---
sourceDocument: Australia Enable AI
sourceDocumentLink: https://www.servicenow.com/docs/r/intelligent-experiences

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Enable AI

ft:clusterId :

    - platai

bundleId :

    - platai

workflow :

    - Platform


---

# Deny-by-default ACL configuration

# Deny-by-default ACL configuration {#ariaid-title1}

Release version: Australia  
Updated May 26, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Deny-by-default ACL configuration

The ServiceNow AI Platform enforces a deny-by-default Access Control List (ACL) configuration for AI agentic types on freshly reset instances.
This means that AI agents and agentic workflows must have explicit ACLs configured to prevent unauthorized access.
Without explicit ACL entries, access to these AI components is denied by default, enhancing security and aligning with secure-by-default best practices.
Show full answer Show less  

## Key Features

* **ACL Types and Behavior:** AI agentic ACLs in AI Agent Studio are role-based and primarily use the "Allow If" type, which grants access if any specified conditions are met. The platform also supports "Deny Unless" ACLs that strictly require all conditions to be met and cannot be overridden.
* **ACL Configuration Options:** ACLs for AI agents and workflows can be configured for "Any authenticated user," "Users with specified roles" (default), or "Public" access. Each AI agent and agentic workflow requires a unique ACL.
* **New ACL Types:** Five new ACL types pertain to agentic components: genaiagent, genaiworkflow, genaiskill, Flow, and flowaction. These default to allow access but are enforced with deny-by-default on freshly reset instances.
* **Security Notifications:** The AI Agent Studio interface provides warnings when AI agents or workflows lack explicit ACLs, helping users identify and resolve missing security configurations.
* **Legacy Wildcard ACLs:** Older wildcard ACLs allow continued operation on existing instances but are superseded by deny-by-default on freshly reset instances to improve security.

## Key Outcomes

* **Enhanced Security:** Enforcing deny-by-default ACLs reduces risks of unauthorized access caused by permissive wildcard ACLs and prevents inadvertent exposure of records without explicit ACLs.
* **Clear Access Control:** The requirement for explicit ACL entries creates a transparent and auditable security model for AI agents and workflows.
* **Consistent Security Model:** This configuration ensures that AI components comply with secure-by-default principles, providing customers with a robust foundation to manage AI agent access.

## Practical Considerations for ServiceNow Customers

* When deploying AI agents or agentic workflows, always configure explicit ACLs in AI Agent Studio following the guided setup processes to avoid access denials.
* Review existing ACLs on freshly reset instances to replace any wildcard ACLs with specific role-based ACLs.
* Monitor AI Agent Studio notifications to promptly identify missing ACLs and maintain secure operation.
* Understand that deny-by-default enforcement applies only to freshly reset instances; existing instances retain legacy ACL behaviors unless manually updated.  
The ServiceNow AI Platform enforces a deny-by-default ACL (Access Control Lists) configuration for AI agentic types on freshly reset instances, for any AI agents and agentic workflows that don't have an individual ACL configured to
reduce unauthorized access risks.

## Configure ACLs in AI Agent Studio {#aia-acl-configuration__section_fkx_whb_hgc}

ACLs configured in the AI Agent Studio for AI agents and agentic workflows are role-based and of the Allow If type:

* Allow-If: Grants access to data or resources when any of the specified conditions in the ACL are met. Allow If ACLs don't prevent other ACLs from granting access to the same resource even if it that specific ACL itself doesn't grant access.
* Deny-Unless: Grants access only when the invoking user identity meets all the specified conditions. No other ACLs can override or grant access to that resource once a Deny Unless ACL is in place. This is available when configuring ACLS in the ACL \[sys_security_acl\] table and not in the AI Agent Studio.
{#aia-acl-configuration__ul_is3_ydh_xgc}

There are three possible options for ACLs created in AI Agent Studio:

* Any authenticated user: Grants access to any user who is authenticated on the instance, regardless of the role.
* Users with specified roles: The default ACL option that requires you to select the specific roles required to invoke an AI agent or an agentic workflow. If you select this option, you will be able to add roles.  
  Note:  
  As the ACLs are Allow If ACLs, any user with at least one of the roles will be able to define specific roles that the users must have to discover and interact with this AI agent.
* Public: Grants access to all users, including guests who aren't signed in.

{#aia-acl-configuration__ul_qdz_hrg_njc}  
Each AI agent and agentic workflow must have its own unique ACL.

* To configure an ACL in the AI Agent Studio for an AI agent, see the [Define security controls for an AI agent](https://www.servicenow.com/docs/SGciUCFmTP77qs2F6Qv4ig "In the guided setup for an AI agent, define security controls for who can access the AI agent and what data the AI agent has access to.") guided setup.
* To configure an ACL for an agentic workflow, see the [Define security controls for an agentic workflow](https://www.servicenow.com/docs/qxzXRhxS2boNbPatAyZ7aQ "In the guided setup for an agentic workflow, define security controls for who can access the agentic workflow and what data the agentic workflow has access to.") guided setup.

{#aia-acl-configuration__ul_ksy_kbg_xgc}  
Note:  
If there are conflicting security requirements between agentic workflows, AI agents, and AI agent tools, or if the invoking user meets the criteria for some ACLs but not others, your agentic AI fails to execute. When configuring these security settings, consider all aspects of the agentic system- including the agentic workflow, AI agents, and tools.

## Security checks on AI Agent Studio {#aia-acl-configuration__section_ux_warnings}

To inform users about security checks on the agentic system, the platform provides the following notifications in the AI Agent Studio interface:

* AI Agent Studio Overview page: The AI Agent Studio overview page displays a warning when agents or agentic workflows don't have explicit ACLs configured on the instance.

* AI agent guided setup: The AI agent guided setup page displays a warning banner when that agent doesn't have the required ACLs configured.  
  Note:  
  To configure access control lists for an AI agent, see [Define security controls for an AI agent](https://www.servicenow.com/docs/SGciUCFmTP77qs2F6Qv4ig "In the guided setup for an AI agent, define security controls for who can access the AI agent and what data the AI agent has access to.").
* Agentic workflow guided setup: The agentic workflow agent guided setup page displays a warning banner when that agentic workflow doesn't have the required ACLs configured.  
  Note:  
  To configure access control lists for an agentic workflow, see [Define security controls for an agentic workflow](https://www.servicenow.com/docs/qxzXRhxS2boNbPatAyZ7aQ "In the guided setup for an agentic workflow, define security controls for who can access the agentic workflow and what data the agentic workflow has access to.").

{#aia-acl-configuration__ul_lmf_pcq_jjc}

These warnings indicate that ACLs are missing and should be configured to verify secure and uninterrupted operation. Users who have already switched to deny-by-default and users who still use wildcard ACLs will both see these
warnings. For wildcard ACL users, the warnings are informational.

## ACL types {#aia-acl-configuration__section_overview}

The AI access control changes brought in five new ACL types that default to allow access, expanding the platform attack surface. The ServiceNow AI Platform enforces a deny-by-default directive for these agentic ACL types on the freshly reset instances. This configuration verifies that records without explicit ACLs aren't inadvertently exposed, aligning the
platform with secure-by-default best practices for AI agentic components.

The ACL types are:

* `gen_ai_agent`
* `gen_ai_workflow`
* `gen_ai_skill`
* `Flow`
* `flow_action`
{#aia-acl-configuration__ul_jmf_pcq_jjc}

## How deny-by-default enforcement works {#aia-acl-configuration__section_how_it_works}

The Security Attribute field value for AI Agent and agentic workflow on the Access Controls table \[sys_security_acl\] is set to Never, enforcing the deny behavior and leaving the Decision Type field value as is, that is, Allow If. This configuration verifies that if an AI component already has a primary ACL in place, access continues to be governed by that ACL. The backup (wild card) ACLs deny access only when no primary ACL is present. The old wildcard ACLs allow users with agents that predate the availability of access controls in agentic products to continue to run their agents, but that general guidelines is to implement deny by default in all instances. The replacement means that the AI agents and agentic workflows must have explicit ACL entries to operate. Without explicit ACLs, access is denied by default.  
Note:  
The enforcement applies only to the freshly reset instances. Any instances that aren't reset aren't affected by this configuration change.

## Scope and applicability {#aia-acl-configuration__section_scope}

The deny-by-default ACL configuration applies under the following conditions:

* The instance is a freshly reset instance.
* The ACL type is one of the five agentic types.
* The existing ACL record uses a wildcard (`*`) pattern.
{#aia-acl-configuration__ul_kmf_pcq_jjc}

## Security benefits {#aia-acl-configuration__section_security_value}

Enforcing deny-by-default ACLs for agentic types provides the following security benefits:

* Reduces the risk of unauthorized access to AI agents and agentic workflows resulting from permissive wildcard ACLs.
* Verifies that records without explicit ACL entries aren't inadvertently exposed.
* Aligns the platform with secure-by-default principles for AI agentic components.
* Provides a clear, auditable ACL model for agentic workflows and AI agents.
{#aia-acl-configuration__ul_mmf_pcq_jjc}

