---
sourceDocument: Brazil Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/governance-risk-compliance

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Entity Based Access

# Entity Based Access {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Entity Based Access

The Entity Based Access (EBA) application in ServiceNow enables administrators to enforce granular data segregation based on entities.
Unlike previous role-only restrictions, EBA allows access control linked to specific entities such as geographical regions or organizational units.
This helps ensure users only access data relevant to their assigned entities, reducing unnecessary data exposure.
Administrators can assign user or user group access tied directly to entities, enhancing security and compliance.
Show full answer Show less  

## Key Features

* **Granular Access Control:** Configure access to records based on entities, entity classes, or entity types, including hierarchical entity relationships.
* **Flexible Configuration:** Supports bulk updates for access restrictions, enabling gradual implementation without disrupting operations.
* **Dynamic User Access:** Access can be granted through entity user fields or user group fields, automatically adjusting as users or groups change.
* **Automated Access Rules:** Entity-based record access rules enforce restrictions automatically on new or updated records, eliminating manual updates.
* **Utility for Bulk Updates:** A guided utility simplifies enabling or disabling access restrictions across large record sets.
* **Deactivation Workflow:** Deactivating an EBA configuration disables restrictions and automates record-level access evaluation for easier administration.

## Important Considerations

* EBA cannot be used simultaneously if User Hierarchy Access or User Group Access is enabled.
* Confidential users retain access to confidential records regardless of EBA configurations.
* Performance and custom table usage considerations are documented in specific knowledge base articles.

## Practical Application for ServiceNow Customers

ServiceNow customers can leverage EBA to tightly control access to sensitive records such as risks, controls, and issues based on entity assignments. This is particularly useful for organizations with geographically distributed teams or segmented business units requiring data isolation. By configuring EBA, administrators gain precise control over who can view or modify records, enhancing security posture and compliance with data governance policies.

## Getting Started

To use Entity Based Access, install the application from the ServiceNow Store and configure entity properties in your instance. Manage access restrictions via the app by assigning users or groups to entities, and apply rules to automate ongoing access management.  
The Entity Based Access (EBA) application enables you to segregate data on the records that are based on entities. Entity-based access administrators can use this tool to set up secure, controlled access to various
objects.

## Entity Based Access overview {#entity-based-access__section_kln_mmw_jfc}

Before the Yokohama release, user restrictions were based only on their roles within the system without consideration for their geographical locations or specific functions. Access to objects like risks, controls,
and issues was broadly managed. For example, a risk manager in North America had access to risk records across all regions, not just their own.

From the Yokohama release onwards, Entity Based Access facilitates object access via entities. You can map entities to specific users or user groups, enabling you with a granular level of access control.

With Entity Based Access, you can segregate data and manage access to help ensure that users can only access permitted data through entity-based access. Your administrators can grant access to an entity's
related records. They can add users or user groups for access. Access can also be granted through entity user fields or entity user group fields, minimizing the risk of unnecessary data exposure.

To use the Entity Based Access configuration, navigate to Entity Based Access Configurations in an instance.

## Key features of Entity Based Access {#entity-based-access__section_t14_hw3_qbc}

Key features of the Entity Based Access configuration include:

* Detailed control over access to various objects via entities within the system.
* Versatile configuration options. For example, you can configure Entity Based Access within an entity hierarchy to restrict access to the entity and its downstream related records or across a group of entities by using an entity class or entity type. With bulk access update configurations, you can apply access restrictions selectively to scoped records. You can implement access restrictions gradually to help ensure smooth adoption without operational disruptions.
* Access that is provided by including specific user field or user group fields in the entity-based access configuration. Users who are part of the configuration get dynamic access to the records.
{#entity-based-access__ul_d5l_tmn_bcc}

## Key points to note about Entity Based Access {#entity-based-access__section_qdh_jts_z2c}

Entity Based Access restricts access to records to users based on the configuration as shown in the following diagram:  
Figure 1. Entity-based access security flow  
The details about the entity-based access security flow are:

* If User Hierarchy Access or User Group Access is enabled, you can't use Entity Based Access.
* Confidential users can continue to access the confidential records whether they're or not part of the entity-based access configuration.
{#entity-based-access__ul_sjs_mts_z2c}  
Important:  
* For information about the performance limitations, see [KB2069935](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB2069935).
* For information on how to use Entity Based Access on custom tables, see the steps in [KB1646304](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1646304).
* For information about the limitations of Entity Based Access, see [https://support.servicenow.com/kb?id=kb_article_view\&sysparm_article=KB2054513](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB2054513).
{#entity-based-access__ul_cn3_3z1_cfc}
* **[Sample use case scenarios](https://www.servicenow.com/docs/BnoBFfScJT~KhWnsx74OAQ)**   
  Use case scenarios offer a clear and comprehensive explanation of why you would use the Entity Based Access application.
* **[User roles for Entity Based Access](https://www.servicenow.com/docs/swETpP4VhnRzoZjq1nKZbg)**   
  Users with specific user roles have access to read or update the Entity Based Access configuration or the bulk access update configuration.
* **[Entity based record access update utility](https://www.servicenow.com/docs/zsxW0pay1wokY8R1uWPw5g)**   
  The entity based record access update utility is a guided assistance, designed to simplify the application of enabling or disabling access restrictions across large volumes of records.
* **[Entity-based record access rules](https://www.servicenow.com/docs/B2HPGV3ucwtB~GhAsxMWAw)**   
  The entity-based record access rules let admins apply restrictions automatically to new and changed records. This configuration ensures that access settings stay enforced. No manual updates are needed when records are created, modified, or when users are added to user fields or user group fields.
* **[Deactivating entity-based access configuration](https://www.servicenow.com/docs/fkbgaQDRGqDu~W9uX0VeQg)**   
  Deactivating entity-based access (EBA) not only disables the configuration but also streamlines admin workflows by automating record-level access evaluation.
* **[Configuring Entity Based Access](https://www.servicenow.com/docs/f~Mum98jyqkbDDYdBqwJ_w)**   
  Configure the Entity Based Access application by installing it from the ServiceNow Store and by setting up Entity Based Access properties in the instance.
* **[Managing Entity Based Access](https://www.servicenow.com/docs/xh~LaBvBpMKqTsB3reP5Zg)**   
  You can manage access to the objects or record types in a system by using the Entity Based Access application. You can restrict access by using an entity, entity class, or entity type configuration.
* **[Entity Based Access reference](https://www.servicenow.com/docs/Nav4zOfMxTOkDyIIw9dsDg)**   
  Entity-based access restriction can be applied on some GRC tables.

