---
sourceDocument: Brazil ServiceNow AI Platform Administration
sourceDocumentLink: https://www.servicenow.com/docs/r/platform-administration

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil ServiceNow AI Platform Administration

ft:clusterId :

    - platadm

bundleId :

    - platadm

workflow :

    - Platform


---

# Read-only options

# Configuring read-only security options {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Configuring read-only security options

This guide explains how to control and customize the editability of read-only fields in ServiceNow by configuring read-only options.
Read-only fields restrict modifications in specific scenarios, and the platform offers configurable behaviors to balance usability and security.
These settings are managed through theRead only optionfield in a dictionary record.
Show full answer Show less  

## Key Features

* **Instance Configured:** Default setting for fields created before the Australia release, maintaining backward compatibility. Behavior is controlled by the `glide.readonly.legacyreadonlybehavior` system property, which defaults to *clientscriptmodifiable*. This allows client scripts to modify read-only fields.
* **Display Read Only:** Fields appear read-only in the UI, but changes can still be made via client scripts and server-side APIs like TableAPI, GraphQL, and GlideRecordSecure().
* **Client Script Modifiable:** Fields are read-only in the UI and can only be modified by client scripts. Server-side scripts and APIs cannot modify these fields.
* **Strict Read Only:** Fields are fully read-only, preventing any changes from client scripts or server-side APIs.

## Testing and Implementation

To ensure smooth transition and maintain compatibility, testing read-only behavior in a non-production instance is essential. Adjust the `glide.readonly.legacyreadonlybehavior` property with values such as *displayreadonly* , *clientscriptmodifiable* , or *strictreadonly* to validate your fields and client scripts under different security models.

**Important:** This system property affects all fields set to **Instance Configured** and is intended only for testing in non-production environments. After successful testing, you can apply stricter read-only options (like Strict Read Only) on a field-by-field basis in your production environment for enhanced security.

## Practical Use for ServiceNow Customers

* Gain precise control over when and how read-only fields can be modified, improving data integrity and security.
* Test changes safely in non-production instances before enforcing stricter controls in production.
* Customize read-only behavior to support client scripts or restrict modifications completely, depending on your security requirements.
* Use the available options to balance usability with security, ensuring critical data is protected without hindering necessary automation or workflows.  
Control the ability to edit read-only fields by configuring read-only options.

Read-only fields are intended to restrict modifications in specific situations. In addition, the system provides configurable read-only options that enable you to customize the behavior of read-only fields according to your
requirements, while balancing usability and security. You can adjust the read-only behavior by updating the Read only option field in a dictionary record.

## Available read-only options {#read-only-option__section_ahk_jqd_tgc}

Instance Configured
:   Default Read only option value for read-only fields created prior to the Australia release. Used for maintaining backwards compatibility and testing read-only behavior in non-production instances.

    When
    the Read only option is set to Instance Configured in a dictionary record, read-only behavior is derived from the glide.read_only.legacy_read_only_behavior system property. By default, the
    property is set to client_script_modifiable, which honors the pre Australia read-only behavior, allowing changes to read-only fields through client scripts.

Display Read Only
:   Displays the field as read-only in the UI, but allows changes to the read-only field through client scripts and server-side operations such as TableAPI, GraphQL, and
    GlideRecordSecure().

Client Script Modifiable
:   Displays the field as read-only in the UI, and allows changes to read-only fields through client scripts but not through background scripts or server-side APIs like TableAPI, GraphQL, and
    GlideRecordSecure().

Strict read only
:   Displays the field as read-only in the UI, but prevents any changes from both client scripts and server-side APIs.

## Testing read-only behavior {#read-only-option__section_bhq_vp1_sgc}

The Instance Configured read-only option maintains backwards compatibility for read-only fields created prior to the Australia release, and also enables you to test other read-only options on a non-production instance before
implementing them on your production instance.

When the Read only option is set to Instance Configured, read-only behavior is determined by the glide.read_only.legacy_read_only_behavior system property. The default value for the
glide.read_only.legacy_read_only_behavior system property is client_script_modifiable, which means the field appears as read-only in the UI, but can still be changed by a client script.

You can test read-only behavior on a non-production instance by updating the system property with the following values and then validating that your fields and client scripts work as expected.

* display_read_only
* client_script_modifiable
* strict_read_only

{#read-only-option__ul_dxz_3c2_tgc}  
Important:  
The glide.read_only.legacy_read_only_behavior system property is only intended for testing read-only behavior on non-production instances. Updating this property affects all fields where the Read only option field is set to Instance Configured.

For example, to verify that tighter security controls still work with your client scripts and other customizations, you can set the glide.read_only.legacy_read_only_behavior property to
strict_read_only in a non-production instance, and then test the behavior. After you verify the behavior in a non-production instance, you can update individual fields on your production instance to use the Strict
Read Only option on a field-by-field basis.
* **[Test read-only options](https://www.servicenow.com/docs/lHM8eWwLkML4Z9P4UtGeRg)**   
  Test read-only behavior on a non-production instance before updating Read only option field values on your production instance.
* **[Make a field read only](https://www.servicenow.com/docs/fxsXtJ1daT~yjyehPlOFYg)**   
  Control whether a field is read only and whether it can be changed by a client script and server-side APIs.

