Summarize Access Observer logs AI agent

  • Release version: Australia
  • Updated August 14, 2026
  • 1 minute to read
  • This ServiceNow Vault agent summarizes access observer logs and provides detailed breakdowns by caller type, users, and roles for specific table and column combinations.

    Workflow

    1. Check the user has the security_admin role (required.)
    2. Retrieve available table/column combinations that have Access Observer logs, display them with log counts, and let the user pick one.
    3. Confirm logs exist for the selected table-column pair.
    4. For each of the seven supported caller types (UI action, UI page, script include, scripted REST API, scheduled jobs, business rule, and unidentified sources). Retrieve the access logs and display a summary showing total accesses, users, roles, and caller sources.
    5. Point the user to the Field Encryption with Vault module skill for encrypting the field and creating module access policies.
    Table 1. Configuration
    Field Description
    Allow third party to access this AI agent

    When enabled, third-party AI agents can use this agent. This value is off (false) by default. This setting is defined in the AI Agent configs [sn_aia_agent_config] table on the External discoverable field.

    Allow AI specialists to access this AI agent

    When enabled, AI specialists can use this agent. This value is off (false) by default. When set to true, more configuration options for tools become available so that an AI specialist can map inputs and response templates to tool outputs. This setting is defined in the AI Agent configs [sn_aia_agent_config] table on the Specialist enabled field.

    Manage long-term memory

    When enabled, all previous user interactions are used as context for the LLM. This value is off (false) by default. This setting is defined by the sn_aia.ltm.enable_long_term_memory system property. For more information, see ServiceNow Otto AI agents reference.

    Tools
    Script
    Check access log counts by caller type
    Check if user has security admin role
    Get Access Logs
    List available table and column combinations
    Agent roles (ACLs) snc_internal, snc_internal
    Data access roles security_admin, sn_vault_console.vault_console_admin
    Triggers

    Optional. None defined by default. An admin can specify triggers if desired. For more information, see Add a trigger to an AI agent.

    Channels

    Configure an assistant for Virtual Agent or ServiceNow Otto panel using Assistant Designer.

    Used in agentic workflows

    Summarize Access Observer logs

    Learn more about ServiceNow Vault at ServiceNow Vault.