---
sourceDocument: Brazil Build or modify applications
sourceDocumentLink: https://www.servicenow.com/docs/r/application-development

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil Build or modify applications

ft:clusterId :

    - cadev

bundleId :

    - cadev

workflow :

    - Development, Data, and Analytics


---

# Restricted caller access privilege settings

# Restricted caller access privilege settings {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Restricted caller access privilege settings

Restricted caller access privilege settings in ServiceNow allow you to define and control cross-scope access to applications, application resources (such as roles, business rules, UI actions, script includes), or events within the ServiceNow AI Platform.
These settings help track and manage requests from one application scope to access resources in another scope, ensuring secure and controlled interactions between different application components.
Show full answer Show less  

## Key Features

* **Tracking cross-scope access requests:** The system automatically creates `sysrestrictedcalleraccess` records when cross-scope access is attempted or when caller access is set to Caller Restriction or Caller Tracking.
* **Privilege setting combinations:** You can configure access at different levels, including:
  * Scope-to-scope: All resources in a source application to all resources in a target application.
  * Scope-to-target: All resources in a source application to a specific target resource.
  * Source-to-scope: A specific source resource to all target application resources.
  * Source-to-target: A specific source resource to a specific target resource.
* **Approval management:** Target application owners can approve or deny cross-scope access requests, enabling precise control over who can access application resources or events.
* **Packaging requested access:** Source application developers can package requested restricted caller access (RCA) records with their applications for target administrators to review and approve during installation.
* **Activation methods:** Restricted caller access can be activated by enabling the Scoped Application Restricted Caller Access plugin, requesting specific applications like HR Service Delivery or Security Incident Response where it is enabled by default, or by enabling a system property for Workflow Studio.

## What This Enables ServiceNow Customers to Do

By using restricted caller access privilege settings, ServiceNow customers can securely manage and monitor cross-scope interactions between applications. This ensures that sensitive application resources are only accessible with explicit permission, reducing security risks and maintaining clear governance of resource access across different application scopes.

## Practical Steps

* Activate the required plugin or system property to enable restricted caller access.
* As a target application owner, create `sysrestrictedcalleraccess` records in your application scope to define allowed or denied access relationships.
* Coordinate with source application developers who need access to your resources to review and approve their access requests.
* Use the system-generated records to track and audit cross-scope access attempts.  
Define cross-scope access to an application, application resource (such as an access
control role, a business rule, a UI action, or a script include), or event. You can even use
these settings to allow or deny requests for access.

## Restricted caller access privilege settings overview {#restricted-caller-access-privilege__section_mrt_shj_gqb}

Restricted caller access \[sys_restricted_caller_access\] records track cross-scope applications or scripts that request access to an application, application resource, or event in the ServiceNow AI Platform. The ServiceNow AI Platform creates sys_restricted_caller_access records when one of these actions occurs:  
* Caller access is set to Caller Restriction or Caller Tracking.
* A cross-scope script attempts to access an application resource or event.  
  Note:  
  A system scope to target scope is an example of a cross-scope.
{#restricted-caller-access-privilege__kdein_jeifin}

You can use these records to do these tasks:

* Track cross-scope requests for access to an application resource. You can use access requests to determine which applications need access to resources and data from other application scopes.
* Approve or deny any cross-scope requests for access to application resources or events. For example, you can create a Restricted Caller Access record to allow access for all scope-to-scope requests.

{#restricted-caller-access-privilege__ul_pym_f3y_f2b}

For more information, see [Requested restricted caller access (RCA)](https://www.servicenow.com/docs/Im7jq9KGar1xWNSW7UOhEg "You can use a requested RCA to grant store apps access to protected resources in the ServiceNow AI Platform without the need to wait for the next family release. If you have the system admin or application admin role, you can review requested RCAs and approve and deny them.").

## Restricted caller access privilege setting combinations {#restricted-caller-access-privilege__section_ubv_s5v_g2b}

As a target application owner, you can define various combinations of privilege settings for restricted caller access and specify whether access is allowed or denied for each relationship. RCA records must be created in the target
application scope to control access to your application's resources. You can define various combinations of privilege settings for restricted caller access and specify whether access is allowed or restricted for each
relationship.  
You can define various combinations of the following settings:

Scope
:   All application resources in a selected source or target scope. To learn more about application scopes, see [Application scope](https://www.servicenow.com/docs/mfpDASazxpd1W0MbyVFDYQ "Application scoping protects applications by identifying and restricting access to application files and data.").

Source
:   A specific application resource (such as a business rule, script include, or table) in a selected source scope.

Target
: A specific application resource in a selected target scope.  
These restricted caller access privilege settings combinations include, but are not limited to, the following combinations:

* Scope-to-scope: Control access from all resources in a source application to all resources in your target application
* Scope-to-target: Control access from all resources in a source application to a specific resource in your target application
* Source-to-scope: Control access from a specific source application resource to all resources in your target application
* Source-to-target: Control access from a specific source application resource to a specific resource in your target application
{#restricted-caller-access-privilege__ul_zcx_jxc_qfb}

For more information about these access setting combinations and to learn how to create each combination, see [Set the application scope, application resource, and event access](https://www.servicenow.com/docs/D0JJxFwHNaNNDyvTfzvfjQ "Create a record in the Restricted Caller Access Privileges [sys_restricted_caller_access] table to set cross-scope resource access requests. Approve or deny requests from a source scope or source scope application resources to a target scope or to target scope application resources.").  
Note:  
Source application developers who need to request access to resources in another application should coordinate with the target application owner. You can package Requested RCA records in your application, which will then be
reviewed and approved or denied by the target application administrator upon installation.

## Activating application restricted caller access {#restricted-caller-access-privilege__section_crw_swq_4bb}

You can activate application restricted caller access through one of the following
methods:  
* Activate the Scoped Application Restricted Caller Access plugin (com.glide.scope.access.restricted_caller).
* Request the HR Service Delivery or Security Incident Response applications. By default, restricted caller access is active in these applications.
* Enable the Restricted Caller Access system property for Workflow Studio.
{#restricted-caller-access-privilege__ul_prl_vwq_4bb}

For more information, see: [Activate application restricted caller access](https://www.servicenow.com/docs/ACJma~lat1KPaL6Ln8fKrg "You can activate the Scoped Application Restricted Caller Access plugin (com.glide.scope.access.restricted_caller) if you have the admin role.").
* **[Activate application restricted caller access](https://www.servicenow.com/docs/ACJma~lat1KPaL6Ln8fKrg)**   
  You can activate the Scoped Application Restricted Caller Access plugin (com.glide.scope.access.restricted_caller) if you have the admin role.
* **[Define cross-scope access to an application resource](https://www.servicenow.com/docs/_MqP7lEQ7uwyjivk0X3Eqg)**   
  Track cross-scope requests for access to an application resource and approve or deny requests.
* **[Set the application scope, application resource, and event access](https://www.servicenow.com/docs/D0JJxFwHNaNNDyvTfzvfjQ)**   
  Create a record in the Restricted Caller Access Privileges \[sys_restricted_caller_access\] table to set cross-scope resource access requests. Approve or deny requests from a source scope or source scope application resources to a target scope or to target scope application resources.

