Enterprise Architecture Workspace access roles

  • Release version: Zurich
  • Updated April 17, 2026
  • 12 minutes to read
  • The following roles help you to configure and use the Enterprise Architecture Workspace application. After access has been granted to a role, all the groups or users assigned to the role are granted access. Roles can contain other roles, and any access granted to a role is granted to any other role that includes it.

    Enterprise Architecture Workspace roles

    The following roles are available in Enterprise Architecture Workspace. After access is granted to a role, all users and groups assigned to that role inherit the permissions. Roles can contain other roles, and any access granted to a role is also granted to any role that includes it.

    Table 1. Enterprise Architecture Workspace roles
    Role Description Typical persona
    sn_apm.apm_admin Full administrative access to configure and manage Enterprise Architecture Workspace settings, including Setup page configuration for all functional areas. Includes all permissions of sn_apm.apm_analyst. EA administrator, IT architect lead
    sn_apm.apm_analyst Create and manage key portfolio records such as business applications and digital integrations. Approve or reject requests when assigned to the Enterprise Architect group. Includes all permissions of sn_apm.apm_user. Enterprise architect, solution architect
    sn_apm.apm_user Create and update portfolio data across business architecture, information portfolio, technology portfolio, modeling, and data certification. Includes all permissions of sn_apm.apm_read. Application owner, business analyst, portfolio manager
    sn_apm.apm_read Read-only access to all pages and records in Enterprise Architecture Workspace. Cannot create or update data. For more information, see Business stakeholder role for Enterprise Architecture Workspace. Business stakeholder, executive, auditor

    Users with Enterprise Architecture Workspace roles and certain platform roles, such as ITIL and other CMDB related roles, may be able to create or edit Business Application records by default.

    Note:
    The global admin role continues to function through role inheritance. However, Enterprise Architecture now uses feature-specific granular admin roles. Use sn_apm.apm_admin instead of admin for application-level administration wherever possible. For more information, see Granular admin role changes in Enterprise Architecture.

    Enterprise Architect group

    The Enterprise Architect group is a platform user group that acts as a governance layer on top of the standard role hierarchy. It is configured intentionally to separate approval authority from general role access: users with the sn_apm.apm_analyst role can perform approvals and governance actions only when they are also members of this group. Assigning the role alone is not sufficient for these actions.

    To add or modify members of the Enterprise Architect group, navigate to All > Enterprise Architecture > Administration > Services Approval Group > Enterprise Architect Group.

    The following table lists the capabilities that require membership in the Enterprise Architect group.

    Table 2. Capabilities requiring Enterprise Architect group membership
    Functional area Role also required Capabilities unlocked by group membership
    Technology Reference Model (TRM) sn_apm.apm_analyst
    • Approve or reject TRM product requests
    • Approve or reject TRM product lifecycle requests
    • Create TRM product lifecycles
    • View and update pending TRM requests
    Enterprise modeling and visualization sn_apm.apm_analyst
    • Approve or reject modeling diagram requests
    • View shape library configurations, entity configurations, and modeling configuration and relationship definitions
    Technology Reference Model (TRM) — data access Group membership only Read data from the following TRM standards tables:
    • TRM Standards phase (sn_apm_trm_standards_phase)
    • TRM standards product lifecycle (sn_apm_trm_standards_product_lifecycle)
    • TRM standards technical debt (sn_apm_trm_standards_technical_debt)
    Application portfolio Group membership Retire a business application
    Architectural artifacts Group membership
    • Approve or reject architectural artifact version approval requests. EA group members receive approval requests by email and can approve or reject directly from the notification.
    • Owner permission on the following architecture document types:
      • Application Architecture
      • Technology Architecture
      • Business Architecture
      • Data Architecture
    Architecture Review Board (ARB) Group membership Request an ARB architecture review
    Publishing Center / TRM Catalog sn_apm.apm_admin + knowledge_admin + sp_admin Create, publish, and manage TRM Publishing Configurations
    Note:
    sp_admin is required in addition to sn_apm.apm_admin and knowledge_admin for EA group members accessing the Publishing Center.
    Administration Group membership
    • Access the Services Approval Group module to view and manage EA workflow groups
    • Configure the EA approval group using the Configure Enterprise Architecture Group step in APM Guided Setup

    Installation and plugin activation

    Plugin activation requires the global admin role.

    Capability admin sn_apm.apm_admin sn_apm.apm_analyst sn_apm.apm_user sn_apm.apm_read Notes

    Activate the EA Workspace plugin

    Yes

    Activate the Technology Portfolio Management (TPM) plugin

    Yes

    Activate the Technology Reference Model (TRM) plugin

    Yes

    Activate the Read only roles for Enterprise Architecture plugin

    Yes

    Setup page

    The Setup page provides configuration options for all functional areas in the workspace.

    Capability admin sn_apm.apm_admin sn_apm.apm_analyst sn_apm.apm_user sn_apm.apm_read Notes

    Configure application categories, category groups, and families

    Yes Yes

    Configure application and capability indicators

    Yes Yes

    Configure scoring profiles and attach profile indicators

    Yes Yes

    Configure TRM phases and TRM categories

    Yes Yes

    Configure information data domains

    Yes Yes

    Configure architectural artifact categories

    Yes Yes

    Configure demand actions

    Yes Yes

    Configure modeling settings, including shape libraries, entities, relationships, and diagram actions

    Yes Yes

    Configure total cost of ownership (TCO) sources, source cost types, and cost types; set TCO dashboard properties

    Yes

    Configure Publishing Center for TRM catalog publishing; modify TRM catalog publishing configurations; associate service portals with a TRM catalog knowledge base

    Yes Yes Yes Yes

    Requires sn_apm.apm_admin and knowledge_admin

    Add and edit certification policies from the Setup page (legacy CMDB-based policies)

    Yes Yes Yes Yes

    Requires certification_admin

    Business architecture

    Business architecture covers business capabilities, business units, departments, goals, value streams, value stream stages, business processes, and demands in the Portfolio List view.

    Capability admin sn_apm.apm_admin sn_apm.apm_analyst sn_apm.apm_user sn_apm.apm_read Notes

    Add and edit business capabilities and sub-capabilities

    Yes Yes Yes Yes

    Add and edit business units

    Yes Yes Yes Yes

    Add and edit departments; add users to departments

    Yes Yes Yes Yes

    Add and edit goals; add quantitative and qualitative targets; create sub-goals

    Yes Yes Yes Yes

    Add and edit value streams; add application models to value streams

    Yes Yes Yes Yes

    Add and edit value stream stages; associate business processes with value stream stages; add or remove business capabilities from value stream stages

    Yes Yes Yes Yes

    Add and edit business processes

    Yes Yes Yes Yes

    Add and edit demands

    Yes Yes Yes Yes

    Create demands from the Business Portfolio view and Application Rationalization views

    Yes Yes Yes Yes

    Export business portfolio data

    Yes Yes Yes Yes

    View all business architecture records

    Yes Yes Yes Yes Yes

    Application portfolio

    The application portfolio covers business applications, application services, digital integrations, digital interfaces, and product capabilities.

    Capability admin sn_apm.apm_admin sn_apm.apm_analyst sn_apm.apm_user sn_apm.apm_read Notes

    Add new business applications

    Yes Yes Yes

    Add and edit digital integrations; associate artifacts and information objects with digital integrations

    Yes Yes Yes

    Add and edit digital interfaces; manage Agile Development components, information objects, and credentials; relate a digital interface to an API

    Yes Yes Yes

    Update business application details

    Yes Yes Yes Yes

    Associate and unassign business capabilities, product capabilities, architectural artifacts, information objects, and TRM products with business applications

    Yes Yes Yes Yes

    Create diagrams and unified maps from a business application

    Yes Yes Yes Yes

    View the business application roadmap

    Yes Yes Yes Yes

    Add and edit application services

    Yes Yes Yes Yes

    Add and edit product capabilities; view all product capabilities

    Yes Yes Yes Yes

    View and manage AI systems and AI portfolio items associated with business applications

    Yes Yes Yes Yes

    Run the job to generate model IDs for business applications

    Yes Yes Yes Yes

    View all business applications, application services, digital integrations, digital interfaces, and associated records

    Yes Yes Yes Yes Yes

    Information portfolio

    The information portfolio covers data domains, information objects, architectural artifacts, and architectural decision records (ADRs).

    Capability admin sn_apm.apm_admin sn_apm.apm_analyst sn_apm.apm_user sn_apm.apm_read Notes

    Add and edit data domains and information objects

    Yes Yes Yes Yes

    Create and edit architectural artifacts; add versions, related entities, and associated records

    Yes Yes Yes Yes

    Share architectural artifacts with users and groups; manage access permissions for architectural artifacts

    Yes Yes Yes Yes

    Request approval for an artifact version; download and delete architectural artifact versions

    Yes Yes Yes Yes

    Create and edit architectural decision records (ADRs); add pages, subpages, and versions to ADRs

    Yes Yes Yes Yes

    Tag users and records in an ADR document; request approval for an ADR

    Yes Yes Yes Yes

    Associate architectural artifacts with business applications, capabilities, business processes, digital integrations, and TRM products

    Yes Yes Yes Yes

    View all data domains, information objects, architectural artifacts, artifact versions, and ADRs

    Yes Yes Yes Yes Yes

    Technology Portfolio Management (TPM)

    Technology Portfolio Management tracks software and hardware lifecycle data for business applications and application services.

    Capability admin sn_apm.apm_admin sn_apm.apm_analyst sn_apm.apm_user sn_apm.apm_read Notes

    Activate the TPM plugin

    Yes

    Update the system property to gather software from CMDB

    Yes

    Update TPM lifecycle data for a business application or application service

    Yes Yes Yes Yes

    View technology lifecycle data and technology risk information

    Yes Yes Yes Yes

    View technology portfolio audit risk details and update verification status

    Yes Yes Yes Yes

    Run the job to populate TPM lifecycle data

    Yes Yes Yes Yes

    Run the scheduled job to update TPM data

    Yes Yes Yes Yes

    Run the scheduled job to generate TPM risk; restart the TPM scheduled job

    Yes Yes Yes Yes

    View TPM logs; run the job to populate TPM lifecycle identifiers

    Yes Yes Yes Yes

    View technology portfolio data, lifecycle timelines, and risk information

    Yes Yes Yes Yes Yes

    Technology Reference Model (TRM)

    The Technology Reference Model provides a structured catalog of approved technologies and their lifecycle phases.

    Capability admin sn_apm.apm_admin sn_apm.apm_analyst sn_apm.apm_user sn_apm.apm_read Notes

    Activate the TRM plugin

    Yes

    Approve or reject TRM product requests

    Yes Yes Yes

    Must be in the Enterprise Architect group

    Approve or reject TRM product lifecycle requests; create TRM product lifecycles

    Yes Yes Yes

    Must be in the Enterprise Architect group

    View and update pending TRM requests

    Yes Yes Yes

    Must be in the Enterprise Architect group

    View all TRM products, grouped by category or individually

    Yes Yes Yes Yes

    View all TRM phases and categories

    Yes Yes Yes Yes

    Request a new TRM product; request a TRM product lifecycle change

    Yes Yes Yes Yes

    Create TRM product lifecycle requests

    Yes Yes Yes Yes

    Associate architectural artifacts with TRM products

    Yes Yes Yes Yes

    View, create, add, and remove business capabilities and business applications associated with TRM products

    Yes Yes Yes Yes

    View TRM technical debt; run the job to generate TRM technical debts

    Yes Yes Yes Yes

    Export TRM product catalog data

    Yes Yes Yes Yes

    View TRM products, categories, phases, technical debt, and lifecycle timelines

    Yes Yes Yes Yes Yes

    Run the scheduled job to sync TRM product names with linked SAM software product names

    Yes

    Requires the admin role. Run on demand from All > System Definition > Scheduled Jobs.

    Enterprise modeling and visualization

    Enterprise modeling and visualization lets users create, manage, and publish architecture diagrams.

    Capability admin sn_apm.apm_admin sn_apm.apm_analyst sn_apm.apm_user sn_apm.apm_read Notes

    Approve or reject modeling diagram requests

    Yes Yes Yes

    Must be in the Enterprise Architect group

    View shape library configurations, entity configurations, modeling configuration, and relationship definitions

    Yes Yes Yes

    Must be in the Enterprise Architect group

    Create empty diagrams and synchronize them with the ServiceNow database

    Yes Yes Yes Yes

    Create business capability maps (BC maps), business application maps (BA maps), and business process maps (BP maps)

    Yes Yes Yes Yes

    Create ArchiMate diagrams, AWS architecture diagrams, and CSDM diagrams

    Yes Yes Yes Yes

    Add, remove, group, ungroup, expand, collapse, and delete shapes

    Yes Yes Yes Yes

    Add related records to shapes; add labels to connector lines

    Yes Yes Yes Yes

    Reorder shapes in a category; show or hide the Shapes panel; toggle between grid and list view; filter shapes

    Yes Yes Yes Yes

    Save a diagram as new; duplicate a diagram

    Yes Yes Yes Yes

    Submit a diagram for approval; synchronize a diagram and individual shapes

    Yes Yes Yes Yes

    Share a diagram; download a diagram; add or edit diagram version details; delete a diagram

    Yes Yes Yes Yes

    Create and manage custom shape libraries, custom shape elements, and custom shape actions; store images in the database for custom shapes

    Yes Yes Yes Yes

    Modify BPMN diagrams

    Yes Yes Yes Yes

    Set relationship type on a connector; set connector line style, arrowhead style, and icon for non-ArchiMate and mixed connectors; swap connector direction; add a label to a connector

    Yes Yes Yes Yes

    Requires Owner or Editor access to the diagram

    Align shapes to a common edge or center; distribute shapes at equal spacing

    Yes Yes Yes Yes

    Requires Owner or Editor access to the diagram. Not available in business capability map diagrams.

    View diagrams and diagram details

    Yes Yes Yes Yes Yes

    Application rationalization

    Application rationalization helps users assess and manage business applications through bubble chart and list views.

    Capability admin sn_apm.apm_admin sn_apm.apm_analyst sn_apm.apm_user sn_apm.apm_read Notes

    Analyze business applications in the bubble chart view by capability

    Yes Yes Yes Yes

    Create demands from the bubble chart view and list view

    Yes Yes Yes Yes

    Set the planned disposition of a business application

    Yes Yes Yes Yes

    Add and edit business application lifecycle data

    Yes Yes Yes Yes

    Edit business application details from the bubble chart and list views

    Yes Yes Yes Yes

    Edit demands and projects associated with a business application

    Yes Yes Yes Yes

    Update the system property to change the number of bubbles displayed

    Yes Yes Yes Yes

    Apply filters on the application rationalization view

    Yes Yes Yes Yes

    Export application rationalization list data

    Yes Yes Yes Yes

    View application rationalization data in bubble chart and list views

    Yes Yes Yes Yes Yes

    Data certification

    Data certification provides a governance mechanism to promote that architecture data is accurate and complete.

    Capability admin sn_apm.apm_admin sn_apm.apm_analyst sn_apm.apm_user sn_apm.apm_read Notes

    Create data certification policies using the certification policy wizard

    Yes Yes Yes Yes

    Requires system admin, CMDB admin, and sn_apm.apm_analyst

    Publish draft certification policies

    Yes

    Run data certification policies

    Yes

    Activate and deactivate certification policies; delete certification policies

    Yes

    Track certification progress across policies

    Yes

    Review and certify data certification tasks assigned to them

    Yes Yes Yes Yes

    User must be assigned a certification task

    Fail records that do not meet certification standards

    Yes Yes Yes Yes

    User must be assigned a certification task

    Reassign certification tasks to other users or groups; request reassignment

    Yes Yes Yes Yes

    User must be assigned a certification task

    Submit completed certification reviews

    Yes Yes Yes Yes

    User must be assigned a certification task

    View certification policies and certification status

    Yes Yes Yes Yes Yes

    Dashboards

    Dashboards provide visibility into application health, assessment scores, and portfolio performance.

    Capability admin sn_apm.apm_admin sn_apm.apm_analyst sn_apm.apm_user sn_apm.apm_read Notes

    View and monitor the Applications Assessment dashboard

    Yes Yes Yes

    View and monitor the Application 360 dashboard

    Yes Yes Yes

    View the workspace home dashboard and portfolio overview and health section

    Yes Yes Yes Yes

    Apply filters on the portfolio overview and health view

    Yes Yes Yes Yes

    View dashboards

    Yes Yes Yes Yes Yes

    Total Cost of Ownership (TCO)

    Total Cost of Ownership tracks and manages direct and indirect costs associated with business applications.

    Capability admin sn_apm.apm_admin sn_apm.apm_analyst sn_apm.apm_user sn_apm.apm_read Notes

    Activate the App TCO plugin

    Yes

    Create TCO sources, TCO source cost types, and TCO cost types

    Yes

    Set properties for TCO dashboards

    Yes

    View all TCO records for business applications

    Yes Yes Yes Yes

    create TCO records

    Yes Yes Yes Yes

    View TCO records

    Yes Yes Yes Yes Yes

    Publishing Center

    The Publishing Center lets administrators publish TRM catalog data to a knowledge base for consumption through a service portal.

    Capability admin sn_apm.apm_admin sn_apm.apm_analyst sn_apm.apm_user sn_apm.apm_read Notes

    Create and modify TRM catalog publishing configurations

    Yes Yes Yes Yes

    Requires sn_apm.apm_admin and knowledge_admin

    Configure TRM data to publish; manage article configurations

    Yes Yes Yes Yes

    Requires sn_apm.apm_admin and knowledge_admin

    Associate portals with a TRM catalog knowledge base

    Yes Yes Yes Yes

    Requires sn_apm.apm_admin and knowledge_admin

    Enable automatic synchronization of published catalogs

    Yes Yes Yes Yes

    Requires sn_apm.apm_admin and knowledge_admin

    Publish and republish TRM catalogs to the knowledge base

    Yes Yes Yes Yes

    Requires sn_apm.apm_admin and knowledge_admin

    Retire and archive published TRM catalogs; view publishing run logs

    Yes Yes Yes Yes

    Requires sn_apm.apm_admin and knowledge_admin

    Access published TRM catalog content through the service portal

    Yes Yes Yes Yes Yes

    Architecture Analyzer

    The Architecture Analyzer lets users explore and visualize relationships between architectural entities on an interactive canvas.

    Capability admin sn_apm.apm_admin sn_apm.apm_analyst sn_apm.apm_user sn_apm.apm_read Notes

    create explorations on the Architecture Analyzer canvas

    Yes Yes Yes Yes

    Add entities to the canvas by selecting entity type and specific record

    Yes Yes Yes Yes

    Add upstream and downstream related entities to a selected entity on the canvas

    Yes Yes Yes Yes

    Show or hide the left navigation pane and the Add to canvas panel

    Yes Yes Yes Yes

    Clear all entities from the canvas

    Yes Yes Yes Yes

    Download an exploration canvas as an image

    Yes Yes Yes Yes

    Rename an exploration; delete an exploration

    Yes Yes Yes Yes

    View existing explorations

    Yes Yes Yes Yes Yes

    AI systems — AI Control Tower integration

    The AI systems integration surfaces AI governance data from AI Control Tower directly on business application records. Viewing full AI system records in AI Control Tower requires roles from the AI Control Tower application in addition to EA Workspace roles.

    Capability admin sn_apm.apm_admin sn_apm.apm_analyst sn_apm.apm_user sn_apm.apm_read Notes

    View the AI systems tab on a business application record

    Yes Yes Yes Yes

    View AI system details including lifecycle phase, state, lifecycle status, and risk classification

    Yes Yes Yes Yes

    Add an existing AI Control Tower AI system to a business application

    Yes Yes Yes Yes

    Remove an AI system association from a business application

    Yes Yes Yes Yes

    Open and view the full AI system record in the AI Control Tower workspace

    Yes Yes Yes Yes

    Requires sn_ai_governance.ai_governance_workspace_user (AI Control Tower role)

    View full AI system governance details in AI Control Tower, including related models, datasets, prompts, approval history, and lifecycle tasks

    Yes Yes Yes Yes

    Requires sn_aig.ai_steward or sn_aig.ai_asset_owner (AI Control Tower roles)

    Manage AI system associations with business applications from the AI Control Tower side

    Yes Yes Yes Yes

    Requires sn_aig.ai_steward or sn_aig.ai_asset_owner (AI Control Tower roles)

    View the AI systems tab on a business application record

    Yes Yes Yes Yes Yes

    My Entities

    My Entities provides a personalized view of the records you own or manage, across all portfolio types.

    Capability admin sn_apm.apm_admin sn_apm.apm_analyst sn_apm.apm_user sn_apm.apm_read Notes

    View and manage your business capabilities, business processes, and business applications

    Yes Yes Yes Yes

    View and manage your application services, information objects, and architectural artifacts

    Yes Yes Yes Yes

    View and manage your TRM products, digital integrations, and digital interfaces

    Yes Yes Yes Yes

    View your assigned entities

    Yes Yes Yes Yes Yes