---
sourceDocument: Brazil Platform security
sourceDocumentLink: https://www.servicenow.com/docs/r/platform-security

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Configure ServiceNow access control

# Configure ServiceNow access control {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read  
Configure an access control record to specify one or more Customer Service and Support
employees who have permission to log in your instance.

## Before you begin

Role required: admin

## About this task

Note:  
The SNC Access Control (com.snc.snc_access_control) plugin prevents Customer Service and Support personnel from accessing the instances without your express permission. However, other authorized ServiceNow Operations personnel, in their capacity to support and manage the product, are required to perform administrative actions on the underlying infrastructure. This infrastructure includes servers and databases, among other infrastructure components that make up the SaaS solution. This access method is fully auditable and tracked.

This plugin enables you to restrict access to your instance without
your express permission, so it may affect support service levels and the
Availability SLA. Availability SLA is then measured from the time that Support
staff personnel are granted access to your instance.

## Procedure

1. Navigate to AllSystem SecuritySNC Access Control.
2. Click New.
3. Fill in the form fields (see table).
4. Click Submit.  
   {#t_ConfigureAccessControl__table_xgv_vj2_p5__entry__2}

   | Form fields | Description |
   |-|-|
   | Name | Names each Customer Service and Support employee who has permission to log in to this instance. * Express the names as firstname.lastname in lower case letters, separated by a period (for example, <kbd class="ph userinput">john.smith</kbd>). Each name must have a corresponding user record in support.servicenow.com. * If more than one Customer Service and Support employee has permission to log in this instance, enter multiple names and separate them by commas. * To enable all Customer Service and Support employees login rights to access the instance, enter an asterisk (\*) in place of the name. * If you intend on restricting Customer Service and Support employee access to the instance, the values in the Name field must not have an asterisk (\*) anywhere in the field. {#t_ConfigureAccessControl__ul_skl_2lb_snb} |
   | Reason | Human-readable field that describes why you are granting access permission. This field is optional. |
   | Start | Specifies the start date and time of the period during which the specified Customer Service and Support employees have login access. This field is mandatory. |
   | End | Specifies the ending date and time of the period during which the specified Customer Service and Support employees have login access. This field is mandatory. |
   | Access type | Controls whether the Customer Service and Support employee can modify data during a hop that uses this record. * Read-only: The hop is allowed only if the Customer Service and Support user also holds the snc_read_only role. If the user does not hold that role, the hop is rejected. This is the default for new SNC Access Control records. * Read and write: The hop is allowed with full read and write permissions. Existing SNC Access Control records that were created before this change default to Read and write. If two SNC Access Control records exist for the same Customer Service and Support user on the same customer instance --- one with Access type Read-only and another with Access type Read and write --- the hop is not blocked; the Read and write record grants access. |
   | Active | Controls whether this permission record is active. The default is Active. |
   [Table 1. SNC Access Control]

   {#t_ConfigureAccessControl__table_xgv_vj2_p5}

*[\>]: and then


