Create a user permission crawl for an external content connector
Retrieve security principals from your source system with a user permission crawl. Run the crawl as a one-time task or schedule it to run on a recurring basis.
Before you begin
To run crawls for external content connectors, your instance must have inbound mTLS support enabled. For details on verifying that this feature is enabled on your instance, see Verify whether inbound mTLS support is activated for your instance.
Role required: sn_ext_conn.xcc_admin
About this task
Many external content connectors support preservation of access permissions for searchable content retrieved from their source systems. To use this feature, search administrators must retrieve security principals from the connector's source system by creating a user permission crawl for the connector.
The user permission crawl maps security principals retrieved from the source system to users in your ServiceNow AI Platform® instance. Each user that corresponds to a source system security principal inherits content access permissions specified for that security principal.
A user permission crawl may take hours or days to complete, depending on the number of security principals defined in your source system.
- Adobe Experience Manager as a Cloud Service external content connector
- Amazon S3 external content connector
- ServiceNow® product documentation external content connector
- Slack external content connector
- Trello external content connector
- Webcrawler external content connector
The Atlassian Confluence Cloud external content connector only retrieves permissions for Confluence Cloud users who have made their email addresses visible to all users. To allow user permission, each Confluence Cloud user must set their own email visibility to Anyone as explained in the https://support.atlassian.com/confluence-cloud/docs/configure-user-email-visibility/ Atlassian support resource.
Procedure
Result
If you skipped step 4, your new user permission crawl is added to the system's crawl queue. The system runs your crawl when it has resources available to do so.
If you selected the Make recurring option in step 4, your new crawl appears in the Crawl schedules list in the external content connector editor's Create crawls tab.
What to do next
You can monitor your user permission crawl's status or review its results using the crawl history and analytics. For details on these metrics, see Review crawl history for an external content connector and Review user permissions for an external content connector.
If you need to cancel your running user permission crawl, see Cancel a running external content connector crawl.