---
sourceDocument: Brazil Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/governance-risk-compliance

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Pre-requisites to enable policy redlining feature

# Pre-requisites to enable policy redlining feature {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 5 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Pre-requisites to Enable Policy Redlining Feature

The policy redlining feature in the Compliance Workspace allows policy collaborators to create, update, and manage policy documents with integrated editing capabilities.
This feature is exclusively available to ServiceNow cloud-based customers and requires specific configurations to connect with cloud hosting services such as Microsoft OneDrive, Microsoft SharePoint, or Google Drive.
Only one cloud hosting service connection can be active at a time.
Show full answer Show less  

## Key Configurations

* **Cloud Hosting Service Connections:**
  * **Microsoft OneDrive and SharePoint:** Requires setting up Microsoft OneDrive and SharePoint integration using delegated Microsoft Azure App permissions including openid, profile, Files.ReadWrite, offlineaccess, User.Read, and additional SharePoint-specific permissions (Sites.Read.All, Sites.ReadWrite.All) to enable secure authentication, file access, and site content management.
  * **Google Drive:** Requires setting up the Google Drive spoke account and integrating Document Services Framework for Google Drive. Additionally, Google Docs integration is necessary for document management within ServiceNow.
* **Spokes and Integration Hub:** Specific spokes with minimum versions are required depending on the chosen cloud service. Note that Integration Hub entitlements included in Compliance Workspace cover integrations with O365 and Google Drive, but using Microsoft or Google integration requires additional Automation Engine or Integration Hub entitlements.
* **System Properties:** Administrators must configure system properties under GRC properties to select the file sharing service (OneDrive, SharePoint, Google Drive, or None). The default folder path for storing documents must also be set.
* **Roles:** The `mpdocumentuser` role is mandatory for users to access and manage policy redlining document tables. The `sncompliance.user` role is also required. Administrators are responsible for assigning these roles and establishing cloud connections.

## Practical Benefits for ServiceNow Customers

* Enables seamless policy document collaboration and redlining within Compliance Workspace integrated with your preferred cloud document storage.
* Ensures secure, authenticated access to documents and sites through delegated permissions and Azure or Google integrations.
* Provides centralized control by administrators to configure system properties, manage roles, and maintain cloud hosting connections.
* Supports efficient document versioning and updates by leveraging Microsoft or Google Drive capabilities directly from ServiceNow.  
Certain configurations are required to be set up for policy collaborators to use the policy redlining feature in the Compliance Workspace.  
Important:  
Currently, the policy authoring and redlining feature is available exclusively to ServiceNow cloud-based customers.

## Spoke support for cloud hosting services {#pre-req-policy-redlining__section_z5m_rcz_zcc}

Spokes required for Policy authoring -- integration with Microsoft Office 365
:
    * Microsoft OneDrive Spoke -- 2.1.1
    * Microsoft OneDrive Spoke for Document Service Framework -- 1.0.5
    {#pre-req-policy-redlining__ul_h1g_yfv_hcc}

Spokes required for Policy authoring -- integration with Microsoft SharePoint
:
    * Microsoft OneDrive spoke 2.3.1
    * Document services framework for OneDrive -- 2.0.0
    {#pre-req-policy-redlining__ul_x3q_yfv_hcc}

Spokes required for Policy authoring -- integration with Google Drive
:
    * Document Service Framework for Google Drive Spoke -- 1.0.1
    * Google Drive Spoke -- 1.4.1
{#pre-req-policy-redlining__ul_xcj_lgc_f1c}  
Note:  
Integration Hub entitlements included in the Compliance Workspace are for Policy authoring -- integration with O365 and integration with Google Drive. Using Microsoft integration or Google Drive integration requires Integration Hub transactions not included in the Compliance Workspace product but requires an Automation Engine or Integration Hub entitlement.

## Connecting to cloud hosting services {#pre-req-policy-redlining__section_dbx_2cz_zcc}

If you're a policy collaborator wanting to use the policy redlining feature in the Compliance Workspace, then you must set up the following configurations.  
Note:  
You can establish a connection with only one of the following cloud hosting services: either Microsoft or Google Drive.

Microsoft implies both Microsoft OneDrive and Microsoft SharePoint.

Establish a connection with cloud hosting services
:

    Connection with Microsoft OneDrive
    :   You must first set up the Microsoft OneDrive to perform actions in Microsoft OneDrive from ServiceNow. For more information, see [Setup Microsoft OneDrive for Document Services](https://www.servicenow.com/docs/access?context=configure-ms-onedrive-doc-services&version=brazil&pubname=brazil-servicenow-platform&ft:locale=en-US).  
        Note:  
        To set up connection you require the following delegated Microsoft Azure App permissions:

        * openid: Enables secure user authentication through Microsoft's identity platform, ensuring that access to the Policy Redlining application is verified and trusted.
        * profile: Provides access to the basic profile information of the user, such as their name. This information is used to personalize the redlining experience and display relevant user details within the interface.
        * Files.ReadWrite: Allows the application to create, read, and update any files the user has permission to access. This is essential for opening, modifying, and saving policy documents during the redlining process on behalf of the authenticated user.
        * offline_access: Grants the ability to refresh access tokens even when the user is not actively logged in. This ensures continuous access to Microsoft resources without requiring frequent re-authentication.
        * User.Read: Allows the application to retrieve the signed-in user's basic profile details. This is required for assigning or validating file permissions specific to that user during redlining activities.
        {#pre-req-policy-redlining__ul_eqk_gwz_m3c}

    Connection with Microsoft SharePoint
    :   You must first set up the Microsoft SharePoint to perform actions in Microsoft SharePoint site from ServiceNow. For more information, see [Setup Microsoft OneDrive for Document Services](https://www.servicenow.com/docs/access?context=configure-ms-onedrive-doc-services&version=brazil&pubname=brazil-servicenow-platform&ft:locale=en-US).

        The Microsoft OneDrive setup configured in ServiceNow is the same as that is done for Microsoft SharePoint as well. However, the Microsoft Azure App permissions are required for Microsoft SharePoint.  
        Note:  
        To set up connection, you require the following delegated Microsoft Azure App permissions:

        * openid: Enables secure user authentication through Microsoft's identity platform, ensuring that access to the Policy Redlining application is verified and trusted.
        * profile: Provides access to the user's basic profile information (such as their name). This information is used to personalize the redlining experience and display relevant user details within the interface.
        * Files.ReadWrite: Allows the application to create, read, and update any files the user has permission to access. This is essential for opening, modifying, and saving policy documents during the redlining process on behalf of the authenticated user.
        * offline_access: Grants the ability to refresh access tokens even when the user is not actively logged in. This ensures continuous access to Microsoft resources without requiring frequent re-authentication.
        * User.Read: Allows the application to retrieve the signed-in user's basic profile details. This is required for assigning or validating file permissions specific to that user during redlining activities.
        * Sites.Read.All: Allows the application to read content across SharePoint sites. This is needed to verify that the user has permission to access the document located in the specified SharePoint site URL, Validate if user has provided a valid site url, validate if user has access to the site they are accessing.
        * Sites.ReadWrite.All: Allows the application to read and write content across SharePoint sites. This is needed to create and update files in SharePoint document libraries. This is needed to verify that the user has permission to access the document located in the specified SharePoint site URL, Validate if user has provided a valid site url, validate if user has access to the site they are accessing.
        {#pre-req-policy-redlining__ul_jkn_5wz_m3c}

    Connection with Google Drive
    :   To set up Google Drive as a cloud hosting service and to create or update the policy text document that resides in Google Drive, you must:

        1. [Set up Google Drive spoke](https://www.servicenow.com/docs/access?context=setup-gdrive&version=brazil&pubname=brazil-integrate-applications&ft:locale=en-US) account.
        2. Integrate the Document Services with Google Drive. For more information, see [Document Services Framework for Google Drive](https://www.servicenow.com/docs/access?context=google-drive-spoke-document-services&version=brazil&pubname=brazil-servicenow-platform&ft:locale=en-US).
        3. To manage documents in Google Docs from your ServiceNow instance, you must integrate the ServiceNow instance with Google docs. For more information, see [Set up the Google Docs](https://www.servicenow.com/docs/access?context=setup-gdocs&version=brazil&pubname=brazil-integrate-applications&ft:locale=en-US).
        {#pre-req-policy-redlining__ul_t5h_b11_dzb}

## Setting up system properties to connect with cloud hosting services {#pre-req-policy-redlining__section_eys_1cz_zcc}

Enable system properties to use policy redlining in Compliance Workspace{#pre-req-policy-redlining__sys-properties-redlining}
:
    1. Navigate to AllPolicy and ComplianceAdministrationGRC properties.
       1. To opt Microsoft OneDrive as your cloud hosting service, select One drive in the Select a file sharing service to host documents and attachments system property list.

          If you select None in the Select a file sharing service to host documents and attachments system property list, then you can import the policy text.
          For more information, see [Import policy text for redlining](https://www.servicenow.com/docs/jsrP23qwilUcP7hzFDWn~Q "Import the policy text as an attachment if you’re unable to do the word editing.").
       2. To opt Google Drive as your cloud hosting service, select Google drive in the Select a file sharing service to host documents and attachments system property list.
       3. To opt Microsoft SharePoint, select SharePoint in the Select a file sharing service to host documents and attachments system property list.
       {#pre-req-policy-redlining__ol_nqv_bcz_zcc}
    2. Set the folder path that is to be created in Microsoft OneDrive in the Default folder path where documents and attachments will be located. You can organize files in sub-folders within this path system property list.
    {#pre-req-policy-redlining__ol_wkn_jtm_wsb}

Provide mp_document_user role
:   The mp_document_user role is required to access policy redlining document-related tables. This role is required for users using the policy redlining feature to create, update, and delete the related documents.

As a sys admin you can establish the cloud hosting connection, enable system properties, and provide the mp_document_user role and compliance user (sn_compliance.user) role for the policy redlining users.

*[\>]: and then


