Configuring user access and data permissions for agentic workflows

  • Release version: Yokohama
  • Updated November 19, 2025
  • 1 minute to read
  • Configure the security controls to specify the users who can discover or use the agentic workflow, and provide data permissions for the agentic workflow.

    Role masking enables users to limit the roles and privileges of agentic workflows during tool execution. Agentic workflows and their AI agents that get installed with Now Assist applications are assigned pre-defined roles. If you select Users with specific roles for user access, you must configure the security controls to include these roles. Data access settings must also include these roles. For the instructions to change the security controls, see Define security controls for an agentic workflow.

    In Now Assist in Contract Management, the following roles are configured with the base system to provide data access to the agentic workflows in Contract Management Pro.
    • sn_cm_gen_ai.ai_contract_fulfiller
    • sn_lg_cnt.contract_fulfiller
    • sn_lg_ops.request_fulfiller
    • sn_cm_core.contract_fulfiller
    • contract_manager
    • sn_lg_cnt.contract_owner
    • sn_cm_obligation.obligation_fulfiller
    To ensure that the agentic workflow can access all the required information for your workspace, add the necessary roles for the agentic workflow in the AI Agent Studio.
    1. Navigate to All > AI Agent Studio > Create and manage > .
    2. Select the Agentic workflows tab.
    3. Open the agentic workflow for which you want to configure the security controls.
    4. In the guided setup, navigate to Define security controls to define the security access.
      1. In the Define user access tab, add the user roles who can discover or invoke the agentic workflow.
      2. In the Define data access tab, add the user roles to define which roles the agentic workflow uses to access data during its execution.

        This configuration controls what information the agentic workflow can read, update, or share, based on the permissions of the selected roles.

    For more information on configuring the security controls, see Define security controls for an agentic workflow.