---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Module access policy overview

# Module access policy overview {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 Minute Lesedauer

Module access policies (MAPs) are access controls that you apply to your cryptographic modules. Use these access policies to decide which users and scripts can access data encrypted by a cryptographic module.

## Module access policies {#module_access_policy_overview__section_t31_w1y_4zb}

Hinweis:  
A subscription is required to utilize the Field Encryption Enterprise functionality. See [Activate Field Encryption](https://servicenow-prod.fluidtopics.net/d~sW4JlJZpz95XWViCzI5w "Activate either Field Encryption Starter or Field Encryption Enterprise.") for more information on Field Encryption Enterprise.

Module access policies are introduced with the Key Management Framework (KMF) in the base system.

Module access policies expand on the role-based designations that were provided with the encryption modules. Module access policies can be based on the following:  
* Basic (scope)
* Role
* System user
* Script
* Resource Exchange  
  Hinweis:  
  See [Key Management Framework Resource Exchange](https://servicenow-prod.fluidtopics.net/yMNf5uG7D5KU6R8q6D9k9Q "ServiceNow Resource Exchange is a KMF feature that gives you the capability to exchange resources between instances in a secure manner.") for details.
{#module_access_policy_overview__ul_vsb_qwp_kqb}

In a cryptographic module, you must configure the correct module access policies to permit access to encrypted data. Without a module access policy associated with a cryptographic module, encrypted data isn't visible to users
and associated fields and columns in lists display as empty.

In this example, the absence of a module access policy on the encrypted Short Description field hides the content from all users accessing the Incident table. With a module access policy in place, only users with a specific role
are able to see the encrypted data.  
Abbildung : 1. Encrypted short descriptions with and without module access policies  
Hinweis:  
The data in the column also appears empty to users without the correct role specified in the module access policy.

Refer to [Create a module access policy](https://servicenow-prod.fluidtopics.net/b5Fi_fL46STNIHpPr4rI2Q "Create module access policies to decide which users and scripts can access data encrypted by a cryptographic module.") for setup.

## Autogen policies {#module_access_policy_overview__section_xjg_v1y_4zb}

Autogen policies are automatically system generated based on the default module access policy defined for the given cryptographic module. If there are no granular level policies defined when the system or a script tries to
access the given cryptographic module, these global policies are generated and applied.  
Wichtig:  
Autogen policy rules aren't applied for scheduled jobs types, or field encryption modules (modules where the parent module is Field Encryption).

