AI Control Tower roles
Summarize
Summary of AI Control Tower roles
The AI Control Tower roles are designed to support the governance, management, and risk compliance of AI systems within an enterprise using ServiceNow. These roles are installed with the AI Control Tower and AI Risk and Compliance applications, enabling organizations to manage AI assets, enforce policies, conduct risk assessments, and oversee AI cases effectively.
Show less
AI Control Tower Roles
- AI Steward: Assigned by the organization, this role has extensive permissions to configure and manage AI Control Tower initiatives, including AI asset lifecycle management, policy adherence, playbook creation, third-party LLM/SLM configuration, multi-instance management, and approval workflows. It also involves activating hyperscaler connections for AI discovery and managing AI Gateway MCP server settings.
- AI Control Tower Workspace User: Responsible for owning and managing AI assets with exclusive access to the AI portfolio tab and the AI Control Tower homepage.
- AI Asset Owner: Ensures AI assets are accurately represented and maintained throughout their lifecycle, manages AI systems, models, datasets, and prompts, and updates deployment phases. They have access to overview, value, and adoption tabs within the AI Control Tower.
AI Risk and Compliance Roles
- AI Risk and Compliance Admin: Manages setup of risk and impact assessment frameworks, configures methodologies and templates, defines automation rules, profiles AI case types, deletes AI systems, and manages entity-based access settings (requires GRC Entity Based Access application).
- AI Risk and Compliance Manager: Has full access to AI systems, can initiate impact and risk assessments, manage AI system lifecycles, perform control attestations, and manage bulk access updates (requires GRC Entity Based Access application).
- AI Risk and Compliance Analyst: Performs impact and risk assessments and manages AI system lifecycles on assigned records only.
- AI Risk and Compliance Business User: Creates AI cases via Employee Center, works on assigned tasks, and performs control attestations.
- AI Risk and Compliance Reader: Read-only access to AI systems and impact assessments.
- AI System Reader: Read access to AI systems within both AI Control Tower and AI Risk and Compliance workspaces.
AI Case Management Roles
- AI Case Business User: Can create AI cases and inquiries from the Employee Center.
- AI Case Analyst: Reviews assigned AI cases and inquiries, identifies impacted areas, compliance risks, and manages issue resolution.
- AI Case Manager: Reviews all AI cases and inquiries along with associated information.
- AI Case Admin: Manages AI case type profiles, sets up assignment rules, and can delete AI cases.
Practical Implications for ServiceNow Customers
Understanding and assigning these roles correctly ensures proper governance and lifecycle management of AI assets, risk and compliance assessments, and effective handling of AI-related cases within ServiceNow. The roles provide a framework to distribute responsibilities across organizational teams, enabling streamlined AI governance aligned with enterprise policies and regulatory requirements.
Certain roles are installed along with the installation of the AI Control Tower.This section also covers roles which are installed with AI Risk and Compliance.
| Role title [name] | Description | Contains roles |
|---|---|---|
| AI steward [sn_ai_governance.ai_steward] |
Note:
The organization decides on assigning the AI steward role. By adding the users to the AI stewards group, allows user to have additional permissions related to playbook. The AI steward is responsible for:
For AI discovery:
For AI Gateway:
|
|
| AI Control Tower Workspace user [sn_ai_governance_workspace_user] |
The AI Control Tower Workspace user is responsible for:
|
None |
| AI asset owner [sn_ai_asset_mgmt.ai_asset_owner] |
The AI asset owner is responsible for:
|
None |
AI AI Risk and Compliance roles
The AI Risk and Compliance application installs the essential role to perform respective day-to-day operational tasks for managing AI systems across the enterprise.
| Role title [name] | Description | Contains roles |
|---|---|---|
|
AI Risk and Compliance Admin [sn_grc_ai_gov.ai_risk_and_compliance_admin] |
The AI Risk and Compliance Admin can perform the following tasks:
|
|
|
AI Risk and Compliance Manager [sn_grc_ai_gov.ai_risk_and_compliance_manager] |
The AI Risk and Compliance Manager can access all AI systems on the system and perform the following tasks:
|
|
|
AI Risk and Compliance Analyst [sn_grc_ai_gov.ai_risk_and_compliance_analyst] |
The AI Risk and Compliance Analyst can access all AI systems assigned to them in the system and perform the following tasks only on the assigned records:
|
|
|
AI Risk and Compliance Business User [sn_grc_ai_gov.ai_risk_and_compliance_business_user] |
The AI Risk and Compliance User can perform the following tasks:
|
Note: For more information on AI Control Tower roles, see AI Control Tower roles. |
|
AI Risk and Compliance Reader [sn_grc_ai_gov.ai_risk_and_compliance_reader] |
The AI Risk and Compliance Reader can have read access to the AI systems and AI impact assessments. |
|
|
AI System Reader [sn_grc_ai_gov.ai_risk_and_compliance_ai_system_reader] |
The AI System Reader can have read access to the AI systems on AI Control Tower workspace and AI Risk and Compliance workspace. | NA |
|
AI Case Business User [sn_ai_case_mgmt.ai_case_business_user] |
The AI Case Business User can create AI case and AI inquiry on the Employee Center. | sn_grc_case_mgmt.grc_case_business_user |
|
AI Case Analyst [sn_ai_case_mgmt.ai_case_analyst] |
The AI Case Analyst can review the AI cases and AI inquiries assigned to them in the system and perform the following tasks only on the assigned records:
|
|
|
AI Case Manager [sn_ai_case_mgmt.ai_case_manager] |
The AI Case Manager can review all the AI cases, AI inquiries, and its associated information. |
|
|
AI Case Admin [sn_ai_case_mgmt.ai_case_admin] |
The AI Case Admin can manage type profiles to segregate AI cases. They can set up assignment rules and delete AI cases. |
|