Vault tools and metrics

  • Release version: Australia
  • Updated May 26, 2026
  • 4 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Vault tools and metrics

    ServiceNow Vault provides integrated tools and metrics designed to help you discover, classify, protect, and monitor sensitive data within your instance. These capabilities enable you to gain comprehensive visibility into your sensitive data security posture, apply protection mechanisms, and detect potential risks or data leaks in real time.

    Show full answer Show less

    Know Your Data

    ServiceNow Vault leverages Data Discovery and Data Classification to identify and organize sensitive data:

    • Data Discovery: Scans your instance for sensitive data patterns, reporting discovered data occurrences, discovery status, and sensitive data in attachments.
    • Data Classification: Helps create and manage data classes by classifying tables, columns, or dictionary entries. This classification supports targeted data protection measures.

    Protect Your Data

    Multiple tools within Vault enable robust protection of sensitive data:

    • Anonymization: Applies various anonymization techniques by data class to sanitize or remove sensitive data, supporting compliance such as data subject rights. Metrics track anonymized data volumes and anonymization job durations.
    • Cloud Encryption with Key Management: Uses block encryption with enhanced key management for secure data storage. Metrics include active key rotations and timing between rotations. Admin roles are required to access key management data.
    • Field Encryption: Ensures sensitive data remains encrypted while accessible only to authorized users. Metrics cover classification status, proportion of data protected, and active encryption keys.
    • Log Export Service (LES): Forwards logs to external analytics for monitoring sensitive data patterns, with default configurations available for quick setup.
    • Zero Trust Access (ZTA): Implements continuous authentication for classified sensitive data access, with default step-up authentication policies to enhance security in real time.

    Monitor Your Data

    The AI Insights section provides visualization and metrics that help you track sensitive data activity and potential threats:

    • Monitors users entering sensitive data in real-time discovery-configured tables and communication channels like Now Assist and Virtual Agent.
    • Displays occurrences of sensitive data by channel and database table, categorized by data pattern types such as driver license numbers or financial information.
    • Enables prioritization of data protection measures based on detected activities.

    Additional Vault Capabilities

    • Encryption Key Management and Field Encryption: A configurable suite of encryption modules to enhance data security.
    • Code Signing: Validates sensitive application configurations and scripts to improve security.
    • Data Privacy Plugin: Removes personally identifiable information (PII) when migrating user data from production to non-production instances.
    • Data Discovery Plugin: Enables identification and classification of PII for stronger security controls.
    • Log Export Service: Integrates ServiceNow logs with enterprise analytics platforms for improved monitoring and performance.
    • Zero Trust Access Service: Dynamically reduces user privileges during web sessions to minimize exposure to sensitive data.

    Learn about the tools and metrics ServiceNow Vault uses to protect and discover sensitive data.

    ServiceNow Vault integrates with several tools to provide you with a cohesive overview of your sensitive data security. You can hover over a widget to get further insight on the reported data. Select the Go to button on any tool to go to its respective page.

    Know your data

    ServiceNow Vault uses Data Discovery and Data Classification help you understand and know your data.
    Table 1. Tools and metrics
    Tool Metric Description
    Discovery

    Use Data Discovery to run a discovery scan to look for data patterns that might be sensitive data. Once discovered, data can then be reviewed or classified for further protection and management.

    Discovered data Occurrences of sensitive data across tables in your instance, categorized by sensitive data pattern type.
    Discovery status Current state of all discovered sensitive data patterns, including new findings pending review, classified, or marked as ignored.
    Discovered attachments Total sensitive data occurrences in attachments across tables in your instance.
    Classification

    Data Classification creates data classes and helps organize your data into data classes for better management. Classified data can be protected at the class level.

    Classifiable data Tables or columns that can be classified.
    Classified data Dictionary entries, tables, or columns that are classified.

    Protect your data

    ServiceNow Vault uses data anonymization, cloud encryption, field encryption, log export, and zero trust access to help secure and protect your data.
    Table 2. Tools and metrics
    Tool Metric Description
    Anonymization

    Anonymize data by data class with different anonymization techniques to preserve data patterns but remove sensitive data. Useful for sanitizing instances for development or removing specific user data because of rights to be forgotten. Default real-time protection policies are available from this card and are applied in addition to any existing policies. For more information, see Default policies and configurations in ServiceNow Vault.

    Existing data All classified data per workflow that is anonymized or not.
    Real time data Number of successful real-time calls to anonymize sensitive data as it enters the platform, by channel.
    Anonymization run times How long scheduled user- or data-based jobs ran in hours for existing data.
    Cloud Encryption with Key Management

    Securely protect sensitive data in encrypted storage for your data using block encryption, along with enhanced key management.

    Active cloud key Total rotations of the active cloud key.
    Note:
    To view this data, you need the Key Management Framework admin role (sn_kmf.admin or sn_kmf.cryptographic_manager).
    Key rotation Time elapsed between each rotation of active keys on your instance. Bar height measures how long a key was used before rotation.
    Note:
    To view this data, you need the Key Management Framework admin role (sn_kmf.admin or sn_kmf.cryptographic_manager).
    Field Encryption

    Securely protect sensitive data while providing access for authorized users. Useful for increasing protections from bad actors.

    Encrypted fields classification status Classification status of all data protected with Field Encryption.
    Classes protected with Field Encryption The proportion of classified data protected withField Encryption.
    Active encryption keys Number of active Field Encryption keys in your instance. Ideally, the number of active keys matches the number of classifications.
    Note:
    To view this data, you need the Key Management Framework admin role (sn_kmf.admin or sn_kmf.cryptographic_manager) and the security_admin role.
    Exploring Log Export Service (LES)

    Forward your instance's logs to external analytics tools to monitor data patterns. New users can activate default configurations from this card. For more information, see Default policies and configurations in ServiceNow Vault.

    Zero Trust Access (ZTA)

    Continuous authentication while accessing classified sensitive data in real time. Default step-up authentication policies are available for Vault customers. For more information, see Default policies and configurations in ServiceNow Vault.

    Continuous Authentication classification status Number of classifications that are protected due to the Continuous Authentication policies.
    Classes protected with Continuous authentication Number of classes protected with continuous authentication, categorized by class.

    Monitor your data

    The AI Insights section within ServiceNow Vault helps you keep track of activities that may indicate potential threats or data leaks.These activities are generated from channels such as Now Assist and Virtual Agent, as well as database tables configured with real-time discovery. This insight can help you prioritize your data protection strategies more effectively. Select View tool metrics to see the underlying metrics.

    Table 3. AI Insights charts
    Metric Chart Component Description
    User entering sensitive data In tables with real-time discovery The number of users whose sensitive data entries were detected in database tables configured with real-time discovery.
    In channels The number of users whose sensitive data entries were detected within channels such as Now Assist or Virtual Agent.
    Channels with sensitive data Channel bars (x-axis) Stacked bars representing each channel where sensitive data was detected, broken down by data patterns. The data pattern legend displays the color code for each pattern. They may include driver license numbers, financial information, and personal identifiers.
    Occurrences of sensitive data (y-axis) The count of sensitive data instances detected per channel.
    Tables with sensitive data found through real-time discovery Table bars (x-axis) Stacked bars representing each database table where sensitive data was detected, broken down by data patterns.
    Occurrences of sensitive data The count of sensitive data instances detected per table.

    All ServiceNow Vault tools