---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Enforce Security Scope for Agent Workspace for HR Case Management \[New in Security Center 1.5 and updated in 2.0\]

# Enforce Security Scope for Agent Workspace for HR Case Management \[New in Security Center
1.5 and updated in 2.0\] {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 Minute Lesedauer

Configure the Agent Workspace for HR Case Management plugin so that data in scope master tables can only be accessed by users with the correct permissions, enforcing the principle of least
privilege.
When the glide.enforce_security_scope.sn_hr_agent_ws plugin is configured to the recommended value of true, then only the access control lists (ACLs) within the Agent Workspace for HR Case Management
plugin are used to determine access to a resource. When this setting is set to false, then Agent Workspace for HR Case Management data in scope master tables are exposed because the ACLs from all scopes are granted
access.For example, an IT Administrator can access Agent Workspace for HR Case Management data when
this setting is set to false. To prevent this from happening, set glide.enforce_security_scope.sn_hr_agent_ws to the recommended value of true which ensures that the principle of least privilege exists
as users can only access resources they have permission to.

## More information {#sc-enforce-security-scope-for-agent-workspace-hr-case__section_more_information}

{#sc-enforce-security-scope-for-agent-workspace-hr-case__table_ajc_b43_3kb__entry__2}

| Attribute | Description |
|-|-|
| Configuration name | glide.enforce_security_scope.sn_hr_agent_ws |
| Configuration type | System Properties (/sys_properties_list.do) |
| Data type | Boolean |
| Recommended value | true |
| Default value | true |
| Category | [Access control](https://servicenow-prod.fluidtopics.net/xAmazkRh5FKyeb7q4TQGWw "The access control category audits the process of protecting resources from unauthorized access through granting and denying requests based on a permission model. This includes ensuring an entity accessing a resource holds valid credentials to do so, creating and protecting a well-defined set of roles or permissions and ensuring role or permission controls are protected from replay and tampering.") |
| Security risk | * Severity score: 2.7 * CVSS score: Low * Security risk details: Configuring this setting to false causes the Agent Workspace for HR Case Management data in scope master tables to be exposed because the ACLs from all scopes are granted access. {#sc-enforce-security-scope-for-agent-workspace-hr-case__ul_g1g_3sf_xwb} |
| Dependencies and prerequisites | Agent Workspace for HR Case Management |
| Functional impact | Configuring this setting to true will enforce global ACLs to be executed for a table, if scoped ACLs do not exist for it. |
| References | * <https://owasp.org/www-project-proactive-controls/#div-numbering> * [Add a component to Agent Workspace](https://www.servicenow.com/docs/access?context=workspace-component&version=australia&pubname=australia-application-development&ft:locale=en-US) {#sc-enforce-security-scope-for-agent-workspace-hr-case__ul_sxt_bcr_41c} |
[ ]

{#sc-enforce-security-scope-for-agent-workspace-hr-case__table_ajc_b43_3kb}

