---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Configuring access control

# Configuring
access control {#ariaid-title1}

* Release version: Australia
* 
* Updated November 27, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Configuring access control

This guide details how to configure entity-based access control (EBA) in ServiceNow Privacy Management, allowing organizations to restrict user access to processing activity records based on their position within an organizational hierarchy.
Implementing EBA enhances data privacy, supports regulatory compliance, and ensures that privacy teams and users only access relevant records tied to their assigned entities.
Show full answer Show less  

## Key Features

* **Entity-Based Access Activation:** Install the Entity-based Access plugin and enable the related property to activate entity-level access control features.
* **Organizational Hierarchy Setup:** Define parent-child relationships between entities (e.g., global, regional, country levels) to establish a clear structure for access control.
* **Record Mapping:** Map existing processing activity records to their appropriate entities in the hierarchy to ensure precise access restrictions.
* **Entity Configuration:** Assign access permissions to individual users or groups based on their entity roles, specifying whether access extends to downstream entities.
* **Bulk Access Updates:** Transition from role-based to entity-based access across records using a bulk update utility that validates and applies restrictions efficiently.
* **Entity-Based Record Access Rules:** Enable continuous enforcement of access restrictions on new or modified records, with automatic updates reflecting changes in organizational structure or processing activities.

## Key Outcomes

* **Granular and Hierarchical Access Control:** Access restrictions align with organizational structure, improving data security and privacy governance.
* **Efficient Management:** Bulk update utility and automated record access rules reduce manual efforts and ensure consistent enforcement of access controls.
* **Regulatory Compliance Support:** Restricting access to entities' relevant data helps meet privacy regulations by limiting unnecessary data exposure.
* **Dynamic Adaptation:** The system automatically adjusts access controls when entities or processing activities change, maintaining up-to-date security postures.  
Configurie
Entity-based access control in Privacy Management, including property
activation, hierarchy setup, record mapping, user assignment, bulk updates, and activating
entity-based record access rules.

The following steps outline how to configure access control in Privacy Management using
Entity-based access (EBA). This process enables organizations to restrict user access to
processing activity records and related data according to their position in the organizational
hierarchy. By following these steps, administrators can ensure that privacy teams and users only
access records relevant to their assigned entities, supporting both security and regulatory
compliance.

1. Install Entity-based access plugin and enable the entity-based access control property. This activates entity-based access features and allows you to configure access restrictions by legal entity.For information, see [Configure Entity-based access](https://servicenow-prod.fluidtopics.net/m~QcWa1G_bcEXVeJSa9pBw "Configure entity-based access by installing the Entity-based Access Configurations plugin and enabling properties for record types.").

2. Establish the organizational structure (parent-child relationships), where a global entity contains regional entities, and those in turn contain country-level entities. For
   information, see [Add hierarchical relationships between entities](https://servicenow-prod.fluidtopics.net/EL_TpLT7umCA8Ftt0WkL1Q "Define hierarchical relationships between entities (Global → Regional → Country-level) using Upstream and Downstream options. Adding an hierarchy creates a clear organizational structure.").

3. If processing activities already exist, map each record to the appropriate entity in the organizational hierarchy, ensuring it is correctly linked as a downstream entity under the relevant legal entity, jurisdiction, or other defined structure. This guarantees that access restrictions are enforced accurately, as each record is tied to the correct part of the organization.
4. In the Entity Configuration module, do the following:
   * Provide access to teams and users based on your organizational structure. You can grant access to individual users, such as entity owners or privacy analysts, or to groups.
   * Specify whether access applies only to the selected entity or also to downstream entities. This step ensures that only the appropriate teams or users can access records for their part of the organization.

   {#configure-access-control-by-legal-entity__ul_p1m_npj_lhc}

   For information, see [Create an entity configuration](https://servicenow-prod.fluidtopics.net/UlTO~YRa7gbPUA1YEqsiiQ "Create an organizational structure by configuring entity-based access for different levels such as headquarters, regional offices, and subsidiaries. Define access rules for users and groups.").
5. Run a bulk access update to switch from role-based access to entity-based access for all applicable records. Bulk Access Update enforces entity-based access restrictions across relevant records in Privacy Management.  
   When performing a bulk update:
   * Select the entity configuration and associated entities.
   * Choose the tables where restrictions apply (for example, Processing Activity or Privacy Assessment).
   * Preview the affected records to validate changes.
   * Enable the update to apply restrictions.
   {#configure-access-control-by-legal-entity__ul_x3m_g1l_lhc}The system queues a scheduled job that processes the update and applies the new access rules to all selected records.

   For information on how to run batch updates, see [Set access restrictions using an entity based record access update utility](https://servicenow-prod.fluidtopics.net/UTP1OkmHedRYrO8J4k6A0A "Set access restrictions for the existing records in bulk by using the Entity based record access update utility guided-experience. Use the workflow to enable or disable access to record types.").
6. Use entity-based record access rules to enable continuous monitoring. These rules automatically apply restrictions to new or modified records, ensuring access settings stay enforced without manual updates. When the structure of the entities change, the system updates access controls automatically.For information on how to configure entity-based record access
   rules, see [Set Entity based record access rules](https://servicenow-prod.fluidtopics.net/u8jX9iVtk0kEJxBmoSJPeA "Use entity-based record access rules to secure records and enable continuous monitoring. These rules automatically apply restrictions to new or modified records, ensuring access settings stay enforced without manual updates. When entities or processing activities change, the system updates access controls automatically.").

{#configure-access-control-by-legal-entity__ol_b4p_jnf_lhc}
* **[Configure Entity-based access](https://servicenow-prod.fluidtopics.net/m~QcWa1G_bcEXVeJSa9pBw)**   
  Configure entity-based access by installing the Entity-based Access Configurations plugin and enabling properties for record types.
* **[Create an entity configuration](https://servicenow-prod.fluidtopics.net/UlTO~YRa7gbPUA1YEqsiiQ)**   
  Create an organizational structure by configuring entity-based access for different levels such as headquarters, regional offices, and subsidiaries. Define access rules for users and groups.
* **[Add hierarchical relationships between entities](https://servicenow-prod.fluidtopics.net/EL_TpLT7umCA8Ftt0WkL1Q)**   
  Define hierarchical relationships between entities (Global → Regional → Country-level) using Upstream and Downstream options. Adding an hierarchy creates a clear organizational structure.
* **[Set access restrictions using an entity based record access update utility](https://servicenow-prod.fluidtopics.net/UTP1OkmHedRYrO8J4k6A0A)**   
  Set access restrictions for the existing records in bulk by using the Entity based record access update utility guided-experience. Use the workflow to enable or disable access to record types.
* **[Set Entity based record access rules](https://servicenow-prod.fluidtopics.net/u8jX9iVtk0kEJxBmoSJPeA)**   
  Use entity-based record access rules to secure records and enable continuous monitoring. These rules automatically apply restrictions to new or modified records, ensuring access settings stay enforced without manual updates. When entities or processing activities change, the system updates access controls automatically.

