Exploring user administration

  • Release version: Washingtondc
  • Updated February 1, 2024
  • 3 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Exploring User Administration

    User administration in ServiceNow involves creating and managing users, groups, and roles to control access to features on the AI Platform. This process is essential for maintaining security, compliance with regulations, and adapting to organizational changes. By effectively managing user accounts and permissions, administrators ensure appropriate access to applications and data.

    Show full answer Show less

    Key Features

    • Creating Users, Groups, and Roles: Administrators can create unique user accounts, define groups for similar roles, and assign roles that dictate access levels.
    • Subscription Management: Administrators can monitor and manage subscription usage, including per-user subscriptions.
    • Monitoring Instance Usage: Users with specific roles can track instance usage through dashboards.
    • User Preferences: Users can customize UI features, and administrators can manage these preferences as needed.
    • User Groups: Groups simplify administration by allowing bulk permission assignments, enabling specific tasks like approving requests or resolving incidents.
    • Roles Management: Roles govern user activities, with the ability to assign multiple roles to users and groups, enhancing access control.

    Key Outcomes

    By effectively utilizing user administration features, ServiceNow customers can:

    • Ensure secure and regulated access to sensitive data.
    • Streamline user management through groups and roles, reducing administrative overhead.
    • Monitor application usage and user activity for better resource allocation.
    • Adapt user permissions to match evolving organizational roles and responsibilities.

    Learn more about user administration for your instance.

    Overview

    Creating users, groups, and roles provide a flexible and scalable way to manage access to features on the ServiceNow AI Platform. By creating user accounts, assigning users to groups, and defining roles and permissions, administrators can ensure that users have the appropriate level of access to applications and data. This enables organizations to control access to sensitive data, maintain conformance with regulatory requirements, and improve overall security. Additionally, users, groups, and roles can be easily managed and modified over time as organizational needs change.

    Work flow

    Subscriptions, users, groups, and roles work together to help you define who can access features on your instance.

    1. Subscription Management

      Understand your subscriptions. Subscription management enables you to manage your subscriptions proactively and monitor subscription usage on your instances.

      Subscriptions may include per-user subscriptions. For more information, see Managing per-user subscriptions in Subscription Management.

    2. Creating users, companies, and departments

      Create an account record for the individuals who have access to your instance. Each user account has a unique login ID, password, and set of permissions (roles) that define what they can do and access within the platform.

    3. Creating groups

      Define groups that have similar roles or permissions. Groups enable you to apply permissions (roles) to multiple users at the same time. When a user is a member of a group, that user has the same permissions that have been defined for the group.

      You can view group members by navigating to All > User Administration > Groups. Select a group name and view the members in the Group Members related list.

    4. Managing roles

      Roles describe the types of activities that a user can perform on the instance. Each role has a set of permissions that can govern what the users and groups can do, such as read, write, create, or delete records. Roles can be assigned to users and groups. Users can have multiple roles.

      For a complete list of the roles included with the ServiceNow AI Platform, see Base system roles.

      Role records are stored in the Roles [sys_user_role] table.

    5. Monitoring instance usage

      Users with the admin or usage_admin role can view the Application usage overview and ServiceNow Store usage overview dashboards to track instance usage.

    6. Monitoring user activity

      Users with the admin role can impersonate users, manage user sessions, and leverage non-interactive sessions.

    Figure 1. User administration workflow
    Create users and add them to groups. Create and assign roles to both users and groups.

    User preferences

    Users can configure many UI features. Some examples include the number of rows per page in a list or whether the response time displays at the bottom of a list or form. Administrators can modify or delete these preferences as needed. For more information, see User preferences.

    User groups

    A group is a set of users who share a common purpose. Groups may perform tasks such as approving change requests, resolving incidents, receiving email notifications, or performing work order tasks. Any business rules, assignment rules, system roles, or attributes that refer to the group apply to all group members automatically. Users with the user_admin role can create and edit groups.

    When possible, simplify user administration by assigning roles to groups. Create groups that contain all the roles necessary for specific personas, and then assign users to those groups.

    Note:
    You can view group members by navigating to All > User Administration > Groups. Select a group name and view the members in the Group Members related list.

    Group records are stored in the Groups [sys_user_group] table.

    User roles

    Roles control access to features and capabilities in applications and modules. The admin role provides access to all features and capabilities.

    After access has been granted to a role, all the groups or users assigned to the role are granted the access. Roles can contain other roles, and any access granted to a role is granted to any role that contains it.

    For a complete list of the roles included with the ServiceNow platform, see Base system roles.

    Note:

    When possible, simplify user administration by assigning roles to groups. Create groups that contain all the roles necessary for specific personas, and then assign users to those groups.

    Role records are stored in the Roles [sys_user_role] table.