
- Username: Email address of the user, click to open a modal window for editing access. See 'Edit User' section, below.
- Access: Level of access a user has, can be END_USER or ADMIN,END_USER
- END_USER: Can create configurations using ServiceNow CPQ. This is for sales users, partners, and similar roles.
- ADMIN: Can access the administrative side of ServiceNow CPQ to create and modify blueprints, fields, rules, and other items.
- Toggle Admin Access: Select one or more users using the check box. Toggle Admin Access adds or removes admin access for the selected users, depending on their current access level.
- Import: At the bottom of the user access page is an exportable sample user access file. After making the necessary modifications to the exported file, you can import it using the Import button.
Editing a user
Individual users can be edited by clicking their username in the table, which launches an Edit User window.
- Username: email address of the user being edited.
- Enable Admin Access: Toggle for controlling access to the Admin features of ServiceNow CPQ. The toggle to the right indicates that the user has Admin privileges.
- Save / Cancel: Confirm any changes made or cancel to not save.
Additional considerations
Users are created and show up on the User screen in ServiceNow CPQ the first time they access a ServiceNow CPQ instance and go through the authorization provider.
All existing users of a ServiceNow CPQ instance have END_USER and ADMIN access. Admin access can be removed from users that do not require it.
Newly created users have END_USER permissions only. The access level can be changed by an administrator following the above steps.
Troubleshooting
- Once granted access, new users may need to do one or more of the following:
- Restart the browser
- Clear the browser cache
- Remove ServiceNow CPQ session cookies before accessing ServiceNow CPQ Admin
- If users experience login issues after a CSV import, verify that the user names in the CSV match the case used in the user records. If ServiceNow CPQ is integrated with Salesforce, user names should be all lowercase to align with system requirements, as Salesforce does not allow user names to be uppercase.
If necessary, edit the CSV so that user names are in lowercase, and import the user again.