Skip to content
Release: Australia · Updated: 2025-01-30 · Official documentation · View source

Roles in Service Operations Workspace for ITSM

You can configure the user access for Service Operations Workspace (SOW) pages using various roles.

Important: Install and activate the ITSM Roles plugin (com.snc.itsm.roles) before assigning the SOW user roles. Without this plugin, role inheritance chains such as (sn_incident_read inheriting sn_sow.sow_home and sn_sow.sow_list) may not function correctly and users may not be able to access the SOW workspace even with the expected roles assigned.

RoleDescriptionInherited roles
itilProvides access to all SOW pages.sn\_sow.sow\_user
sn\_sow.sow\_userProvides access to SOW. By default, the itil role contains the sn\_sow.sow\_user. In case a user has roles other than itil, ensure that sn\_sow.sow\_user role is assigned to the user to access SOW.None
sn\_sow.sow\_homeProvides access to SOW home \(landing\) page.sn\_sow.sow\_user
sn\_sow.sow\_listProvides access to SOW list pages.sn\_sow.sow\_user
adminProvides access to all the pages in SOW including SOW Admin Center.A user with this role can perform configurations for all modules in SOW Admin Center.None
sn\_sow\_itsm\_admin.sow\_admin\_userProvides access to SOW Admin Center pages for SOW configuration. A user with this role can perform configurations related to Incident Management only.None
sn\_sow\_admin.sow\_admin\_center\_userEnables change managers to access the SOW Admin Center page. Change managers can use configurations for change features like modern change adoption, change models, DevOps change automation, and so on.sn\_ace.ace\_user
awa\_agentProvides access to inbox in SOW.None
sn\_sow.it\_agent\_dashboard\_userProvides access to IT Agent Dashboard.None
Service desk agent\[sn\_service\_desk\_agent\]Enables gathering, and verifying information, as well as delivering quick resolutions for tier 1 service desk agents. This user role is available when the ITSM Roles plugin \(com.snc.itsm.roles\) is installed.- sn\_incident\_write - sn\_problem\_write - sn\_change\_write - sn\_request\_write - tracked\_file\_reader With the installation of the ITSM Gen AI \(com.sn.itsm.gen.ai\) plugin, the following roles are also assigned: - knowledge\_user - now\_assist\_panel\_user
Incident Management
sn\_incident\_readProvides the read access to incident record pages.sn\_sow.sow\_home and sn\_sow.sow\_listSo, users with the sn\_incident\_read role can access the SOW home \(landing\) and list pages.
sn\_incident\_writeProvides the write access to incident record pages.sn\_sow.sow\_home and sn\_sow.sow\_listSo, users with the sn\_incident\_write role can access the SOW home \(landing\) and list pages.
Problem Management
problem\_task\_analystWorks on a problem task and manages it through its life cycle.None
problem\_coordinatorWorks on a problem or problem task and manages it through its life cycle.itil and problem\_task\_analyst
problem\_managerResponsible for the overall Problem Management process and can configure Problem Management settings, as well as act as a problem coordinator.problem\_coordinator
problem\_adminA problem manager who can also delete problems and problem tasks.problem\_manager
sn\_problem\_readProvides the read access to problem record pages.sn\_sow.sow\_home and sn\_sow.sow\_list allow users with the sn\_problem\_read role to access the SOW home \(landing\) and list pages.
sn\_problem\_writeProvides the write access to problem record pages.sn\_sow.sow\_home and sn\_sow.sow\_list enable users with the sn\_problem\_write role to access the SOW home \(landing\) and list pages.
Change Management
sn\_change\_readProvides the read access to change record pages.sn\_sow.sow\_home and sn\_sow.sow\_listSo, users with the sn\_change\_read role can access the SOW home \(landing\) and list pages.
sn\_change\_writeProvides the write access to change record pages.sn\_sow.sow\_home and sn\_sow.sow\_listSo, users with the sn\_change\_write role can access the SOW home \(landing\) and list pages.
change\_managerProvides access to configurations related to Change Management in SOW Admin Center.- sn\_sttrm\_attribute\_read - sn\_sttrm\_condition\_read - sn\_chg\_soc.change\_soc\_admin - personalize\_decision\_table\_input - sn\_sow\_admin.sow\_admin\_center\_user - itil
sn\_devops.viewerProvides access to view or add DevOps data to a change request.None
Request Management
sn\_request\_readProvides the read access to request record pages.sn\_sow.sow\_home and sn\_sow.sow\_listSo, users with the sn\_request\_read role can access the SOW home \(landing\) and list pages.
sn\_request\_writeProvides the write access to request record pages.sn\_sow.sow\_home and sn\_sow.sow\_listSo, users with the sn\_request\_read role can access the SOW home \(landing\) and list pages.
On-call Scheduling
oc\_readProvides the read access to Schedules page.Users with the oc\_read role can access the On-call Schedules, Experts On-call, Escalation Tracking, and other On-call features in Service Operations Workspace.

Tip: If the user has a role that inherits SOW access (such as sn_incident_read) but cannot access the workspace, verify that:

  • id="ul_access_troubleshoot"
  • The ITSM Role plugin com.snc.itsm.roles is installed and active.
  • The user was assigned the role directly or via group membership.
  • No custom ACL is overriding the default role-based access for SOW pages.
  • For ACL-level issues, contact ServiceNow Support.