---
sourceDocument: Australia Operational Technology Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/operational-technology

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Operational Technology Management

ft:clusterId :

    - optm

bundleId :

    - optm

workflow :

    - Technology


---

# Enhanced Access Control

# Enhanced Access Control for Operational Technology {#ariaid-title1}

Release version: Australia  
Updated March 12, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Enhanced Access Control for Operational Technology

Enhanced Access Control for Operational Technology (OT) in ServiceNow introduces advanced security mechanisms to protect OT data by implementing data filters, deny-unless access control rules (ACLs), and ACL query rules.
These components help prevent unauthorized access and misconfiguration risks within your OT environment.
Show full answer Show less  

## Key Features

* **Data Filters:** Control access at the query level to restrict data visibility.
* **Deny Unless ACLs:** Enforce strict access by denying data access unless specific conditions are met, supporting strong IT and OT separation.
* **ACL Query Rules:** Provide precise control over query operations with exact and range query ACLs.
* **IT and OT Separation:** Non-OT users cannot view OT Configuration Items (CIs) in the CMDB. Access to OT devices is limited to users with designated OT roles.
* **Role-Based Access:**
  * **cmdbotviewer:** Read-only access to OT devices.
  * **cmdboteditor:** Full create, read, update, and delete permissions on OT extension classes but cannot modify IT CIs or certain related IT CI fields.
* **Site-Based Access Control:** Access to view, edit, or delete OT devices is further restricted based on site assignments using "Can Read" and "Can Edit" user criteria. This ensures users only access OT assets relevant to their assigned sites.
* **Related Record Table Restrictions:** Access to OT-related CMDB CI tables such as IP Address, Network Adapter, and Serial Number is limited to users with OT roles and is governed by the same site-based access rules.

## Practical Outcomes for ServiceNow Customers

* Improved security posture by strictly segregating OT data from IT users and controlling access through clearly defined roles and site permissions.
* Reduced risk of unauthorized changes or viewing of sensitive OT configuration items and related records.
* Granular control over who can view or modify OT devices and related data, aligned with organizational policies on site and role-based access.
* Compliance facilitation by enforcing operational boundaries between IT and OT systems within the CMDB.  
Enhanced Access Control for Operational Technology (OT) implements data filters, deny unless access control rules (ACLs), and ACL query rules to help promote system security.

## Enhanced Access Control overview {#ot-enhanced-access-control__section_lhc_b5s_dgc}

Enhanced Access Control provides the following components to provide access control configurations for your data to help avoid misconfiguration and security issues.

Data filers
:   Ability to control access at the query level.

Deny Unless ACLs
:   Ability to deny access to data unless the specific conditions are met.

ACL Query Rules
:   Exact query and range query ACL operations to control query privileges.

## Enhanced Access Control for OT {#ot-enhanced-access-control__section_zjc_w5s_dgc}

Deny Unless ACLs help enforce IT and OT separation and site-based access.  
IT and OT separation  
Non-OT users can't view OT devices in Configuration Management Database (CMDB) tables. If a device is classified as an OT CI, only users assigned the cmdb_ot_viewer role or the cmdb_ot_editor role can access it. The following table describes each role.{#ot-enhanced-access-control__table_lgz_3w2_fgc__entry__2}

| Role | Description |
|-|-|
| OT Viewer \[cmdb_ot_viewer\] | Read-only access to OT device records. |
| OT Editor \[cmdb_ot_editor\] | Create, read, update, and delete access for [Operation Technology (OT) extension classes](https://www.servicenow.com/docs/access?context=cmdb-ci-class-models-operation-technology&version=australia&pubname=australia-servicenow-platform&ft:locale=en-US). Note: Users assigned the cmdb_ot_editor role can edit and delete only OT configuration items (CIs), and can't edit IT CIs. |
[Table 1. OT roles to view OT CIs]

{#ot-enhanced-access-control__table_lgz_3w2_fgc}  
There are also restrictions on OT users who can edit or delete IT configuration items (CIs). Users assigned the cmdb_ot_editor role or the cmdb_ot_admin role can't edit or delete IT CIs in the following related lists:

* IP Address
* Network Adapter
* Storage Device
* File System
* Memory Module
* Patch = CI Field
* Package = CI Field
* Managed Network
{#ot-enhanced-access-control__ul_ed2_ncf_fgc}  
Site-based access

Site-based access specifies which users can view, edit, and delete OT devices for a designated site. You can assign site-based access to users by using Can Read or Can Edit user
criteria. For more information about assigned Can Read access, see [Assign the user criteria for Can Read access to a site](https://servicenow-prod.fluidtopics.net/rMaPhN4dNxpPcclozBDYAA "Assign the user criteria to a site to define which users can read or view the equipment model entities that belong to the selected site."). For more information about assigning Can Edit access, see [Assign the user criteria for Can Edit access to a site](https://servicenow-prod.fluidtopics.net/B4LPVIQoIUvFk17qRu~5ZQ "Assign the user criteria to a site to define which users can edit the equipment model entities that belong to the selected site.").  
The following table describes the site-based access for users assigned the cmdb_ot_viewer role or the cmdb_ot_editor role. {#ot-enhanced-access-control__table_td2_jy2_fgc__entry__2}

| Role | Site-based permission |
|-|-|
| cmdb_ot_viewer | With Can Read access, users assigned the cmdb_ot_viewer role can only view OT devices for a designated site. For example, if you're assigned the cmdb_ot_viewer role and have Can Read access to the Atlanta site, then you can only view the site's OT devices. You can't edit or delete the OT devices associated with Atlanta. |
| cmdb_ot_editor | To edit OT devices, users with the cmdb_ot_editor role should be assigned Can Edit access for the site, or sites they belong to. For example, if you're assigned the cmdb_ot_editor role but only have Can Read access to the Atlanta site, you can only view the devices associated with Atlanta. If you're assigned the cmdb_ot_editor role and have Can Edit access to the San Diego site, you can edit or delete the devices associated with San Diego. |
[Table 2. Site-based access for OT roles]

{#ot-enhanced-access-control__table_td2_jy2_fgc}

## Enhanced Access Control for OT CMDB CI related record tables {#ot-enhanced-access-control__section_cjw_yz2_fgc}

Non-OT users can't view OT devices in the following OT CMDB CI related record tables:

* IP Address \[cmdb_ci_ip_address\]
* Network Adapter \[cmdb_ci_network_adapter\]
* Serial Number \[cmdb_serial_number\]

{#ot-enhanced-access-control__ul_gb4_ycf_fgc}If a related record is an OT device, only users assigned the cmdb_ot_viewer role or the cmdb_ot_editor can view or edit the OT device respectively.

Related records also adhere to site-based access restrictions. With Can Read access, users assigned the cmdb_ot_viewer role can only view the OT-related CMDB CI records for a designated site. Users with the cmdb_ot_editor role must be assigned Can Edit access for a site to edit or delete the OT-related CMDB CI records of the designated site.

