CPQ: User Access Control
Summarize
Summary of CPQ: User Access Control
The User Access Control feature in CPQ enables ServiceNow customers to manage and customize user permissions effectively across different CPQ areas. This control is essential for regulating access to CPQ Admin functions and related utilities, ensuring users have appropriate privileges aligned with their roles. Note that this feature requires activation via a ServiceNow support request.
Show less
Access Levels and Areas
Access is managed through defined levels—NONE, READ, EDIT, and ADMIN—across several key areas:
- ENDUSER: Basic runtime user access.
- CONFIG: Configuration access, including GET, POST, PUT, PATCH, DELETE, and Matrix Loader endpoints.
- TRANSACTION: Transaction-related permissions mirroring CONFIG’s access levels.
- MANAGEDTABLES: Permissions for individual or grouped tables, allowing granular control such as editing specific tables while reading others.
- DEPLOY: Full administrative control over deployments, including all blueprint, transaction, product catalog enrichment, and product filter deploys.
- UTILITIES: Access to logs, runtime clients, admin API keys, external connections, settings, and webhooks.
User Roles and Permissions
Roles correspond to specific access levels and correlate directly to API endpoints:
- READ: Access to GET endpoints.
- EDIT: Additional access to POST, PUT, PATCH, DELETE endpoints.
- ADMIN: Full access including Matrix Loader and deployment related operations.
These roles allow precise control over user capabilities within CPQ.
Modifying Access Controls
Admin users can update access settings via CSV import through the User Access utility (Admin > Utilities > User Access). This method supports adding, modifying, or deleting user access:
- View existing user access and details with tooltips.
- Prepare CSV files to specify user names, email addresses, access areas, access levels, and actions (e.g., UPSERT, DELETE).
- Import CSV files to apply changes, with immediate confirmation of success or failure.
This process enables bulk management of user permissions, including granular table-level access and complex role configurations.
Practical Application for ServiceNow Customers
By leveraging User Access Control, customers can:
- Ensure security and compliance by granting only necessary permissions per user role.
- Customize access down to individual tables, supporting precise operational requirements.
- Streamline administration through CSV-based bulk updates, improving efficiency and reducing errors.
- Manage deployment and utility access securely, maintaining control over critical CPQ functions.
View access types, access areas, and user roles that can be managed via the User Access utility.
Use the User Access utility to manage access to CPQ Admin. Admin users have full admin access unless their access level is modified via CSV import.
For basic user access in CPQ, see User access.
Access levels
- NONE
- READ
- EDIT
- ADMIN
Access areas
- END_USER
- CONFIG
Users with ADMIN can use the Matrix Loader, including product filters and the catalog enrichment script MANAGED_TABLES.
- TRANSACTION
Users with ADMIN can use the Matrix Loader.
- MANAGED_TABLES
- TABLEApplies permissions for an individual table listed in addition to any MANAGED_TABLES access level. Examples:
- EX: MANAGED_TABLES: NONE + TABLE “myTable” Edit = ability to edit “myTable” only
- EX: MANAGED_TABLES: READ + TABLE “myTable” Edit = ability to read all tables and edit "myTable"
- DEPLOY
- Applies all blueprint, transaction, product catalog enrichment, and product filter deploys
- Roles are either NONE or ADMIN UTILITIES
- UTILITIES
- Logs, user access, runtime clients, admin API keys, external connections, settings, webhooks, connections
- Products (for Ecommerce tenants)
Tables
User access can be limited to specific tables via CSV or API.
User roles
- END_USER: This is the only permission for the runtime
- CONFIG_NONE / CONFIG_READ / CONFIG_EDIT / CONFIG_ADMIN
- READ correlates to GET endpoints
- EDIT additionally correlates to POST PUT PATCH DELETE endpoints
- ADMIN additionally correlates to Matrix Loader endpoints
- TRANSACTION_NONE / TRANSACTION_READ / TRANSACTION_EDIT / TRANSACTION_ADMIN
- READ correlates to GET endpoints
- EDIT additionally correlates to POST PUT PATCH DELETE endpoints
- ADMIN additionally correlates to Matrix Loader endpoints
- MANAGED_TABLES_NONE / MANAGED_TABLES_READ / MANAGED_TABLES_EDIT / MANAGED_TABLES_ADMIN
- READ correlates to GET endpoints
- EDIT additionally correlates to POST PUT PATCH DELETE endpoints
- ADMIN additionally correlates to Matrix Loader endpoints
- DEPLOY_NONE / DEPLOY_ADMIN (no EDIT or READ): ADMIN everything deployment related, including Product Filter Rules and Product Catalog Enrichment Deployments
- UTILITIES_NONE / UTILITIES_READ / UTILITIES_ADMIN (no EDIT)
- READ correlates to GET endpoints
- ADMIN correlates to everything else
Modifying access controls
Admin users can modify access via CSV upload (Admin > Utilities > User Access). The User Access list shows existing users.
Steps:
- Hover a tooltip to view a userʼs access.
- Create a CSV file to add users, make changes to users, or delete users. (See below for sample CSV files.)
- Import the CSV file.
You will receive a message confirming success or failure.
Changes to user list are now made.
Sample CSVs
Default all-access admin CSV:
name,userName,area,access,action
User,email@example.com,DEPLOY,ADMIN,
User,email@example.com,UTILITIES,ADMIN,
User,email@example.com,CONFIG,ADMIN,
User,email@example.com,TRANSACTION,ADMIN,
User,email@example.com,MANAGED_TABLES,ADMIN,
Example complex-access CSV:
name,userName,area,access,action
User 1,user.one@example.com,DEPLOY,ADMIN
User 2,user.two@example.com,UTILITIES,ADMIN
User 2,user.two@example.com,CONFIG,ADMIN
User 2,user.two@example.com,TRANSACTION,ADMIN
User 3,user.three@example.com,END_USER,END_USER
User 4,user.four@example.com,END_USER,END_USER,DELETE
User 5,user.five@example.com,CONFIG,ADMIN
User 5,user.five@example.com,TRANSACTIONS,ADMIN
User 5,user.five@example.com,MANAGED_TABLES,READ
User 5,user.five@example.com,UTILITIES,ADMIN
User 5,user.five@example.com,DEPLOY,ADMIN
User 6,user.six@example.com,CONFIG,ADMIN
CSV adding user to the table "sampleTable":
name,userName,area,access,variableName,action
John Smith,john.smith@example.com,CONFIG,ADMIN,,UPSERT
John Smith,john.smith@example.com,TRANSACTIONS,ADMIN,,UPSERT
John Smith,john.smith@example.com,TABLE,ADMIN,sampleTableName,UPSERT
Jane Doe,jane.doe@example.com,MANAGED_TABLES,READ,,DELETE
Jane Doe,jane.doe@example.com,UTILITIES,,NONE