---
sourceDocument: Australia Impact
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/impact

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Impact

ft:clusterId :

    - ipact

bundleId :

    - ipact


---

# Configure Scan Engine integrations

# Configure Scan Engine integrations {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Configure Scan Engine integrations

Scan Engine integrations enable synchronization and governance across ServiceNow instances and external agile systems.
These integrations help you compare technical debt, synchronize custom definitions and exception reasons, create user stories from findings, and enforce deployment policies for custom applications.
Show full answer Show less  

## Key Features

* **Definitions integration:** Synchronizes definition overrides and custom definitions between non-production and production instances to maintain consistent rulesets.
* **Exception reason integration:** Synchronizes exception reasons, allowing approvals or rejections in production based on updates from non-production instances.
* **User story integration:** Automatically creates tasks for findings from ServiceNow into ServiceNow production, Jira, Azure DevOps, or other systems.
* **Deployment and synchronization integrations:**
  * **Update sets:** Synchronizes update set summary scans to production from integrated instances.
  * **AES/AEMC:** Enforces governance on custom app deployments by validating requests against admin-defined conditions before approval, blocking deployments if conditions fail.
* **Other integration type:** Allows creation of work items in any external system using custom payload scripting and basic authentication.

## Prerequisites and Configuration Steps

* Create dedicated integration user accounts in both development and production environments with required roles (**snse.scanengineadmin** , **snse.internalrestintegration** , and **admin** for update set scans).
* Register each participating instance in the **My SN Instances** table, designating only one as production.
* Configure authentication using OAuth (recommended for production) or Basic Authentication.
* Validate instance connections using the Validate Connection action on each registered instance.
* Note that Azure DevOps and other external systems use basic auth records and API tokens configured in Scan Engine properties.

## Platform Considerations

* **Key Management Framework (KMF):** Encrypts passwords instance-specifically, requiring password re-entry when sharing Auth records across instances.
* Approve any pending Scan Engine scripting scope requests in KMF before retrying authentication.
* Enable ECMAScript 2021 (ES12) mode in Scan Engine properties for modern JavaScript syntax support in User Story field mapping scripts.

## Benefits for ServiceNow Customers

By configuring these integrations, customers can ensure consistent scanning rules across environments, streamline exception management, automate agile task creation, and enforce deployment governance. This leads to improved visibility, control, and efficiency in managing application security and technical debt across the ServiceNow platform and connected agile tools.  
Scan Engine integrates with other ServiceNow instances and external agile systems to synchronize definitions, manage exception reasons, create user stories, and enforce governance over app deployments.

Scan Engine has the ability to integrate with your other environments running Impact so that you can:

* Compare technical debt across instances
* Sync custom definitions across instances
* Enable approvals for finding exceptions in production
* Create user stories from findings

The following integrations are available for the Scan Engine.
{#instance-integration-scan-engine__table_i33_xr5_3hc__entry__2}

| Integration | Description |
|-|-|
| [Definitions integration](https://servicenow-prod.fluidtopics.net/bAcDwKsN6iMuxOZNtvqA2w "The Definitions integration synchronizes new, customized, and overridden definitions between non-production and production instances.") | Allows users to synchronize definition overrides and custom definitions between non-production and production instances. Ensuring a consistent ruleset is being applied throughout the instance stack. |
| [Exception reason integration](https://servicenow-prod.fluidtopics.net/dN1GbIsAmXO8sZdZ99xsaQ "You can synchronize exception reasons from non-production to Production instances once a record is created or updated.") | * Synchronizes exception reasons between non-production and production instances. * Facilitates the approval or rejection of exception reasons in the production environment. {#instance-integration-scan-engine__ul_j33_xr5_3hc} |
| [User story integration](https://servicenow-prod.fluidtopics.net/T~iXBVrufCLPeug3LcR2TA "The User story integration creates agile tasks and stories directly from Scan Engine finding records in ServiceNow, Jira, Azure DevOps, or any external system.") | Creates tasks for findings from a ServiceNow instance to: * ServiceNow production Instance * Jira * Azure DevOps * Others {#instance-integration-scan-engine__ul_l33_xr5_3hc} |
| [Deployment and synchronization integrations](https://servicenow-prod.fluidtopics.net/DH4BirffxVjbc2GskQG8Wg "The AES/AEMC and Update set integrations control how custom app deployments are governed and how scan results are synchronized across your instance stack.") | * Update sets: Synchronizes update set summary scans to the production instance from instances where this integration is enabled. * AES/AEMC: Provides automated governance for custom app deployments by validating deployment requests against admin-defined conditions before approval. When a developer submits a deployment request, the system automatically runs checks to ensure all required rules are met, blocking deployment if conditions fail. |
[Table 1. Scan Engine integrations]

{#instance-integration-scan-engine__table_i33_xr5_3hc}

## Prerequisites {#instance-integration-scan-engine__section_ob1_ls5_djc}

Most integrations share the same foundational setup. Complete the following before configuring any specific integration.

* [Create an integration user account](https://servicenow-prod.fluidtopics.net/R8zhF4x0HSwyhYcCi965FA "Create a dedicated integration user account and assign the required roles so that the Scan Engine can authenticate and communicate between your ServiceNow instances.") in development and production environments.
* [Register your instance](https://servicenow-prod.fluidtopics.net/CW_9LTbn1YISzXh4d4sYSg "Register each participating ServiceNow instance in the My SN Instances table before configuring any instance-to-instance integration."): Register each participating instance in the My SN Instances table. Only one instance in your stack may be designated as Production.
* Configure authentication using Basic or OAuth. OAuth is strongly recommended for all production environments. See [Configure the OAuth authentication method development instance](https://servicenow-prod.fluidtopics.net/1yaYVDnxfcmFLl6Jpf0k0A "Set up OAuth authentication for instance-to-instance Scan Engine integrations using several stages, an integration user account, an OAuth2 configuration record, and provider and client application registries.") and [Configure the OAuth authentication method production instance](https://servicenow-prod.fluidtopics.net/U1vbd9zLkRmM8GWrIUPM7g "Export OAuth records from the development instance, import them into the production instance, correct Key Management Framework (KMF) credential encryption, and configure development-to-production authentication so that both instances can validate their connections to each other.") or [Configure the Basic authentication method](https://servicenow-prod.fluidtopics.net/cuVzGTUp4EYPFdAvW75jrw "Confirm an integration user, create a Basic authentication record, then connect your instances using basic authentication. Basic authentication is supported but OAuth is recommended for production environments.") for details.
* [Validate your instance connection](https://servicenow-prod.fluidtopics.net/HA6MFEOw7zePlehyV0xnCQ "Validate the connection between registered instances to confirm that authentication and My SN Instances configuration are correct before enabling integrations."): Validate each instance connection using the Validate Connection action on each My SN Instances record.

{#instance-integration-scan-engine__ul_pb1_ls5_djc}  
Note:  
Azure DevOps and the Other integration type authenticate via Basic auth records and API tokens configured directly in Scan Engine Properties, as they do not use My SN Instances. AES/AEMC only requires one My SN Instances record to designate the production controller, with no Authentication Type set.

## Role requirements {#instance-integration-scan-engine__section_rbr_4s5_djc}

{#instance-integration-scan-engine__table_sbr_4s5_djc__entry__3}

| Role | Purpose | Where required |
|-|-|-|
| `sn_se.scan_engine_admin` | Full admin access to Scan Engine configuration | Integration user on all instances |
| `sn_se.internal_rest_integration` | Allows REST calls between instances | Integration user on all instances |
| `admin` | Platform admin | Update Set Scans integration only |
[ ]

{#instance-integration-scan-engine__table_sbr_4s5_djc}  
Important:  
Neither Scan Engine role is inherited by the platform admin role. Always assign both roles explicitly on every instance the integration user is imported to.

## Platform notes {#instance-integration-scan-engine__section_q5d_qs5_djc}

Key Management Framework (KMF)
:   KMF replaced the Glide Encryptor class for encrypting `password_2` fields. KMF encryption is instance-specific, an encrypted value from one instance cannot be decrypted on another. Any Auth record that crosses
    an instance boundary requires a password re-entry on the receiving instance. If a pending Scan Engine scripting scope request is blocking authentication, it must be approved in the Key Management Framework module access policies before retrying.

ECMAScript 2021 (ES12) mode
:   For User Story integrations, enable ECMAScript 2021 (ES12) mode in Scan Engine Properties to use modern JavaScript syntax in field mapping scripts. Without this mode, only the application default JavaScript mode is available.
* **[Create an integration user account](https://servicenow-prod.fluidtopics.net/R8zhF4x0HSwyhYcCi965FA)**   
  Create a dedicated integration user account and assign the required roles so that the Scan Engine can authenticate and communicate between your ServiceNow instances.
* **[Register your instance](https://servicenow-prod.fluidtopics.net/CW_9LTbn1YISzXh4d4sYSg)**   
  Register each participating ServiceNow instance in the My SN Instances table before configuring any instance-to-instance integration.
* **[Definitions integration](https://servicenow-prod.fluidtopics.net/bAcDwKsN6iMuxOZNtvqA2w)**   
  The Definitions integration synchronizes new, customized, and overridden definitions between non-production and production instances.
* **[Exception reason integration](https://servicenow-prod.fluidtopics.net/dN1GbIsAmXO8sZdZ99xsaQ)**   
  You can synchronize exception reasons from non-production to Production instances once a record is created or updated.
* **[User story integration](https://servicenow-prod.fluidtopics.net/T~iXBVrufCLPeug3LcR2TA)**   
  The User story integration creates agile tasks and stories directly from Scan Engine finding records in ServiceNow, Jira, Azure DevOps, or any external system.
* **[Deployment and synchronization integrations](https://servicenow-prod.fluidtopics.net/DH4BirffxVjbc2GskQG8Wg)**   
  The AES/AEMC and Update set integrations control how custom app deployments are governed and how scan results are synchronized across your instance stack.
* **[Configure other integration options](https://servicenow-prod.fluidtopics.net/5zaLrMBod6ruAvOI_u2xDA#configure-other-integration-options)**   
  Configure the Other integration type to create work items in any external system using a custom payload script and basic authentication.

**Previous topic:** [Initiate data migration from IDI](https://servicenow-prod.fluidtopics.net/CtZNMpX4ThLy_Mb73lSyIA "After the connection is established between your Impact Store Application and the Impact Delivery Instance, next migrate your data.")  
**Next topic:** [Create an integration user account](https://servicenow-prod.fluidtopics.net/R8zhF4x0HSwyhYcCi965FA "Create a dedicated integration user account and assign the required roles so that the Scan Engine can authenticate and communicate between your ServiceNow instances.")

