---
sourceDocument: Australia Build or modify applications
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/application-development

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Build or modify applications

ft:clusterId :

    - cadev

bundleId :

    - cadev

workflow :

    - Development, Data, and Analytics


---

# Roles and personas

# Creator Studio roles and personas {#ariaid-title1}

Release version: Australia  
Updated March 12, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 5 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Creator Studio roles and personas

Creator Studio roles in ServiceNow control user permissions related to app creation and management within the platform.
By assigning appropriate roles, administrators can regulate who can create, manage, or collaborate on apps, preventing redundant or unused applications in the instance.
The roles also support collaboration workflows and compatibility across different instance versions.
Show full answer Show less  

## Key Personas and Their Roles

* **Low-code/Citizen Developer:** Tech-savvy users without formal development training who can submit app ideas and build apps if approved. They have either the `sncreatorstudio.user` or `sncreatorstudio.restricteduser` roles.
* **App Engine Admin:** Oversees app development processes, approves app requests, manages collaborators, and typically has the `appengineadmin` role within the corresponding admin group.
* **Security Admin:** Manages platform-level roles and access control lists, essential for updating Creator Studio roles.
* **System Administrator:** Has unrestricted access to all system features and data; high-level privileges should be assigned cautiously, especially for sensitive data.

## Roles and Permissions in Creator Studio

* **Creator Studio User (`sncreatorstudio.user`):** Can create apps and is automatically designated as app owner with delegated development rights.
* **Creator Studio Restricted User (`sncreatorstudio.restricteduser`):** Cannot create apps but can request app creation and collaborate on apps they are assigned to.
* **App Engine Admin (`appengineadmin`):** Approves app creation and collaboration requests and manages development environments.
* **ServiceNow Otto for Creator (`now.assist.creator`):** Grants access to AI-powered form creation skills.
* **Granular Admin Roles:** Include configuration admin, task admin, app configurator, and reports viewer roles that provide focused administrative capabilities over app tasks, configuration, and reporting.

## User Groups and Access Management

Creator Studio user groups simplify access control:

* **Creator Studio Users:** Automatically approved to create apps; assigned the `sncreatorstudio.user` role.
* **Creator Studio Restricted Users:** Must request app creation; assigned the `sncreatorstudio.restricteduser` role.

## Collaboration and Testing Considerations

* Users with Creator Studio roles cannot test apps in non-production Request App Workspace but can preview apps within Creator Studio.
* Fulfillment of requests requires additional roles (e.g., `xacmeuserapp.agent`) that must be assigned by administrators.
* Collaboration workflows depend on matching plugin versions between non-production and production instances; assigning the `catalogbuildereditor` role to Creator Studio user groups ensures compatibility.
* App collaboration is managed per app by inviting collaborators or requesting access.  
Roles control what everyone you work with can do in Creator Studio. Administrators assign roles to give team members permission to configure or use Creator Studio.
The two roles for Creator Studio are used to restrict access from creating new apps, which helps make sure your instance isn't overfilled with redundant, unplanned, or unused apps.

## Personas that use Creator Studio {#roles-creator-studio__section_pps_54b_v1c}

Personas aren't explicitly part of Creator Studio, but administrators assign roles to give team members permission to configure or use Creator Studio.  

Low-code/citizen developer
:   Low-code/citizen developers are tech savvy and interested in creating apps. Though they might not have formal coding or app development training, citizen developers can submit ideas for new apps and, if approved, build them
    using Creator Studio.

    Low-code/citizen developers have either the sn_creatorstudio.user or sn_creatorstudio.restricted_user role.

App Engine admin
:   App Engine admins manage all processes related to app development in Creator Studio. They review new app ideas, handle app deployment, and manage collaborators, usually in the App Engine Management Center.

    App Engine admins have the app_engine_admin role and must be in the app_engine_admin group.

Security admin
:   The security admin creates and modifies roles and access control lists for apps. This role is set on the platform level, and it is required for making updates to roles in Creator Studio.

System administrator
:   The system administrator has access to all system features, functions, and data, regardless of security constraints. Grant this privilege carefully. If you have sensitive information, such as HR records, that you must
    protect, create a custom admin role for that area and train a person who is authorized to see those records to act as the administrator.

## Roles and what they can do in Creator Studio {#roles-creator-studio__section_jwt_rjq_h1c}

In addition to the roles in the following table, users with the admin and delegated_developer roles can also access Creator Studio.

For complete details on which roles each role contains, see [Components installed with Creator Studio](https://servicenow-prod.fluidtopics.net/qZQL5wOiNpq6z~~gEesUIg "When you activate the Creator Studio plugin, various components like tables and user roles are automatically installed.").  
{#roles-creator-studio__table_zbp_qgq_h1c__entry__3}

| Role | Name | Description |
|-|-|-|
| Creator Studio User | sn_creatorstudio.user | * Users can create apps in Creator Studio. * The user is automatically delegated as the app owner. For more information, see [Delegated development and deployment](https://servicenow-prod.fluidtopics.net/puoonuu7YQnaAqcFsxmASg "Delegated development allows designated users without a system admin role to develop or deploy applications on the ServiceNow AI Platform."). * Contains sn_g_app_creator.app_creator. {#roles-creator-studio__ul_bd3_bhq_h1c} Note: This role gets assigned the delegated_developer role when they create or get access to an app. |
| Creator Studio Restricted User | sn_creatorstudio.restricted_user | * Users can't create apps in Creator Studio. * Users can request apps to be created for them, and to work on an app. * Users can work on apps that they've been designated as developers for. * When assigned to work on an app, this user gets the delegated_developer role for that app. {#roles-creator-studio__ul_gs1_vhq_h1c} |
| App Engine Admin | app_engine_admin | * Approve requests from restricted users to create an app. * Approve collaboration requests. * Select other development environments from the experience switcher. * Contains sn_creator_studio.admin_write and sn_creator_studio.basic_write to enable admins to see the apps they need to approve. {#roles-creator-studio__ul_xnc_2jq_h1c} |
| ServiceNow Otto for Creator | now.assist.creator | Grants users access to AI skills to create forms in Creator Studio. |
| Creator Studio configuration admin | sn_creatorstudio.configuration_admin | Granular admin role that contains the following Creator Studio granular admin roles: * sn_creatorstudio.task_admin * sn_creatorstudio.app_configurator * sn_creatorstudio.reports_viewer {#roles-creator-studio__ul_n5h_rjd_tgc}For more information on working with granular roles, see [Granular admin roles](https://www.servicenow.com/docs/access?context=granular-admin-roles&version=australia&pubname=australia-platform-security&ft:locale=en-US). |
| Task admin | sn_creatorstudio.task_admin | Granular admin role that grants users access to change several fields on the Request Task table or a table that extends Request Task. This role contains the following: * Table-level access for sn_creatorstudio_task: Create, Write, Delete * Field-level access for: * sn_creatorstudio_task.request_type, which enables you to change the associated form * sn_creatorstudio_child_task.parent, which enables you to change the parent table for any subtask tables created from a task activity added to an app's playbook. {#roles-creator-studio__ul_znr_gld_tgc} {#roles-creator-studio__ul_wds_2ld_tgc} |
| App configurator | sn_creatorstudio.app_configurator | Granular admin role that grants users access to change the associated table for an app built in Creator Studio. |
| Reports viewer | sn_creatorstudio.reports_viewer | Granular admin role that grants users access to run reports on tables. |
[Table 1. Creator Studio roles]

{#roles-creator-studio__table_zbp_qgq_h1c}  
Note:  
To ensure that users can use the Collaboration Approval Workflow regardless of instance versions, admins must assign the catalog _builder_editor role to Creator Studio user groups.

## User groups and what they can do in Creator Studio {#roles-creator-studio__section_ixt_sjq_h1c}

Groups are a standard functionality that help you quickly control people's access to Creator Studio by adding them to a group.  
{#roles-creator-studio__table_dgw_vjq_h1c__entry__2}

| Group | Description |
|-|-|
| Creator Studio Users | * Users are automatically approved to create apps in Creator Studio. * Contains sn_creatorstudio.user. {#roles-creator-studio__ul_ehg_wlq_h1c} |
| Creator Studio Restricted Users | * Users in this group need to request applications be created in Creator Studio on their behalf. * Contains sn_creatorstudio.restricted_user. {#roles-creator-studio__ul_ym4_cmq_h1c} |
[Table 2. Creator studio user groups]

{#roles-creator-studio__table_dgw_vjq_h1c}

## Developer roles and testing apps on instances {#roles-creator-studio__id_ndc_htx_y1c}

If you have a Creator Studio role of sn_creatorstudio.user or sn_creatorstudio.restricted_user, you won't be able to test the apps you build on the non-production instance's Request App Workspace. You should be able to test the
app on the non-production instance using Creator Studio's app previews. You will be able to test the apps as a fulfiller in the workspace on the app that's been deployed to production.  
Use case:  
Let's say that a user is in the Creator Studio Users group, so when that user builds an app, that user gets delegated development permissions for that app. That user can then publish a request form, and if there are no roles required for the
form, that user can submit requests with the form.

However, that user won't be able to fulfill requests or access the Request App Workspace because that user won't have the x_acme_user_app.agent role, and that user can't give that role to themself. Administrators must assign
additional roles as necessary.

## Collaboration roles and instances on different versions {#roles-creator-studio__id_y4n_14f_p1c}

As admins implement Creator Studio, they may have it installed on a non-production instance while their production instance is on a previous version of the ServiceNow AI Platform that doesn't have Creator Studio. This mis-match of instance versions affects the Collaboration Approval Workflow, which specifies the non-production instance as the source and the production instance as the controller. If the
controller doesn't have the version of the collaboration plugin that supports Creator Studio, collaboration is unsupported.

To ensure that users can use the Collaboration Approval Workflow regardless of instance versions, admins must assign the catalog _builder_editor role to Creator Studio user groups.{#roles-creator-studio__cs-cb-permission-collab}

## Roles and app development collaboration {#roles-creator-studio__section_myh_5yr_m1c}

Roles define user access to Creator Studio. Permission to work on individual apps is controlled on an app-by-app basis. That is, you must manage the collaborators for each app by inviting other citizen developers to work on the app with you,
or request to join someone else's app. For more information, see [Collaborating with others to build apps in Creator Studio](https://servicenow-prod.fluidtopics.net/TYt6tmoUiJOV0Wb_IwrQhA "Sometimes you need help with building out your app, and that’s OK! And sometimes other people need your help building their apps, which is great! This point is where collaboration comes into play.").

