---
sourceDocument: Australia IT Service Management
sourceDocumentLink: https://www.servicenow.com/docs/r/it-service-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia IT Service Management

ft:clusterId :

    - itsm

bundleId :

    - itsm

workflow :

    - Technology


---

# Create an ACL

# Create an ACL {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Create an access control rule (ACL) to avoid the Needs review field from being modified after it has been set.

## Before you begin

Role required: admin with elevated security

## About this task

The newly created UI Policy makes the Needs review field
mandatory when a change request reaches the Complete
state.

The subsequent configuration of the state model ensures that a value is required in the Needs review field before the change request can be saved in the Complete state. To avoid the
Needs review value from being changed after it has been set, create access control level record (ACL) to make the field read-only.

## Procedure

1. Open the Change Request form.
2. Open the form context menu and select ConfigureSecurity Rules.
3. Elevate your security role in the user menu that opens when you select your name in the header.  
   Only administrators with elevated security roles can add ACLs.
4. Select New.
5. Enter the following values.  
   {#t_CreateNewACL__table_wjg_xgm_b1b__entry__2}

   | Field | Value |
   |-|-|
   | Type | Record |
   | Operation | Write |
   | Name (first part) | Change Request |
   | Name (second part) | Needs review |
   | Condition | \[State\] \[is\] \[Implement\] |
   [ ]

   {#t_CreateNewACL__table_wjg_xgm_b1b}  
6. Select Submit.
**Previous topic:** [Add a UI policy](https://www.servicenow.com/docs/~Yg2GF6NmJzi1VUq_D4xgg "Add a UI policy to display the Needs review field for Normal change requests when it reaches the Complete state.")  
**Next topic:** [Update the state handler script include](https://www.servicenow.com/docs/Z3b3dPc~ZWVvBbXkuybDMQ "Update the ChangeRequestStateHandler script include with the new Complete state.")

*[\>]: and then


