Using CPQ user access management

  • Release version: Australia
  • Updated March 12, 2026
  • 3 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Using CPQ User Access Management

    This guide explains how to manage user access to the Configure, Price, Quote (CPQ) Admin interface in ServiceNow. It enables administrators to grant or remove admin rights for CPQ users and troubleshoot common access issues. Managing access ensures that only authorized users can modify CPQ configurations and administrative settings, while others have end-user permissions suitable for sales and partner roles.

    Show full answer Show less

    Key Features

    • User Access Utility: Available via a support request, this tool allows admins to control access levels for CPQ users. Admin users have full rights unless restricted by CSV import changes.
    • Access Levels:
      • ADMIN: Full access to CPQ Admin functions including blueprint creation, field and rule management.
      • ENDUSER: Permission to create configurations without admin capabilities, ideal for sales and partners.
    • Access Management via CSV: Admins can export a user access sample file, modify user roles, and import it back to update multiple users efficiently.
    • Edit User Interface: Admins can click individual usernames to toggle admin access and save changes directly within the CPQ Admin interface.
    • Automatic User Creation: Users first appear in the system after accessing CPQ and authenticating. New users default to ENDUSER access unless upgraded by an admin.
    • Troubleshooting: Recommended steps for new users include restarting the browser, clearing cache and session cookies. CSV imports require matching username case sensitivity, especially in Salesforce-integrated instances where usernames must be lowercase.

    Practical Application for ServiceNow Customers

    ServiceNow customers using CPQ can use these user access management capabilities to:

    • Secure the CPQ Admin interface by limiting admin rights to only necessary personnel.
    • Efficiently onboard and manage user permissions in bulk through CSV imports, saving time and reducing errors.
    • Resolve common access problems quickly by following the outlined troubleshooting steps.
    • Ensure compliance with external integrations like Salesforce by maintaining proper username formatting.

    By applying these practices, customers can maintain a well-controlled CPQ environment that supports both administrative functions and end-user configuration activities with appropriate security and ease of management.

    Manage access to the CPQ Admin interface. Grant or remove admin rights and troubleshoot access issues.

    The User Access utility allows managing access to selected areas of CPQ Admin. Admin users have full admin access unless their access level is modified via CSV import.

    Note:
    The User Access utility is enabled via a support request. Open a ticket by using the ServiceNow Support portal. For step-by-step instructions, see Create a case on Now Support for CPQ Customers.

    CPQ Admins can control access to the CPQ Admin interface by granting admin access only to specific users. All existing users have admin access, which can be adjusted to end-user access as needed. New users automatically receive end-user access and need to be explicitly granted admin access by a user with admin access.

    Note:
    If a message appears that says "An unknown error occurred" when you try to access CPQ Admin, admin access may not be toggled on. If you encounter this message, contact a user with CPQ admin access to enable your access.

    Setting up user access

    Admin users can modify access via CSV upload (Admin > Utilities > User Access)

    The User Access window displays the users currently in the system. To view a user's access, move the cursor over the user. The access is displayed in a tooltip.

    To add, change, or delete users, create a CSV file and import the file into Admin Assist.

    • Username: Email address of the user, click to open a modal window for editing access. See 'Edit User' section, below.
    • Access: Level of access a user has, can be END_USER or ADMIN,END_USER
      • END_USER: Can create configurations using CPQ. This is for sales users, partners, and similar roles.
      • ADMIN: Can access the administrative side of CPQ to create and modify blueprints, fields, rules, and other items.
    • Toggle Admin Access: Select one or more users using the check box. Toggle Admin Access adds or removes admin access for the selected users, depending on their current access level.
    • Import: At the bottom of the user access page is an exportable sample user access file. After making the necessary modifications to the exported file, you can import it using the Import button.

    Editing a user

    Individual users can be edited by clicking their username in the table, which launches an Edit User window.

    • Username: email address of the user being edited.
    • Enable Admin Access: Toggle for controlling access to the Admin features of CPQ. The toggle to the right indicates that the user has Admin privileges.
    • Save / Cancel: Confirm any changes made or cancel to not save.

    Additional considerations

    Users are created and show up on the User screen in CPQ the first time they access a CPQ instance and go through the authorization provider.

    All existing users of a CPQ instance have END_USER and ADMIN access. Admin access can be removed from users that do not require it.

    Newly created users have END_USER permissions only. The access level can be changed by an administrator following the above steps.

    Troubleshooting

    • Once granted access, new users may need to do one or more of the following:
      • Restart the browser
      • Clear the browser cache
      • Remove CPQ session cookies before accessing CPQ Admin
    • If users experience login issues after a CSV import, verify that the user names in the CSV match the case used in the user records. If CPQ is integrated with Salesforce, user names should be all lowercase to align with system requirements, as Salesforce does not allow user names to be uppercase.

      If necessary, edit the CSV so that user names are in lowercase, and import the user again.