---
sourceDocument: Xanadu Customer Service Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/xanadu/customer-service-management

 Release :

    - xanadu

ft:locale :

    - en-US

ft:publication_title :

    - Xanadu Customer Service Management

ft:clusterId :

    - csm

bundleId :

    - csm

workflow :

    - Customer and Industry


---

# CSM Walk-up Experience portal security and access

# CSM Walk-up Experience portal security and access {#ariaid-title1}

* Release version: Xanadu
* 
* Updated August 1, 2024
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Security is built into the application to prevent end-user facing devices at the Walk-up Experience onsite portal from offering elevated role privileges to users. The Walk-up Experience onsite portal is accessed by an account containing only the sn_walkup.walkup_login role. The sn_walkup.walkup_login role contains the snc_external role.

## Understanding Walk-up Experience portal security {#csm-walkup-security-portal__section_kbf_fkw_2fb}

Accessing the onsite Walk-up Experience portal requires the singularly assigned
sn_walkup.walkup_login role. The user record with this role cannot contain any other roles.
Since most user records contain multiple roles, the sn_walkup.walkup_login role is assigned to a
user record account, not a human user. The security feature prevents the onsite portal check-in
device from permitting users who may try accessing the portal with an elevated privilege role.

The sn_walkup.walkup_login role is granted to a user record for an account used to log in to
the check-in device. Device can typically be a tablet, at the onsite Walk-up Experience
portal. It is not an actual human being with an assigned role, but an account with a role. For
example, a technician opening the onsite Walk-up portal for business logs in to the check-in
device using the user record that contains the sn_walkup.walkup_login role. Again, the portal
can only be accessed by a user record that contains this role only. A user cannot access the portal with the admin role or if the user record contains roles other than the sn_walkup.walkup_login role.

## Access to Walk-up Experience {#csm-walkup-security-portal__section_w2v_jkw_2fb}

Technicians opening up the onsite Walk-up location for business, or joining the support team
during operation hours, access the user record account. Technicians with sn_walkup.walkup_login
role can log in to the Walk-up Experience portal. Internal and external users can access
the onsite Walk-up Experience portal via a check-in device, typically a tablet, to enter
a queue. Internal, authenticated users can also access an online queue check-in via desktop.

