Roles in Service Operations Workspace for ITSM
You can configure the user access for Service Operations Workspace (SOW) pages using various roles.
Important: Install and activate the ITSM Roles plugin (com.snc.itsm.roles) before assigning the SOW user roles. Without this plugin, role inheritance chains such as (sn_incident_read inheriting sn_sow.sow_home and sn_sow.sow_list) may not function correctly and users may not be able to access the SOW workspace even with the expected roles assigned.
| Role | Description | Inherited roles |
|---|---|---|
| itil | Provides access to all SOW pages. | sn\_sow.sow\_user |
| sn\_sow.sow\_user | Provides access to SOW. By default, the itil role contains the sn\_sow.sow\_user. In case a user has roles other than itil, ensure that sn\_sow.sow\_user role is assigned to the user to access SOW. | None |
| sn\_sow.sow\_home | Provides access to SOW home \(landing\) page. | sn\_sow.sow\_user |
| sn\_sow.sow\_list | Provides access to SOW list pages. | sn\_sow.sow\_user |
| admin | Provides access to all the pages in SOW including SOW Admin Center.A user with this role can perform configurations for all modules in SOW Admin Center. | None |
| sn\_sow\_itsm\_admin.sow\_admin\_user | Provides access to SOW Admin Center pages for SOW configuration. A user with this role can perform configurations related to Incident Management only. | None |
| sn\_sow\_admin.sow\_admin\_center\_user | Enables change managers to access the SOW Admin Center page. Change managers can use configurations for change features like modern change adoption, change models, DevOps change automation, and so on. | sn\_ace.ace\_user |
| awa\_agent | Provides access to inbox in SOW. | None |
| sn\_sow.it\_agent\_dashboard\_user | Provides access to IT Agent Dashboard. | None |
| Service desk agent\[sn\_service\_desk\_agent\] | Enables gathering, and verifying information, as well as delivering quick resolutions for tier 1 service desk agents. This user role is available when the ITSM Roles plugin \(com.snc.itsm.roles\) is installed. | - sn\_incident\_write - sn\_problem\_write - sn\_change\_write - sn\_request\_write - tracked\_file\_reader With the installation of the ITSM Gen AI \(com.sn.itsm.gen.ai\) plugin, the following roles are also assigned: - knowledge\_user - now\_assist\_panel\_user |
| Incident Management | ||
| sn\_incident\_read | Provides the read access to incident record pages. | sn\_sow.sow\_home and sn\_sow.sow\_listSo, users with the sn\_incident\_read role can access the SOW home \(landing\) and list pages. |
| sn\_incident\_write | Provides the write access to incident record pages. | sn\_sow.sow\_home and sn\_sow.sow\_listSo, users with the sn\_incident\_write role can access the SOW home \(landing\) and list pages. |
| Problem Management | ||
| problem\_task\_analyst | Works on a problem task and manages it through its life cycle. | None |
| problem\_coordinator | Works on a problem or problem task and manages it through its life cycle. | itil and problem\_task\_analyst |
| problem\_manager | Responsible for the overall Problem Management process and can configure Problem Management settings, as well as act as a problem coordinator. | problem\_coordinator |
| problem\_admin | A problem manager who can also delete problems and problem tasks. | problem\_manager |
| sn\_problem\_read | Provides the read access to problem record pages. | sn\_sow.sow\_home and sn\_sow.sow\_list allow users with the sn\_problem\_read role to access the SOW home \(landing\) and list pages. |
| sn\_problem\_write | Provides the write access to problem record pages. | sn\_sow.sow\_home and sn\_sow.sow\_list enable users with the sn\_problem\_write role to access the SOW home \(landing\) and list pages. |
| Change Management | ||
| sn\_change\_read | Provides the read access to change record pages. | sn\_sow.sow\_home and sn\_sow.sow\_listSo, users with the sn\_change\_read role can access the SOW home \(landing\) and list pages. |
| sn\_change\_write | Provides the write access to change record pages. | sn\_sow.sow\_home and sn\_sow.sow\_listSo, users with the sn\_change\_write role can access the SOW home \(landing\) and list pages. |
| change\_manager | Provides access to configurations related to Change Management in SOW Admin Center. | - sn\_sttrm\_attribute\_read - sn\_sttrm\_condition\_read - sn\_chg\_soc.change\_soc\_admin - personalize\_decision\_table\_input - sn\_sow\_admin.sow\_admin\_center\_user - itil |
| sn\_devops.viewer | Provides access to view or add DevOps data to a change request. | None |
| Request Management | ||
| sn\_request\_read | Provides the read access to request record pages. | sn\_sow.sow\_home and sn\_sow.sow\_listSo, users with the sn\_request\_read role can access the SOW home \(landing\) and list pages. |
| sn\_request\_write | Provides the write access to request record pages. | sn\_sow.sow\_home and sn\_sow.sow\_listSo, users with the sn\_request\_read role can access the SOW home \(landing\) and list pages. |
| On-call Scheduling | ||
| oc\_read | Provides the read access to Schedules page. | Users with the oc\_read role can access the On-call Schedules, Experts On-call, Escalation Tracking, and other On-call features in Service Operations Workspace. |
Tip: If the user has a role that inherits SOW access (such as sn_incident_read) but cannot access the workspace, verify that:
- id="ul_access_troubleshoot"
- The ITSM Role plugin
com.snc.itsm.rolesis installed and active. - The user was assigned the role directly or via group membership.
- No custom ACL is overriding the default role-based access for SOW pages.
- For ACL-level issues, contact ServiceNow Support.