---
sourceDocument: Xanadu Employee Service Management
sourceDocumentLink: https://www.servicenow.com/docs/r/xanadu/employee-service-management

 Release :

    - xanadu

ft:locale :

    - en-US

ft:publication_title :

    - Xanadu Employee Service Management

ft:clusterId :

    - emplsm

bundleId :

    - emplsm

workflow :

    - Employee


---

# Add field security in HR

# Add field security in HR {#ariaid-title1}

* Release version: Xanadu
* 
* Updated August 1, 2024
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

You can secure a field on a form so that specific HR users cannot view
it.

## Before you begin

Role required: sn_hr_core.admin, security_admin

## About this task

Use Access Control (ACL) on a field to secure it.  
Note:  
This example shows how to secure the Ethnicity field on an HR Profile form so users with the HR Manager \[hr_manager\] role or below cannot view it.

## Procedure

1. Navigate to AllHR Profile.
2. Elevate your role to add security_admin.  
   Select your login name and select Elevate Roles.
3. Check security_admin.
4. Select OK.
5. Select an HR profile record to edit.  
   It can be any record.
6. Right-click the Ethnicity field and select Configure Security.  
7. The Security Mechanic menu appears.  
   Change the Operation to secure field to read.
8. Move a role that you want to view the field to the Selected column.  
   For example, move sn_hr_core.admin. By selecting read and adding sn_hr_core.admin, any role below this role, cannot read the field. For example, sn_hr_core.manager is below this role and cannot view this field after completing the steps.
9. Click OK.  
   Because HRSM is a scoped application, you have to ensure that you are in the scoped version within the form.
   * Click the Settings ![Gear icon]() icon.
   * Select Developer under System Settings.
   * Change Application to Human Resources: Core.
   * Close the window.
   {#FieldSecurity__ul_lgh_dxc_wz}
**Related topics**   

* [Access control list rules](https://www.servicenow.com/docs/access?context=access-control-rules&version=xanadu&pubname=xanadu-platform-security&ft:locale=en-US)

*[\>]: and then


