Security & Privacy tab in AI Control Tower
Review AI security metrics such as access issues, dormant and privileged AI agents, and map the relationships of your ServiceNow agents, agentic workflows, and tools. Check your entitlements to determine whether you have access to AI Control Tower Security and Privacy.
The Security & Privacy tab of AI Control Tower offers a dashboard-based overview of your AI security metrics. The dashboard contains several visualizations detailing AI security metrics. In addition to tracking metrics the Security & Privacy tab contains the access map, a tool that gives an node-graph visualization of the relationships between your ServiceNow agents, agentic workflows, and tools. You can use the map to investigate the relationships between your AI agents and workflows further.
Dashboard
- Access issues
The Access issues chart displays the proportion of AI agents experiencing access-related issues and lists the top AI systems with access issues. AI agents with access issues may be unable to complete their workflows due to the access issue. Hover over a portion of the chart to see the exact proportion and count of agents.
You can create AI security tasks directly from the list view by selecting Create AI task. See all active AI security tasks in AI assets in the AI Task section. Access to this section requires the sn_vsc.task_manager role.
Resolved AI security tasks that are over 180 days old are archived. Archival days can be configured in system properties.
- Autonomous vs. supervised agentic workflows
The chart displays the proportion of autonomous (self-driven) to supervised (human-guided) agentic tools in use. Hover over a portion of the chart to see the exact proportion and count of agents.
To show AWS agent metrics, filter the metrics by selecting AWS Bedrock in the provider drop-down list. You must have an AWS account configured for your instance. For more details, see AI connections.
- Privileged AI Agents
The area chart shows AI agents with elevated permissions such as an agent with admin or security admin permissions that can perform critical actions. Some workflows require AI agents have elevated permissions to complete. Hover over a portion of the chart to see the exact number of privileged agents on that day.
To show AWS agent metrics, filter the metrics by selecting AWS Bedrock in the provider drop-down list. You must have an AWS account configured for your instance and the Now Assist AiSP AWS IAM Privileged Policy Checker skill enabled. For more details, see AI connections and Activate a Now Assist skill.
You can create AI security tasks directly from the list view by selecting Create AI task. See all active AI security tasks in AI assets in the AI Task section. (Role required: sn_vsc.task_manager.)
Resolved AI security tasks that are over 180 days old are archived. Archival days can be configured in system properties.
- Dormant AI systems
The area chart shows AI agents that have not been active for over 90 days. Review dormant AI agent permissions to reduce security risk. Hover over a portion of the chart to see the exact number of dormant AI systems for that day.
To show AWS agent metrics, filter the metrics by selecting AWS Bedrock in the provider drop-down list. You must have an AWS account configured for your instance. For more details, see AI connections.
When an AI agent becomes dormant, an AI security task is created automatically to streamline your workflow, and quickly resolve issues. The AI security task is assigned to the agent’s owner. See all active AI security tasks in AI assets in the AI Task section.
Resolved AI security tasks that are over 180 days old are archived. Archival days can be configured in system properties.
- Prompt injection
- These charts show prompt injection data provided by Now Assist Guardian. To see data, enable Now Assist Guardian for your instance. For more details, see Now Assist Guardian analytics.
- Offensive content
- These charts show offensive content data provided by Now Assist Guardian. To see data, enable Now Assist Guardian for your instance. For more details, see Now Assist Guardian analytics.
- Sensitive data
-
The Sensitive data detected chart shows sensitive data that was identified in user responses to Now Assist prompts. Exposure of sensitive data is limited to the LLM in your instance.
The Sensitive data anonymized chart shows prompt data that met configured data patterns. This data was anonymized based on the configuration for the pattern in Configuration Data Patterns in Data Privacy.
Access map
The Access map displays a node map detailing the relationships of your ServiceNow® agents, agentic workflows, and tools. You can use the map to review these relationships, configure agent details, and resolve access issues. The map includes filters for both agents and agentic
workflows. You can open the access map by either navigating to , or selecting the link in the dashboard. See Using the access map to learn how to use access map.
If a warning icon appears on any agent, that agent has access issues. Select the warning icon to see details such as the workflow, agent, and tool associated with the access issue.
In Access issues, the User ID is the ID of the user who ran the agent.
ServiceNow AI Insights
ServiceNow AI Insights require that the Now Assist AICT Security Posture Summarizer skill is enabled. For more details, see Activate a Now Assist skill.
- Positives: Enabled settings and features that improve your security posture.
- Areas for Attention: Low- to medium-risk items to resolve.
- High Impact Observations: High-risk items to resolve.
- Actions: Suggested action items to address Areas for Attention and High-Impact Observations.
ServiceNow AI Security Score
The ServiceNow AI security score is a measure of the health of your ServiceNow AI assets in terms of access issues, privileged AI agents, and dormant AI systems.
- AI assets impacting your score
- To see more information about your score, select See details in the Security & Privacy tab. A list view shows the ServiceNow AI assets that are included in your AI security score calculation. Your score is the average of all ServiceNow AI assets listed.