Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Components installed with ITSM Roles - Change Management

Several user roles are installed with the activation of the ITSM Roles — Change Management plugin (com.snc.itsm.roles.change_management). Security ACLs to support the security model for Change Management and related functionality are also installed.

When you install the ITSM Roles — Change Management plugin (com.snc.itsm.roles.change_management), the plugin updates the Security Access Control Lists (ACLs), integrating revised scripts, and other files to overhaul the security model for these applications.

Note: The Application Files table lists the components that are installed with this application. For instructions on how to access this table, see Find components installed with an application.

Roles installed

Role title \[name\]DescriptionContains roles
Change admin\[sn\_change\_admin\]Provides configuration and authorization access for system properties in the Change Management application. Provides a granular, application-specific write access replacing the global admin role.- sn\_change\_write - sn\_change\_cab.cab\_manager - change\_manager
   
Change read\[sn\_change\_read\]Read access to the Change Management application and related records.Note: A user with the sn_change_read role can view all change requests as well as the CAB workbench.- sn\_cmdb\_user - dependency\_views - view\_changer - cmdb\_read - app\_service\_user - cmdb\_query\_builder\_read
Change write\[sn\_change\_write\]Write access to the Change Management application and related records.- sn\_change\_read - template\_editor - cmdb\_query\_builder
Incident read\[sn\_incident\_read\]Read access to the Incident Management application and related records.Note: An ESS user (user with no role) can view only those incidents that they create or someone else creates on their behalf. A user with the sn_incident_read role can view all incidents as well as the major incident workbench.- dependency\_views - agent\_workspace\_user - view\_changer - cmdb\_read - cmdb\_query\_builder\_read
Incident write\[sn\_incident\_write\]Write access to the Incident Management application and related records.- sn\_incident\_read - template\_editor
Problem read\[sn\_problem\_read\]Read access to the Problem Management application and related records.NA
Problem write\[sn\_problem\_write\]Write access to the Problem Management application and related records.- sn\_problem\_read - template\_editor
sn\_request\_readRead access to the Request (sc_request) or Requested Item (sc_req_item) only for a user who is also an approver of the request or requested item.Note: As there are future updates expected for the sn_request_read role, do not assign it to users without the business_stakeholder role.NA
sn\_request\_writeWrite access to the Request \(sc\_request\) or Requested Item \(sc\_req\_item\).- task\_editor - dependency\_views - agent\_workspace\_user - view\_changer - cmdb\_read - cmdb\_query\_builder\_read - sn\_request\_read
sn\_request\_comment\_writeWrite access to the comments for the Requested Item (sc_req_item).Note: The sn_request_comment_write role alone does not give access to comments write, you will need write access for the table.NA
\[sn\_service\_desk\_agent\]Enables gathering, and verifying information, as well as delivering quick resolutions for tier 1 service desk agents. This user role is available when the ITSM Roles plugin \(com.snc.itsm.roles\) is installed.- sn\_incident\_write - sn\_problem\_write - sn\_change\_write - sn\_request\_write - tracked\_file\_reader With the installation of the ITSM Gen AI \(com.sn.itsm.gen.ai\) plugin, the following roles are also available: - knowledge\_user - now\_assist\_panel\_user

Parent Topic:Request ITSM Roles- Change Management