---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Enforce application scope restrictions \[New in Security Center 1.3 and removed in 1.5\]

# Enforce application scope restrictions \[New in Security Center 1.3 and removed in
1.5\] {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 Minute Lesedauer

Use the glide.record.legacy_cross_scope_access_policy_in_script property to control the permissions of scoped apps.
If the glide.record.legacy_cross_scope_access_policy_in_script property is set to true, scoped apps can call APIs which should only be available to global apps. This property bypasses the intended access
controls for creating and updating developers for those scoped apps.

## More information {#sc-enforce-application-scope-restrictions__section_qhx_1b1_xwb}

{#sc-enforce-application-scope-restrictions__table_ajc_b43_3kb__entry__2}

| Attribute | Description |
|-|-|
| Configuration name | glide.record.legacy_cross_scope_access_policy_in_script |
| Configuration type | System Properties (/sys_properties_list.do) |
| Data type | Boolean |
| Recommended value | false |
| Default value | true (when the property does not exist in the sys_properties table.) |
| Category | [Access control](https://servicenow-prod.fluidtopics.net/xAmazkRh5FKyeb7q4TQGWw "The access control category audits the process of protecting resources from unauthorized access through granting and denying requests based on a permission model. This includes ensuring an entity accessing a resource holds valid credentials to do so, creating and protecting a well-defined set of roles or permissions and ensuring role or permission controls are protected from replay and tampering.") |
| Security risk | * Severity score: 3.5 * CVSS score: Low * Security risk details: If this property is not set to the recommended value, then scoped apps and delegated developers for those scoped apps can create and update records in global tables such as Incident. {#sc-enforce-application-scope-restrictions__ul_g1g_3sf_xwb} |
| Dependencies and prerequisites | None |
[ ]

{#sc-enforce-application-scope-restrictions__table_ajc_b43_3kb}

