Exploring Cloud Account Management
The ServiceNow Cloud Account Management in Cloud Workspace application provides a framework to streamline the cloud account creation and management process.
Cloud Account Management overview
The automation capabilities of Cloud Account Management in Cloud Workspace simplify administrative tasks related to account management, such as creation, suspension, reactivation, and certification. Data certification confirms the integrity and security of user accounts within the organization's cloud environment.
As a Cloud Account Management admin, you can view the account statistics displayed on the Home tab, which include critical severity accounts, high severity accounts, suspended accounts, accounts due for certification, and accounts with undefined budgets.
About Cloud Workspace entitlements
- Cloud Account Management entitlement becomes available with the ITOM Cloud Accelerate license.
- The Cloud Governance Suite (CGS) license is a prerequisite to have Cloud Workspace. The CGS license provides the following capabilities:
- Access the home page
- Access the asset explorer, which provides an overview of your cloud assets and asset details
- The Cloud Governance Suite with the Cloud Account Management entitlements (CGS + CAM) provides the following additional capabilities:
- View an overview of your accounts and account details
- Submit, view, or approve account requests
- Certify an account
- View the compliance dashboard
- Configure Cloud Account Management or view configuration details
- Create request policies to automate the complete account creation and suspension process
Compliance dashboard in Cloud Workspace
The compliance dashboard consolidates data from ITOM Visibility, Cloud Account Management to provide a unified view of cloud data and key metrics critical for security and compliance reporting.
For more details, see Viewing the compliance dashboard.
Cloud account terminology
- Microsoft Azure Cloud (Azure) refers to subscriptions
- Amazon AWS Cloud (AWS) refers to management and member accounts
- Google Cloud Platform (GCP) refers to projects
- Console user access
- Programmatic user access
- AWS refers to the IAM user
- Azure refers to service principals
- GCP refers to service accounts
Cloud Account Management user personas
| User | Description |
|---|---|
| Requester | Initiates cloud account creation requests and requests for suspension or reactivation of their own accounts. |
| Approver | Reviews account requests and either approves or denies them. |
| Admin | Confirms that the Cloud Account Management configurations align with cloud configurations. Customizes the default data certification policy. Onboards accounts created outside the Cloud Account Management application. |
| Certifier | Approves an account as certified or failed. Acts as a verification entity by confirming the accuracy and integrity of the data. |
| Asset viewer | Can view all the configuration items (CIs) in Asset Explorer and access the compliance dashboard. |
| Account manager | Can view all account details and associated assets. Account managers have edit access to accounts with primary ownership and read-only access to those with secondary ownership. |
For more information about Cloud Account Management groups and responsibilities, see Cloud Account Management ACL groups, roles, and responsibilities.
Cloud Account Management Benefits
The Cloud Account Management provides several benefits.
| Benefit | Feature | Users |
|---|---|---|
| Simplifies subscription account creation by defining standardized procedures and user roles and permissions to promote consistency and compliance with security policies. | Requester | |
|
Enables suspending or reactivating accounts, and adding unmanaged accounts. Offers a visualization dashboard to manage accounts and request policies to automate account creation, approvals, and budget checks. |
Add an unmanaged cloud account |
Admin |
| Streamlines performing verifications that a person or entity has legitimate ownership or control over an account for security, compliance, and regulatory purposes. | Certifier |