---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Platform security granular admin roles

# Platform security granular admin roles {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 Minuten Lesedauer

Use granular admin roles to verify access management by assigning roles that define user permissions and responsibilities.  
Tipp:  
Use the search field to filter the granular admin role by entering keywords related to the role name or product.
{#platsec-granular-roles__Platform-Security-granular-admin-roles__entry__3}

| Product | Role required | Role description |
|-|-|-|
| Access Analyzer | access_analyzer_admin | Role required to access the Access analyzer to compare user records and access, simulate user access, and view access insights. To learn more, see [Access Analyzer](https://servicenow-prod.fluidtopics.net/fLmEAMeSTtgVriWPIdvwjQ "ServiceNow Access Analyzer is an access diagnostic tool designed for AI administrators or creators to validate the access controls configured within various resources and agentic assets (agentic workflows and AI agents)."). |
| Adaptive Authentication | adaptive_auth_admin | Role required to configure adaptive authentication policies. To learn more, see [Adaptive authentication](https://servicenow-prod.fluidtopics.net/XQ5OEG0LBshxmWwXEKVReg "Use the Adaptive authentication policy framework to enforce contextual authentication controls to the right users at the right time. Adaptive authentication uses authentication policies to evaluate authentication requests and then either deny or allow access to your instance based on the specified policy conditions."). |
| Authentication Factors | auth_factors_admin | Role required to configure authentication for voice agent environments, with the factors that first identify the caller, then authenticate them before granting access. |
| API Access Policies, API Auth Scopes, Processor Access Policies | * api_service_admin * adaptive_auth_policy_admin {#platsec-granular-roles__ul_xhq_l41_n3c} | Role required to enable users to configure non-oauth related functionality like REST or SOAP policies, inbound authentication profiles, token based auth, processors. |
| Custom URL | custom_url_admin | Role required to configure custom URL, view datacenters jobs in read-only mode, and select portal and SSO records. To learn more, see [Custom instance URLs](https://servicenow-prod.fluidtopics.net/K7IBX4bHoRStiBjmPQ_5HA "You can enable your ServiceNow instance to be accessible from a company-branded or custom URL."). |
| E-signature with SSO | * sso_config_admin * script_include_admin * ui_page_admin {#platsec-granular-roles__ul_k4m_k41_n3c} | Role required to configure E-signature with SSO (SAML or OIDC) only and not required if using local database login. To learn more, see [E-signature for Multi-Provider SSO](https://servicenow-prod.fluidtopics.net/joBAebWQV7yDJpxxFX6YiQ "E-signature with Multi-Provider SSO enables you to use the e-signature properties instead the SAML or OIDC properties for authentication."). |
| Encryption | security_admin | Role required to perform security operations as an admin. |
| Encryption | sn_kmf.admin | Role required to have admin and security admin access to be sn_kmf.admin. Can assign sn_kmf.cryptographic_manager or sn_kmf.cryptographic_auditor role to other users and has read, write, and execution permissions for key operations. |
| Encryption | sn_kmf.cryptographic_auditor | Role required to have read permission for key operations. |
| Encryption | sn_kmf.cryptographic_manager | Role required to have read, write, and execution permissions for key operations. |
| Federated ID | iamsync_admin | Role required to manage the Federated ID and read or write Federated ID related property. To learn more, see [Global Identity](https://servicenow-prod.fluidtopics.net/K3_vLT7h_th3aw1ZiC7CKQ "Use ServiceNowGlobal Identity to help identify and manage users across multiple instances."). |
| Identity AI Agent | ai_user_admin | Role required to manage AI user identities within the instance. They can create,edit,delete AI users, and assign or remove roles associated with them. |
| Identity AI Agent | agent_role_config_admin | Role required to configure and manage AI agent access during agentic workflow execution. You can mask roles for AI agents using the Agent Access Role Configurations table helping protect sensitive data and enforce role-based restrictions. |
| Identity AI Agent | agent_role_config_viewer | Role required to view existing records on the Agent Access Role Configurations table. |
| Identity and Access audit | identity_access_audit_viewer It contains: * role_viewer * group_viewer {#platsec-granular-roles__ul_k15_kpp_c3c} | Role required to view the User Trails, Group Trails, Role Trails, ACL Trails and Audit results. |
| Identity and Access audit | security_admin | Role required to: * Configure Retention Period, Configure Tables \& Fields. * Change identity security audit feature property. {#platsec-granular-roles__ul_o15_kpp_c3c} |
| Identity Center | user_login_history_viewer | Role required to view login history details in the Identity Center, including login timestamps, browser information,IP address, and login status. Supports security investigations by enabling filtered views of login actions and helps identify suspicious activity. To learn more, see [Identity Center for users](https://servicenow-prod.fluidtopics.net/mSdEVn_piPcVeDUaOgDRfA "View the details about your active sessions, login history, and trusted devices with the Identity Center."). |
| Identity Center | privileged_role_config_admin | Role required to grants full access to manage role configurations in the Identity Center, including adding, deleting, creating, reading, and viewing reports in the sys_icenter_role_config table. To learn more, see [Identity Metrics for administrators](https://servicenow-prod.fluidtopics.net/z6Cq7gbbVpusELacxcTiWw "View trends of the users, privileged users, active sessions, and integrated account on your ServiceNow instance."). |
| Identity Center | role_viewer | Role required to only view the records in the sys_icenter_role_config table. To learn more, see [Identity Center for users](https://servicenow-prod.fluidtopics.net/mSdEVn_piPcVeDUaOgDRfA "View the details about your active sessions, login history, and trusted devices with the Identity Center."). |
| Instance operator | instance_operator It contains: * identity_access_audit_viewer * user_role_history_viewer {#platsec-granular-roles__ul_u15_kpp_c3c} | Role required to manage perform specific role related operations and know about identity access audits. |
| Machine Identity Console | mi_admin | Role required to manage identities that interact with systems and data. To learn more, see [Machine Identity Console](https://servicenow-prod.fluidtopics.net/8RCHlQWGlYT47vGsAKtr3A "Manage your service accounts which are used for integrations with ServiceNow."). |
| Password policy | password_policy_admin | Role required to configure password policy-related items. To learn more, see [Local authentication](https://servicenow-prod.fluidtopics.net/AmMHQ1R68WdNpLmurm7mkA "Use ServiceNow local authentication to secure the users login on a local device.") |
| Role delegation | role_delegator_admin | Role required for role delegation. |
| Roles | user_role_history_admin It contains: * user_role_history_viewer * role_viewer {#platsec-granular-roles__ul_dch_qv1_23c} | Role required to manage perform specific role related operations. |
| SCIM | scim_admin | Role required to configure and manage SCIM provisioning, including creating customization properties, supported and extension schema, and ETL definitions for user and group data. To learn more, see [System for Cross-domain Identity Management (SCIM)](https://servicenow-prod.fluidtopics.net/B~BRfAchRqbwz0DOnplNBQ "The System for Cross-domain Identity Management (SCIM) API provides endpoints to create, read, update, and delete operations on users and groups using the SCIM protocol."). |
| SCIM custom schema | scim_config_admin | Role required to configure SCIM custom schema and system properties. To learn more, see [SCIM customization properties and schemas](https://servicenow-prod.fluidtopics.net/hnSlWXI4pAl1XQro_GM72Q "The SCIM customization includes the following properties, supported schemas, and unsupported schemas."). |
| SCIM Client | scim_client_config_admin | Role required to configure SCIM Client. To learn more, see [SCIM Client](https://servicenow-prod.fluidtopics.net/D~5gLK1PWqnXvwv_o8WLQw "The SCIM Client facilitates provisioning and updates on identity resources through CRUD operations exposed by SCIM endpoint on an external system."). |
| SCIM Provider | scim_admin | Role required to configure SCIM Provider. To learn more, see [SCIM Provider](https://servicenow-prod.fluidtopics.net/LwOdrOvoQX9r_Ill52clSA "The Service Provider provisions users and groups using the SCIM API."). |
| Self-Register to ServiceNow instance | external_user_self_registration_admin | Role required to on-board a large volume of external users to your instance. To learn more, see [Self-register to ServiceNow instance](https://servicenow-prod.fluidtopics.net/TQuAPHxZ69Yn2G_OpuUBkA "Use external user self-registration to on-board a large volume of external users to your instance. This feature enhances identity verification to improve customer experiences and supports commonly used registration flows."). |
| ServiceNow Vault | sn_vault_console.vault_console_admin | Role required to have a collection of Data Classification admin, Data Privacy admin, and CA Admin roles to execute a template flow and monitor sensitive data. To learn more, see [Configuring ServiceNow Vault](https://servicenow-prod.fluidtopics.net/YQWABYgnjePpabbmHxIROw "Learn how to install and configure ServiceNow Vault.") |
| ServiceNow Vault | sn_vault_console.vault_console_auditor | Role required to have a collection of Data Discovery Auditor, Data Classification Auditor, Data Privacy Auditor, and Continuous Auth Auditor roles to view the policies and metrics related to ServiceNow Vault. |
| SSO (SAML and OIDC) | * sso_config_admin * business_rule_admin * script_include_admin {#platsec-granular-roles__ul_h21_p41_n3c} | Role required to configure SSO configuration (SAML or OIDC). To learn more, see [Multi-Provider single sign-on (SSO)](https://servicenow-prod.fluidtopics.net/HVjJt_0KCqg4EiNYQj99yA "External SSO allows organizations to use several SSO identity providers (IdPs) to manage authentication as well as retain local database (basic) authentication."). |
| System OAuth | oauth_admin | Role required to configure all OAuth related functionality. To learn more, see [OAuth Inbound and Outbound authentication](https://servicenow-prod.fluidtopics.net/t4zTs3mAikfn3q0kIdh0fw "OAuth based authentication validates the identity of the client that attempts to establish a trust on the system by using an authentication protocol."). Hinweis: You must assign the following roles for the following configurations: * The admin role for non out of the box properties. * The script_include_admin to change existing scripts (JWT, and so on). {#platsec-granular-roles__ul_x41_3pp_c3c} |
| Time limited role | user_admin | Role required to assign a role to a user temporarily, usually if the user must perform a one-time action that is normally not permissible by their role. |
| User Impersonation | user_impersonation_history_viewer | Role required to see the user impersonation history table. |
| Security Center | sn_vsc.security_center_admin | Role required to access Security Center consoles and tools. Users with this role can also create and manage security tasks. |
[Tabelle : 1. Platform Security granular admin roles]

{#platsec-granular-roles__Platform-Security-granular-admin-roles}

