---
sourceDocument: Australia Enable AI
sourceDocumentLink: https://www.servicenow.com/docs/r/intelligent-experiences

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Enable AI

ft:clusterId :

    - platai

bundleId :

    - platai

workflow :

    - Platform


---

# Security \& privacy tab in AI Control Tower

# Security \& privacy tab in AI Control Tower {#ariaid-title1}

Release version: Australia  
Updated March 12, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 8 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Security \& privacy tab in AI Control Tower

The Security \& privacy tab in AI Control Tower provides ServiceNow customers with a comprehensive dashboard to monitor and manage the security posture of their AI assets.
It offers visual insights into access issues, dormant and privileged AI agents, and the relationships among ServiceNow agents, agentic workflows, and tools.
This tab supports proactive security management by highlighting potential risks and suggesting remediation actions.
Show full answer Show less  

## Key Features

* **Dashboard Visualizations:** Displays key AI asset security metrics such as access issues, privileged agents, dormant systems, and security task statuses.
* **Access Map:** A node-graph visualization tool that maps relationships between agents, workflows, and tools, enabling detailed investigation of access issues. Filters allow focused views of agents and workflows, with warning icons indicating access problems.
* **AI Asset Security Score:** A calculated score reflecting the overall health of AI assets based on access issues, privileged agent risks, and dormant systems. Customers can review asset details, mute assets from scoring, or adjust category weightings to tailor the score to their environment.
* **AI Asset Security Tasks:** Enables creation and tracking of remediation tasks directly from the dashboard, helping teams manage and resolve security issues efficiently. Tasks older than 180 days are archived by default, with configurable archival settings.
* **ServiceNow AI Insights:** Summarizes positive security settings, areas requiring attention, and high-risk observations along with suggested actions, requiring activation of the Now Assist AICT Security Posture Summarizer skill.
* **MCP Server Access Metrics:** Monitors client-server interactions via the instance's AI Gateway, showing top connecting clients, authorized and failed access attempts for improved security monitoring.
* **Guardrail Monitoring:** Includes analytics on prompt injection, offensive content, sensitive data exposure, data integrity incidents, agent goal deviations, PII detection in agent outputs, and agentic output injection detection. These features require enabling AI Guardian and proper configuration of data patterns to detect potential vulnerabilities.

## Practical Benefits for ServiceNow Customers

By using the Security \& privacy tab, ServiceNow customers can:

* Gain centralized visibility into the security status of all AI assets within their instance.
* Identify and quickly remediate access issues and risky AI agents, reducing security vulnerabilities.
* Understand relationships between agents and workflows to better manage permissions and dependencies.
* Monitor compliance with security guardrails to prevent data leaks, unauthorized actions, and injection attacks.
* Leverage AI-driven insights and suggested actions to continuously improve their AI security posture.
* Customize scoring and detection parameters to align with organizational risk tolerance and policies.

## Access and Configuration Notes

* Access to AI asset security tasks requires the **snvsc.taskmanager** role.
* Enabling Now Assist skills such as AICT Security Posture Summarizer and AI Guardian is necessary to unlock advanced AI insights and guardrail analytics.
* Integration with AWS metrics requires AWS account configuration and enabling related Now Assist skills.
* Security-vulnerable pattern detection is continuously evolving; customers should review and update configurations regularly to maintain optimal protection.  
Review AI asset security metrics such as access issues, dormant and privileged AI agents, and map the relationships of your ServiceNow agents, agentic workflows, and tools.

The Security \& privacy tab of AI Control Tower offers a dashboard-based overview of your AI asset security metrics. The dashboard contains several visualizations detailing AI asset security metrics. In addition to tracking metrics, the
Security \& privacy tab contains the access map, a tool that gives an node-graph visualization of the relationships between your ServiceNow agents, agentic workflows, and tools. You can use the map to investigate the relationships between your AI agents and workflows further.  
Note:  
You can drill down into the data on each widget by selecting the chart.

<br />

## ServiceNow AI Insights {#security-privacy-tab__section_nfl_yzc_lhc}

ServiceNow AI Insights require that the Now Assist AICT Security Posture Summarizer skill is enabled. For more details, see [Activate a Now Assist skill](https://www.servicenow.com/docs/_cxB8oDyWVk~yp8cPa8TMQ "Configure the triggers, settings, and display locations for AI skills to enable generative AI capabilities across the ServiceNow AI Platform.").  
AI Control Tower AI insights summarize positives and potential issues to remediate to improve the overall security posture of your instance.

* Positives: Enabled settings and features that help improve your security posture.
* Areas for Attention: Low- to medium-risk items to resolve.
* High Impact Observations: High-risk items to resolve.
* Actions: Suggested action items to address Areas for Attention and High-Impact Observations.
{#security-privacy-tab__ul_gmb_kqr_c3c}

## Access map {#security-privacy-tab__section_ay5_hnx_tfc}

The Access map displays a node map detailing the relationships of your ServiceNow® agents, agentic workflows, and tools. You can use the map to review these relationships, configure agent details, and resolve access issues. The map includes filters for both agents and agentic workflows. You can open the access map by either navigating to AllAI Security and PrivacyAccess Map, or selecting the link in the dashboard. See [Using the access map](https://www.servicenow.com/docs/OVVmQSm2ao_lXWlJmwfDQg "Learn how to use the Access map in AI Control Tower.") to learn how to use access map.  

If a warning icon appears on any agent, that agent may have access issues. Select the warning icon to see details such as the workflow, agent, and tool associated with the access issue.  
In Access issues, the User ID is the ID of the user who ran the agent.   

## AI asset security score {#security-privacy-tab__section_w3b_11d_lhc}

The AI asset security score is a measure of the health of your AI assets in terms of access issues, privileged AI agents, and dormant AI systems.  

AI assets impacting your score
:   To see more information about your score, select See details in the Security \& privacy tab. A list view shows the AI assets that are included in your AI asset security score
    calculation. Your score is the average of all managed AI assets listed. Users should actively manage and review their agent assets and not rely solely on this AI asset security score.
:   You can exclude an AI asset from your score by selecting a row and selecting Mute. For example, you can mute an AI asset if you determine that remediating the asset's issue would be a risky change. You can also configure the score to remove large language model (LLM) guardrail categories from the score or change the weights of categories. For more information, see [Data sharing, processing, and security in AI Control Tower](https://www.servicenow.com/docs/m1eaSveCOUa1tK1Cfj987w "Explore the Data sharing, processing, and Security & privacy sections.").{#security-privacy-tab__simpletable_nqz_1sl_mhc__entry__2}

    | Column | Description |
    |-|-|
    | AI system | Name of the AI asset. |
    | Category | Type of issue, such as dormant AI system, privileged AI agent, or access issue. |
    | Provider | Whether the asset is provided by ServiceNow or is external. |
    | Score impact | The percentage impact to your AI asset security score. |
    | Date | Date the issue occurred. |
    | AI Task | The AI asset security task to remediate the issue, if applicable. |
    [Table 1. AI asset details]

    {#security-privacy-tab__simpletable_nqz_1sl_mhc}

## Access {#security-privacy-tab__section_m2h_zfq_xfc}

Access issues

:   The Access issues chart displays the proportion of AI agents that may be experiencing access-related issues and lists the top AI systems with access issues. AI agents with access issues may be unable to complete their
    workflows due to the access issue. Hover over a portion of the chart to see the exact proportion and count of agents.

    <br />

    <br />

    You can create AI asset security tasks directly from the list view by selecting Create AI task. See all active AI asset security tasks in AI assets in
    the AI Task section. Access to this section requires the sn_vsc.task_manager role.

    Resolved AI asset security tasks that are over 180 days old are archived. Archival days can be configured in system properties.

Privileged AI Agents

:   The area chart shows AI agents with elevated permissions such as an agent with admin or security admin permissions that can perform critical actions. Some workflows require that AI agents have elevated permissions to
    complete. Hover over a portion of the chart to see the exact number of privileged agents on that day.

    To show AWS agent metrics, filter the metrics by selecting AWS Bedrock in the provider drop-down list. You must have an AWS account configured for your instance and the Now Assist AiSP AWS IAM Privileged Policy Checker skill enabled. For more details, see [AI connections setup](https://www.servicenow.com/docs/~fjmmytMrXwgkU9MKeeQSw "Explore the AI connections setup page and its features.") and [Activate a Now Assist skill](https://www.servicenow.com/docs/_cxB8oDyWVk~yp8cPa8TMQ "Configure the triggers, settings, and display locations for AI skills to enable generative AI capabilities across the ServiceNow AI Platform.").

    <br />

    You can create AI asset security tasks directly from the list view by selecting Create AI task. See all active AI asset security tasks in AI assets in
    the AI Task section. (Role required: sn_vsc.task_manager.)

    Resolved AI asset security tasks that are over 180 days old are archived. Archival days can be configured in system properties.

Dormant AI systems

:   The area chart shows AI agents that have not been active for over 90 days. Review dormant AI agent permissions to reduce security risk. Hover over a portion of the chart to see the exact number of dormant AI systems for that
    day.

    To show AWS agent metrics, filter the metrics by selecting AWS Bedrock in the provider drop-down list. You must have an AWS account configured for your instance. For more details, see [AI connections setup](https://www.servicenow.com/docs/~fjmmytMrXwgkU9MKeeQSw "Explore the AI connections setup page and its features.").

    <br />

    When an AI agent becomes dormant, an AI asset security task is created automatically to streamline your workflow, and quickly resolve issues. The AI asset security task is assigned to the agent's
    owner. See all active AI asset security tasks in AI assets in the AI Task section.

    Resolved AI asset security tasks that are over 180 days old are archived. Archival days can be configured in system properties.

## ServiceNow instance access to MCP servers {#security-privacy-tab__section_bvt_mwx_l3c}

MCP server access metrics include MCP client-server interactions routed through this instance's AI Gateway. Interactions that bypass the AI Gateway or are routed through another instance's AI Gateway aren't included.

Clients connecting to MCP servers
:   The Clients connecting to MCP servers chart shows the top 10 clients (ServiceNow AI agents or registered third-party MCP clients) connecting to MCP servers through this instance's AI Gateway. MCP server access metrics are captured for all client-server interactions routed through the AI Gateway. To see more clients, select the chart to drill down into the data.

Authorized access attempts to MCP servers
:   The Authorized access attempts to MCP servers chart shows successful access attempts from MCP clients to MCP servers through this instance's AI Gateway. Clients include ServiceNow AI agents and registered third-party MCP clients. To see more attempts, select the chart to drill down into the data.

Failed access attempts to MCP servers
:   The Failed access attempts to MCP servers chart shows unsuccessful access attempts from MCP clients to MCP servers through this instance's AI Gateway. Clients include ServiceNow AI agents and registered third-party MCP clients. To see more data, select the chart to drill down into the data.

## Guardrails

Prompt injection
:   These charts show prompt injection data provided by AI Guardian. To see data, enable AI Guardian for your instance. For more details, see [AI Guardian analytics](https://www.servicenow.com/docs/L3eS4MWnqpHXmbe3__2dtA "Monitor the performance of guardrails enabled through AI Guardian.").

Offensive content
:   These charts show offensive content data provided by AI Guardian. To see data, enable AI Guardian for your instance. For more details, see [AI Guardian analytics](https://www.servicenow.com/docs/L3eS4MWnqpHXmbe3__2dtA "Monitor the performance of guardrails enabled through AI Guardian.").

Sensitive data

:   The Sensitive data detected chart shows sensitive data that was identified in user responses to Now Assist prompts. Exposure of sensitive data is limited to the LLM in your instance.

    The Sensitive data anonymized chart shows prompt data that met configured data patterns. This data was anonymized based on the configuration for the pattern in Configuration Data Patterns in Data
    Privacy.

Data integrity incident detection
:   The Data integrity incident detection chart is designed to help show potential violations of certain LLM guardrail policies. ServiceNow analyzes the AI agent's output from each of its tasks deterministically to detect potential violations. You can choose to include or omit these policies. For more information about policies and
    how to configure data for this chart, see [Data sharing, processing, and security in AI Control Tower](https://www.servicenow.com/docs/m1eaSveCOUa1tK1Cfj987w "Explore the Data sharing, processing, and Security & privacy sections.").

Agent goal deviation
:   The Agent goal deviation chart is designed to help identify when AI agents may have deviated from their intended role or objective during execution. Deviations include but aren't limited to unauthorized actions or prompt
    injection attempts. The data is collected by analyzing agent execution history and then evaluated by AI. You can choose the data models to include or omit. Due to the probabilistic nature of the analysis by data model, not all
    occurrences may be identified. For information on how to configure data for this chart, see [Data sharing, processing, and security in AI Control Tower](https://www.servicenow.com/docs/m1eaSveCOUa1tK1Cfj987w "Explore the Data sharing, processing, and Security & privacy sections.").

AI agent output with PII detected
:   The AI agent output with PII detected chart shows when agents' LLM output potentially contains personally identifiable information (PII). The data is collected by analyzing LLM output for PII sensitive data patterns specified
    in Data Privacy and additional PII patterns. These are the default Data Privacy sensitive data patterns: credit card, date of birth, email, Social Security number, U.S. bank ABA routing number, and U.S. phone number.

    ServiceNow analyzes the AI agent's output from each of its tasks deterministically based on the widely known patterns listed to find out potential security vulnerabilities. For example, U.S. phone
    number, credit card number, or Social Security number.
    You can choose to include or omit potential PII patterns to detect. For information on how to configure data for this chart, see [Data sharing, processing, and security in AI Control Tower](https://www.servicenow.com/docs/m1eaSveCOUa1tK1Cfj987w "Explore the Data sharing, processing, and Security & privacy sections.").

Agentic output injection detection

:   The Agentic output injection detection chart shows when agents' LLM output potentially contains known security-vulnerable patterns. These patterns are Eval-Function-Audit, Html-Tag-injection, Non-printable-class, Script-Tag-injection, SQL-query-injection, and Terminal-RCE from the sn_data_discovery_data_pattern table in the AI Security and Privacy application.ServiceNow analyzes the AI agent's output from each of its tasks deterministically based on the patterns listed to find out potential security vulnerabilities. For example, HTML tags shouldn't have
    scripts associated with them for cross-site script attacks (XSS), or stacked SQL queries could result in SQL injection attacks.

    You can choose to include or omit potential patterns to detect. For information on how to configure data for this chart, see [Data sharing, processing, and security in AI Control Tower](https://www.servicenow.com/docs/m1eaSveCOUa1tK1Cfj987w "Explore the Data sharing, processing, and Security & privacy sections.").  
    Note:  
    These security-vulnerable patterns are ever-evolving, so not all patterns may be identified.

*[\>]: and then


