Walk-up Experience portal security and access
Summarize
Summary of Walk-up Experience portal security and access
The Walk-up Experience on-site portal in ServiceNow is designed with built-in security to ensure that users accessing the portal through end-user facing devices do not receive elevated role privileges. The portal is accessed by accounts that have thesnwalkup.walkuploginrole only, safeguarding the environment from unauthorized access.
Show less
Key Features
- Explicit Role Plugin: Activation of the Explicit Role (com.glide.explicitroles) plugin is required to assign security roles—either sncinternal or sncexternal—to users. This plugin was introduced in the Paris release of ServiceNow AI Platform.
- Role Assignment Behavior: For new Walk-up Experience installations (starting from the Quebec release), the plugin explicitly sets the Walk-up Experience user as an external user (sncexternal role). However, during upgrades prior to the Yokohama release, the Walk-up Experience user is assigned sncinternal due to plugin behavior, and this role cannot be removed automatically during upgrade.
- Access Control: Users with the snwalkup.walkuplogin role, such as agents opening the on-site Walk-up location or support team members, can log into the Walk-up Experience portal. Both internal and external users can access the portal via check-in devices like tablets to enter queues. Internal authenticated users also have the option to check in online via desktop or mobile devices.
Important Upgrade Considerations for Yokohama Release
- When upgrading to the Yokohama release, the Explicit Role plugin assigns the Walk-up Experience user the sncinternal role instead of sncexternal. This occurs because all users receive the sncinternal role by default, and the upgrade process cannot remove it automatically.
- For new installations of Walk-up Experience on Yokohama, this process is seamless because the Explicit Role plugin installs first and assigns the correct roles automatically.
- After upgrading to Yokohama, administrators must manually remove the sncinternal role from the Walk-up Experience user accounts and add the sncexternal role. This manual adjustment is necessary only for upgrades to Yokohama and not for future releases.
Practical Implications for ServiceNow Customers
Understanding the role assignments and plugin dependencies is critical to maintaining secure and proper access to the Walk-up Experience portal. Customers performing upgrades to Yokohama should plan to adjust user roles manually to ensure users have the correct external role and avoid unintended elevated privileges. For new installations, the process is automated, simplifying setup and security management.
This guidance helps ensure that both internal and external users can securely access the portal and use check-in devices or online check-in options without compromising security policies.
Security is built into the application to prevent end-user facing devices at the Walk-up Experience on-site portal from offering elevated role privileges to users. The Walk-up Experience on-site portal is accessed by an account containing only the sn_walkup.walkup_login role.
Understanding Walk-up Experience portal security
Activate the Explicit Role (com.glide.explicit_roles) plugin to assign users security roles, either snc_internal or snc_external. This plugin was introduced in the ServiceNow AI Platform Paris release. With the Quebec release, for new installations, Walk-up Experience added a dependency on this plugin to explicitly set the Walk-up Experience user as an external user.
Access to Walk-up Experience
Agents opening up the on-site Walk-up location for business, or joining the support team during operation hours, access the user record account with sn_walkup.walkup_login role to log into the Walk-up Experience portal. Internal and external users can access the on-site Walk-up Experience portal via a check-in device, typically a tablet, to enter a queue. Internal, authenticated users can also access an online queue check-in via desktop or mobile device.
Important information for upgrading Walk-up Experience to Yokohama
The Explicit Role (com.glide.explicit_roles) plugin was introduced in the ServiceNow AI Platform Paris release. When installed, users are assigned security roles, either snc_internal or snc_external. With the Yokohama, release Walk-up Experience has added a dependency on this plugin to explicitly set the Walk-up Experience user as an external user.