---
sourceDocument: Australia ServiceNow AI Platform Administration
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/platform-administration

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia ServiceNow AI Platform Administration

ft:clusterId :

    - platadm

bundleId :

    - platadm

workflow :

    - Platform


---

# Exploring Instance Scan

# Exploring Instance Scan {#ariaid-title1}

Release version: Australia  
Updated July 3, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Exploring Instance Scan

Instance Scan is a ServiceNow tool designed to help you assess the health and security of your instance by detecting anomalies, vulnerabilities, and best practice deviations.
It uses focused checks that analyze tables, records, or metadata across your instance.
The tool supports multiple scan types---full scan, point scan, and test scan---allowing flexible and targeted assessments.
Although domain separation is partially supported (findings are domain-separated by source record), full domain separation is not yet implemented.
Show full answer Show less  

## Key Features

* **Checks:** Defined rules that detect issues related to security, upgrade best practices, manageability, user experience, and performance.
* **Results and Findings:** Scan outcomes report the status and details of violations found during scans, helping you identify problem areas.
* **Dashboard:** A system-wide visual interface to manage and analyze scan results, providing insight into your instance's overall health.
* **Quota Rules:** Configurable thresholds that prevent excessively long running scans, ensuring efficient resource use and avoiding failures.
* **Scan Types:**
  * **Full Scan:** Runs all active checks across the entire instance.
  * **Point Scan:** Targets a specific record, update set, or application with applicable checks.
  * **Test Scan:** Allows testing of individual checks to validate their effectiveness before running full scans.

## User Roles

* **scanuser:** Can execute scans, view checks, findings, and results.
* **scancheckwriter:** Includes scanuser permissions plus the ability to create new checks.

## Benefits for ServiceNow Customers

* Enables creation and management of custom checks and check suites to monitor instance health.
* Provides flexible scanning options to efficiently identify and address instance issues.
* Offers a comprehensive dashboard for monitoring and analyzing scan outcomes, supporting proactive instance management.
* Includes quota rules to control scan execution time and prevent system resource overuse.

## Next Steps

To leverage Instance Scan effectively, customers should explore configuration options, learn to create and manage checks, execute various scan types, and use the dashboard to monitor instance health continuously.  
If you are new to Instance Scan, read this overview to learn what the
tool can do. Follow the tutorial to create checks and execute scans that uses most basics of Instance Scan features.  
Note:  
Instance Scan doesn't fully support domain separation. Findings are visibly domain separated based on the domain of the source record. For more information see [Domain separation](https://www.servicenow.com/docs/access?context=domain-sep-landing-page&version=australia&pubname=australia-platform-security&ft:locale=en-US).

## Instance Scan overview {#hs-getting-started__section_qqh_vkz_mdc}

Instance Scan uses the following records, components and scan types.

Checks
:   Checks are singular focused rules that detect anomalies or opportunities in an instance. These checks can run against tables, records, or metadata. Checks are defined to identify security, upgrade best practices, manageability, user experience and performance vulnerabilities. See [Getting started with checks](https://servicenow-prod.fluidtopics.net/nSRArF1TVbSjrqu0UBkGcg "Checks are singular focused rules that detect anomalies or opportunities in an instance. These checks can run against tables, records, or metadata. Checks are defined to identify security, upgrade best practices, manageability, user experience and performance vulnerabilities.") for more information.

Results
:   An Instance Scan result reports the status and type of the scan. See [Results](https://servicenow-prod.fluidtopics.net/v2aWykUKyT5ovzK0Z~Bb9g "After the scans have been executed, you can review them with the findings and results components.") for more information.

Findings
:   A finding is a reference to a record that has violated a rule from a check on the instance. See [Findings](https://servicenow-prod.fluidtopics.net/v2aWykUKyT5ovzK0Z~Bb9g "After the scans have been executed, you can review them with the findings and results components.") for more information.

Dashboard
:   The Instance Scan dashboard is a system-wide visual representation of the health of your instance. The dashboard helps you manage and analyze the full scan results against your instance. See [Instance Scan dashboard](https://servicenow-prod.fluidtopics.net/As14ZK6lfvRPBArw6DeV_g "The Instance Scan dashboard is a system wide visual representation of the health of your instance. The dashboard helps you to manage and analyze the results of full scan against your instance.") for more information.

Quota rule
:   A quota rule determines the execution threshold of a scan. The quota rule prevents the instance from running long scans. For example, any scan running longer than the threshold set by the quota rule will result in a failure. See [Quota rules](https://servicenow-prod.fluidtopics.net/SGxFD0TGcYkNzbKL_npRkw "A timeout determines the execution threshold of a scan from running long scans. For example, any scan running longer than the set time period results in a failure.") for more information.

Full scan
:   Execute a scan for the entire instance by selecting Execute Full Scan. Implementing a full scan runs all the active checks present in your instance.

Point scan
:   Execute all applicable checks against a single record, update set, or an application by selecting Run Point Scan. For example, if you execute a point scan against a business rule, only the checks that are applicable to the business rule table run, and only that single target record is scanned. If you execute an update set scan or an application scan, all records related to that update set or application are scanned. See [Execute an app scan](https://servicenow-prod.fluidtopics.net/vgucX7I_4u8ZhDR7uHeJug "Scan the installed files of an application as well as the application record itself with applicable checks by executing an application scan.") and [Execute an update set scan](https://servicenow-prod.fluidtopics.net/~WB05PvHIPbuxMNVgeyjqg "Use an update set scan to run applicable checks against the current versions of records that have updates in the update set. If a record has been modified since it was added to the update set, the scan reflects those later changes. Issues that exist only in the update set version of a record aren't detected.") for more information.

Test scan
: Execute a test scan to verify if the check works as expected. The test scan enables you to test a single check instead of a full scan by selecting a single check and selecting Test Check on the Check form.  
Note:  
Instance Scan can scan tables that are extended by sys_metadata.

## Instance Scan users {#hs-getting-started__section_kbs_pkd_qjb}

Instance Scan has the following roles.{#hs-getting-started__table_ph5_fns_xjb__entry__2}

| Users | Description |
|-|-|
| scan_user | The scan_user role can run different types of scans, read checks, execute checks, and view the findings and results. |
| scan_check_writer | This role includes the scan_user role and provides permission to create new checks. |
[ ]

{#hs-getting-started__table_ph5_fns_xjb}

## Instance Scan benefits {#hs-getting-started__section_b3z_nm2_bbc}

{#hs-getting-started__table_c3z_nm2_bbc__entry__3}

| Benefit | Feature | Users |
|-|-|-|
| Create checks and check suites to know the health of your instance | * [Getting started with checks](https://servicenow-prod.fluidtopics.net/nSRArF1TVbSjrqu0UBkGcg "Checks are singular focused rules that detect anomalies or opportunities in an instance. These checks can run against tables, records, or metadata. Checks are defined to identify security, upgrade best practices, manageability, user experience and performance vulnerabilities.") * [Create a check](https://servicenow-prod.fluidtopics.net/pxMZytg88S33TLnKJJFVlw "Create your own checks by implementing the following procedure.") * [Create a check suite](https://servicenow-prod.fluidtopics.net/O_mO72gOZTePbgLTQCguaA "Create a check suite to bundle a group of checks into a suite and execute it.") {#hs-getting-started__ul_ugl_54z_4dc} | scan_user |
| Execute scans on the created checks to review the instance health | [Executing a scan](https://servicenow-prod.fluidtopics.net/q69X8ioER7e5OOY~6WXJgw "Use the following types of scans to execute checks, a scan or a suite scan.") | scan_user |
| Scheduling of scans and suite scan | * [Schedule a full scan](https://servicenow-prod.fluidtopics.net/UEHvpt8_aZqMpTy0WrsrVg "Create a schedule to regularly trigger a full scan even when you don’t have an active session. A schedule creates an established baseline for the health of the instance and provides a comparison to configuration and instance health over time.") * [Schedule a suite scan](https://servicenow-prod.fluidtopics.net/O7gMmHVl7LngVs2SJWtRAw "Create a schedule to regularly trigger a suite scan even when you don’t have an active session.") {#hs-getting-started__ul_csz_v4z_4dc} | scan_user |
| Monitor your scans to ensure no health issues of your instance | [Monitoring a scan](https://servicenow-prod.fluidtopics.net/9lo69PkgffXYiR7CeBTaPw "You can check the progress status of a scan by checking the progress tracker.") | scan_user |
| Manage and analyze the results of full scan against your instance | [Instance Scan dashboard](https://servicenow-prod.fluidtopics.net/As14ZK6lfvRPBArw6DeV_g "The Instance Scan dashboard is a system wide visual representation of the health of your instance. The dashboard helps you to manage and analyze the results of full scan against your instance.") | scan_user |
[ ]

{#hs-getting-started__table_c3z_nm2_bbc}

## What to explore next {#hs-getting-started__cf-exploring-parent-links}

To learn more about using Instance Scan, see:

* [Configuring Instance Scan](https://servicenow-prod.fluidtopics.net/13IcnOFiSMn3_QntBbOqTg "Execute the different kinds of scans that Instance Scan offers to keep a check on the health of your instance. You can also schedule a full scan so you can ensure the health of your instance even without an active session.")
* [Using Instance Scan](https://servicenow-prod.fluidtopics.net/xRR8XQwL0PKUJynbUVoArQ "Execute and schedule the following scans within Instance Scan. You can also analyze the results of the scans in your instance on a dashboard.")
* [Instance Scan references](https://servicenow-prod.fluidtopics.net/DKpz8UNijDa72vWlThY5ug "The reference topics provide additional information about Instance Scan.")
{#hs-getting-started__ul_fhy_xfw_sbc}

