---
sourceDocument: Australia Platform security
sourceDocumentLink: https://www.servicenow.com/docs/r/platform-security

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Use Scripting Governance Tool

# Use Scripting Governance Tool {#ariaid-title1}

* Release version: Australia
* 
* Updated April 6, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Use the Scripting Governance Tool to provide a single, centralised control for managing scripting access across your ServiceNow AI Platform.

## Before you begin

Role required: security_admin  
Important:  
You must have elevate your role <kbd class="ph userinput">security_admin</kbd>. See [Elevate to a privileged role](https://www.servicenow.com/docs/KHD6acRdk65mqNIgdvlpng "The base system admin can elevate to a privileged role to have access to the features of High Security Settings.").

The Scripting Governance Tool helps you review user scripting governance your ServiceNow AI Platform. The Conditional Script Writer group grants scripting permissions to its members via the <kbd class="ph userinput">snc_required_script_writer_permission</kbd> role. Users are added
to the group by either an automated assignment or manual configuration. You can manage both of these settings from the Scripting Governance Tool.

## Procedure

1. Navigate to AllSystem SecurityScripting Governance Tool.
2. Use the following features to learn more:  
   {#use-sgt__table_j3q_mjm_w3c__entry__2}

   | Features | Description |
   |-|-|
   | Users in Conditional Script Writer Group | Displays the number of users in the Conditional Script Writer group. These users are granted the <kbd class="ph userinput">snc_required_script_writer_permission</kbd> until removed from the group. |
   | Auto-assignment | Auto-assignment assigns new users to the Conditional Script Writer group if the users are <kbd class="ph userinput">internal users</kbd> and has one functional role. You can select the slider to de-activate. Note: It is recommended to de-activate auto-assignment. |
   | Scan for users who have scripted (Recommended) | Scans for users in the ServiceNow AI Platform who have modified records containing script fields such as business rules, script includes, or client scripts. When running the scan, you can define a time period for which the scan checks. |
   | Manual Configuration | You can manually select users that stay in the Conditional Script Writer group. Select the Manage scripting access button and enter the users into the text field for manually managing the user removal process from the Conditional Script Writer group. |
   | Groups containing a scripting role | Displays the number of groups that contain a scripting role. By default the Conditional Script Writer group has a scripting role. Note: It is recommended to manage scripting access exclusively through the Conditional Script Writer group. Adding the <kbd class="ph userinput">snc_required_script_writer_permission</kbd> role as a child role to other roles or groups reduces your ability to centrally control who can script on your instance. |
   | Roles containing a scripting role | Displays the number of roles that contain a <kbd class="ph userinput">snc_required_script_writer_permission</kbd> role. Note: It is recommended to manage scripting access exclusively through the Conditional Script Writer group. Adding the <kbd class="ph userinput">snc_required_script_writer_permission</kbd> role as a child role to other roles or groups reduces your ability to centrally control who can script on your instance. |
   | View scans | After you run the scan, the details of the scan are displayed on the View scans. |
   | View removals | When you schedule for removal of user from the Conditional Script Writer group, the details are displayed on the View removals. |
   [Table 1. Scripting Governance Tool]

   {#use-sgt__table_j3q_mjm_w3c}   

## Result

You can view the following topics to understand how you can:

* [Scan for users who have scripted](https://www.servicenow.com/docs/4Y2dmUPW4y1sX434uXCHug "Scan your instance to find users who have scripted within a specific time frame. The scan queries the audit logs and identifies any user who has performed write or update to a table having script field.")
* [Remove users from the Conditional Script Writer group](https://www.servicenow.com/docs/dIw08ixWZoFisqke7OWZwA "Use the Manage scripting access to manually add or remove users from the Conditional Script Writer group to control who has scripting access.")
{#use-sgt__ul_yyf_xsm_w3c}

*[\>]: and then


