Configuring access control

  • Release version: Australia
  • Updated November 27, 2025
  • 2 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Configuring access control

    This guide details how to configure entity-based access control (EBA) in ServiceNow Privacy Management, allowing organizations to restrict user access to processing activity records based on their position within an organizational hierarchy. Implementing EBA enhances data privacy, supports regulatory compliance, and ensures that privacy teams and users only access relevant records tied to their assigned entities.

    Show full answer Show less

    Key Features

    • Entity-Based Access Activation: Install the Entity-based Access plugin and enable the related property to activate entity-level access control features.
    • Organizational Hierarchy Setup: Define parent-child relationships between entities (e.g., global, regional, country levels) to establish a clear structure for access control.
    • Record Mapping: Map existing processing activity records to their appropriate entities in the hierarchy to ensure precise access restrictions.
    • Entity Configuration: Assign access permissions to individual users or groups based on their entity roles, specifying whether access extends to downstream entities.
    • Bulk Access Updates: Transition from role-based to entity-based access across records using a bulk update utility that validates and applies restrictions efficiently.
    • Entity-Based Record Access Rules: Enable continuous enforcement of access restrictions on new or modified records, with automatic updates reflecting changes in organizational structure or processing activities.

    Key Outcomes

    • Granular and Hierarchical Access Control: Access restrictions align with organizational structure, improving data security and privacy governance.
    • Efficient Management: Bulk update utility and automated record access rules reduce manual efforts and ensure consistent enforcement of access controls.
    • Regulatory Compliance Support: Restricting access to entities’ relevant data helps meet privacy regulations by limiting unnecessary data exposure.
    • Dynamic Adaptation: The system automatically adjusts access controls when entities or processing activities change, maintaining up-to-date security postures.

    Configurie Entity-based access control in Privacy Management, including property activation, hierarchy setup, record mapping, user assignment, bulk updates, and activating entity-based record access rules.

    The following steps outline how to configure access control in Privacy Management using Entity-based access (EBA). This process enables organizations to restrict user access to processing activity records and related data according to their position in the organizational hierarchy. By following these steps, administrators can ensure that privacy teams and users only access records relevant to their assigned entities, supporting both security and regulatory compliance.