Enterprise Architecture Workspace access roles

  • Release version: Yokohama
  • Updated April 17, 2026
  • 11 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Enterprise Architecture Workspace access roles

    The Enterprise Architecture Workspace provides role-based access controls to manage and configure various functional areas of enterprise architecture in ServiceNow. Access roles govern permissions for users and groups, enabling efficient administration, data management, approval workflows, and visualization capabilities within the workspace.

    Show full answer Show less

    Key Roles and Access

    • snapm.apmadmin: Full administrative privileges including setup and configuration across all functional areas; typically assigned to EA administrators and IT architect leads.
    • snapm.apmanalyst: Manage portfolio records, approve or reject requests (requires membership in the Enterprise Architect group for approval actions); typical users are enterprise or solution architects.
    • snapm.apmuser: Create and update portfolio data across business, information, technology portfolios, modeling, and certification; suitable for application owners and analysts.
    • snapm.apmread: Read-only access to all workspace data and pages; ideal for business stakeholders, executives, and auditors.

    Roles can include other roles to inherit permissions, and membership in the Enterprise Architect group is required for approval and governance actions beyond role assignment alone.

    Enterprise Architect Group

    This group adds a governance layer enabling users with the analyst role to approve and reject key requests related to Technology Reference Model (TRM) products, product lifecycles, and modeling diagrams. Group membership is managed through administration settings and is essential for unlocking approval capabilities.

    Functional Area Capabilities

    • Setup and Plugin Activation: Administrators can activate key plugins (EA Workspace, TPM, TRM, Read-only roles) and configure setup options like application categories, scoring profiles, TRM phases, modeling settings, and certification policies.
    • Business Architecture: Manage business capabilities, units, goals, value streams, processes, and demands with full CRUD (create, read, update, delete) capabilities.
    • Application Portfolio: Add and edit business applications, digital integrations, interfaces, services, product capabilities, AI systems, and generate roadmaps and diagrams.
    • Information Portfolio: Manage data domains, architectural artifacts, decision records, and handle artifact versioning and sharing.
    • Technology Portfolio Management (TPM): Track software and hardware lifecycle data, update lifecycle and risk details, and run TPM-related jobs and audits.
    • Technology Reference Model (TRM): Approve TRM product requests, manage lifecycles, associate artifacts, view technical debt, and export catalog data (approval actions require Enterprise Architect group membership).
    • Enterprise Modeling and Visualization: Create and manage architecture diagrams, including ArchiMate, AWS, CSDM, BPMN, and custom shape libraries; diagram approval requires Enterprise Architect group membership.
    • Application Rationalization: Analyze and manage business applications with bubble chart and list views, lifecycle data, and demand management.
    • Data Certification: Govern data accuracy through certification policies, task management, and review workflows; requires specific certification roles for policy creation.
    • Dashboards: Access and filter dashboards for application assessments, portfolio health, and analytics.
    • Total Cost of Ownership (TCO): Manage direct and indirect costs related to business applications, configure dashboard properties, and view cost records.
    • Publishing Center: Publish TRM catalog data to knowledge bases and service portals, manage configurations and synchronization (requires both EA admin and knowledge admin roles).
    • Architecture Analyzer: Explore architectural relationships on an interactive canvas, create and manage explorations, and download visualizations.
    • AI Systems Integration: View AI governance data from AI Control Tower on business applications; full AI system record access requires additional AI Control Tower roles.
    • My Entities: Personalized view and management of owned or managed records across all portfolio types.

    Practical Implications for ServiceNow Customers

    Understanding and assigning these roles appropriately ensures secure and effective use of the Enterprise Architecture Workspace. Customers can:

    • Configure and govern enterprise architecture data and processes with clear role boundaries.
    • Enable approval workflows by assigning users to both roles and the Enterprise Architect group.
    • Leverage comprehensive portfolio management features spanning business, application, information, and technology domains.
    • Utilize advanced modeling, certification, rationalization, and cost management tools.
    • Integrate external AI governance data while maintaining role-based access control.
    • Publish architecture catalogs for broader organizational consumption via service portals.

    Proper role and group management is critical to unlocking functional capabilities while maintaining governance and compliance within the ServiceNow Enterprise Architecture Workspace.

    The following roles help you to configure and use the Enterprise Architecture Workspace application. After access has been granted to a role, all the groups or users assigned to the role are granted access. Roles can contain other roles, and any access granted to a role is granted to any other role that includes it.

    Enterprise Architecture Workspace roles

    The following roles are available in Enterprise Architecture Workspace. After access is granted to a role, all users and groups assigned to that role inherit the permissions. Roles can contain other roles, and any access granted to a role is also granted to any role that includes it.

    Table 1. Enterprise Architecture Workspace roles
    Role Description Typical persona
    sn_apm.apm_admin Full administrative access to configure and manage Enterprise Architecture Workspace settings, including Setup page configuration for all functional areas. Includes all permissions of sn_apm.apm_analyst. EA administrator, IT architect lead
    sn_apm.apm_analyst Create and manage key portfolio records such as business applications and digital integrations. Approve or reject requests when assigned to the Enterprise Architect group. Includes all permissions of sn_apm.apm_user. Enterprise architect, solution architect
    sn_apm.apm_user Create and update portfolio data across business architecture, information portfolio, technology portfolio, modeling, and data certification. Includes all permissions of sn_apm.apm_read. Application owner, business analyst, portfolio manager
    sn_apm.apm_read Read-only access to all pages and records in Enterprise Architecture Workspace. Cannot create or update data. For more information, see Business stakeholder role for Enterprise Architecture Workspace. Business stakeholder, executive, auditor

    Users with Enterprise Architecture Workspace roles and certain platform roles, such as ITIL and other CMDB related roles, may be able to create or edit Business Application records by default.

    Enterprise Architect group

    The Enterprise Architect group is a platform user group that acts as a governance layer on top of the standard role hierarchy. It is configured intentionally to separate approval authority from general role access: users with the sn_apm.apm_analyst role can perform approvals and governance actions only when they are also members of this group. Assigning the role alone is not sufficient for these actions.

    To add or modify members of the Enterprise Architect group, navigate to All > Enterprise Architecture > Administration > Services Approval Group > Enterprise Architect Group.

    The following table lists the capabilities that require membership in the Enterprise Architect group.

    Table 2. Capabilities requiring Enterprise Architect group membership
    Functional area Role also required Capabilities unlocked by group membership
    Technology Reference Model (TRM) sn_apm.apm_analyst
    • Approve or reject TRM product requests
    • Approve or reject TRM product lifecycle requests
    • Create TRM product lifecycles
    • View and update pending TRM requests
    Enterprise modeling and visualization sn_apm.apm_analyst
    • Approve or reject modeling diagram requests
    • View shape library configurations, entity configurations, and modeling configuration and relationship definitions

    Installation and plugin activation

    Plugin activation requires the global admin role.

    Capability admin sn_apm.apm_admin sn_apm.apm_analyst sn_apm.apm_user sn_apm.apm_read Notes

    Activate the EA Workspace plugin

    Yes

    Activate the Technology Portfolio Management (TPM) plugin

    Yes

    Activate the Technology Reference Model (TRM) plugin

    Yes

    Activate the Read only roles for Enterprise Architecture plugin

    Yes

    Setup page

    The Setup page provides configuration options for all functional areas in the workspace.

    Capability admin sn_apm.apm_admin sn_apm.apm_analyst sn_apm.apm_user sn_apm.apm_read Notes

    Configure application categories, category groups, and families

    Yes Yes

    Configure application and capability indicators

    Yes Yes

    Configure scoring profiles and attach profile indicators

    Yes Yes

    Configure TRM phases and TRM categories

    Yes Yes

    Configure information data domains

    Yes Yes

    Configure architectural artifact categories

    Yes Yes

    Configure demand actions

    Yes Yes

    Configure modeling settings, including shape libraries, entities, relationships, and diagram actions

    Yes Yes

    Configure total cost of ownership (TCO) sources, source cost types, and cost types; set TCO dashboard properties

    Yes

    Configure Publishing Center for TRM catalog publishing; modify TRM catalog publishing configurations; associate service portals with a TRM catalog knowledge base

    Yes Yes Yes Yes

    Requires sn_apm.apm_admin and knowledge_admin

    Add and edit certification policies from the Setup page (legacy CMDB-based policies)

    Yes Yes Yes Yes

    Requires certification_admin

    Business architecture

    Business architecture covers business capabilities, business units, departments, goals, value streams, value stream stages, business processes, and demands in the Portfolio List view.

    Capability admin sn_apm.apm_admin sn_apm.apm_analyst sn_apm.apm_user sn_apm.apm_read Notes

    Add and edit business capabilities and sub-capabilities

    Yes Yes Yes Yes

    Add and edit business units

    Yes Yes Yes Yes

    Add and edit departments; add users to departments

    Yes Yes Yes Yes

    Add and edit goals; add quantitative and qualitative targets; create sub-goals

    Yes Yes Yes Yes

    Add and edit value streams; add application models to value streams

    Yes Yes Yes Yes

    Add and edit value stream stages; associate business processes with value stream stages; add or remove business capabilities from value stream stages

    Yes Yes Yes Yes

    Add and edit business processes

    Yes Yes Yes Yes

    Add and edit demands

    Yes Yes Yes Yes

    Create demands from the Business Portfolio view and Application Rationalization views

    Yes Yes Yes Yes

    Export business portfolio data

    Yes Yes Yes Yes

    View all business architecture records

    Yes Yes Yes Yes Yes

    Application portfolio

    The application portfolio covers business applications, application services, digital integrations, digital interfaces, and product capabilities.

    Capability admin sn_apm.apm_admin sn_apm.apm_analyst sn_apm.apm_user sn_apm.apm_read Notes

    Add new business applications

    Yes Yes Yes

    Add and edit digital integrations; associate artifacts and information objects with digital integrations

    Yes Yes Yes

    Add and edit digital interfaces; manage Agile Development components, information objects, and credentials; relate a digital interface to an API

    Yes Yes Yes

    Update business application details

    Yes Yes Yes Yes

    Associate and unassign business capabilities, product capabilities, architectural artifacts, information objects, and TRM products with business applications

    Yes Yes Yes Yes

    Create diagrams and unified maps from a business application

    Yes Yes Yes Yes

    View the business application roadmap

    Yes Yes Yes Yes

    Add and edit application services

    Yes Yes Yes Yes

    Add and edit product capabilities; view all product capabilities

    Yes Yes Yes Yes

    View and manage AI systems and AI portfolio items associated with business applications

    Yes Yes Yes Yes

    Run the job to generate model IDs for business applications

    Yes Yes Yes Yes

    View all business applications, application services, digital integrations, digital interfaces, and associated records

    Yes Yes Yes Yes Yes

    Information portfolio

    The information portfolio covers data domains, information objects, architectural artifacts, and architectural decision records (ADRs).

    Capability admin sn_apm.apm_admin sn_apm.apm_analyst sn_apm.apm_user sn_apm.apm_read Notes

    Add and edit data domains and information objects

    Yes Yes Yes Yes

    Create and edit architectural artifacts; add versions, related entities, and associated records

    Yes Yes Yes Yes

    Share architectural artifacts with users and groups; manage access permissions for architectural artifacts

    Yes Yes Yes Yes

    Request approval for an artifact version; download and delete architectural artifact versions

    Yes Yes Yes Yes

    Create and edit architectural decision records (ADRs); add pages, subpages, and versions to ADRs

    Yes Yes Yes Yes

    Tag users and records in an ADR document; request approval for an ADR

    Yes Yes Yes Yes

    Associate architectural artifacts with business applications, capabilities, business processes, digital integrations, and TRM products

    Yes Yes Yes Yes

    View all data domains, information objects, architectural artifacts, artifact versions, and ADRs

    Yes Yes Yes Yes Yes

    Technology Portfolio Management (TPM)

    Technology Portfolio Management tracks software and hardware lifecycle data for business applications and application services.

    Capability admin sn_apm.apm_admin sn_apm.apm_analyst sn_apm.apm_user sn_apm.apm_read Notes

    Activate the TPM plugin

    Yes

    Update the system property to gather software from CMDB

    Yes

    Update TPM lifecycle data for a business application or application service

    Yes Yes Yes Yes

    View technology lifecycle data and technology risk information

    Yes Yes Yes Yes

    View technology portfolio audit risk details and update verification status

    Yes Yes Yes Yes

    Run the job to populate TPM lifecycle data

    Yes Yes Yes Yes

    Run the scheduled job to update TPM data

    Yes Yes Yes Yes

    Run the scheduled job to generate TPM risk; restart the TPM scheduled job

    Yes Yes Yes Yes

    View TPM logs; run the job to populate TPM lifecycle identifiers

    Yes Yes Yes Yes

    View technology portfolio data, lifecycle timelines, and risk information

    Yes Yes Yes Yes Yes

    Technology Reference Model (TRM)

    The Technology Reference Model provides a structured catalog of approved technologies and their lifecycle phases.

    Capability admin sn_apm.apm_admin sn_apm.apm_analyst sn_apm.apm_user sn_apm.apm_read Notes

    Activate the TRM plugin

    Yes

    Approve or reject TRM product requests

    Yes Yes Yes

    Must be in the Enterprise Architect group

    Approve or reject TRM product lifecycle requests; create TRM product lifecycles

    Yes Yes Yes

    Must be in the Enterprise Architect group

    View and update pending TRM requests

    Yes Yes Yes

    Must be in the Enterprise Architect group

    View all TRM products, grouped by category or individually

    Yes Yes Yes Yes

    View all TRM phases and categories

    Yes Yes Yes Yes

    Request a new TRM product; request a TRM product lifecycle change

    Yes Yes Yes Yes

    Create TRM product lifecycle requests

    Yes Yes Yes Yes

    Associate architectural artifacts with TRM products

    Yes Yes Yes Yes

    View, create, add, and remove business capabilities and business applications associated with TRM products

    Yes Yes Yes Yes

    View TRM technical debt; run the job to generate TRM technical debts

    Yes Yes Yes Yes

    Export TRM product catalog data

    Yes Yes Yes Yes

    View TRM products, categories, phases, technical debt, and lifecycle timelines

    Yes Yes Yes Yes Yes

    Enterprise modeling and visualization

    Enterprise modeling and visualization lets users create, manage, and publish architecture diagrams.

    Capability admin sn_apm.apm_admin sn_apm.apm_analyst sn_apm.apm_user sn_apm.apm_read Notes

    Approve or reject modeling diagram requests

    Yes Yes Yes

    Must be in the Enterprise Architect group

    View shape library configurations, entity configurations, modeling configuration, and relationship definitions

    Yes Yes Yes

    Must be in the Enterprise Architect group

    Create empty diagrams and synchronize them with the ServiceNow database

    Yes Yes Yes Yes

    Create business capability maps (BC maps), business application maps (BA maps), and business process maps (BP maps)

    Yes Yes Yes Yes

    Create ArchiMate diagrams, AWS architecture diagrams, and CSDM diagrams

    Yes Yes Yes Yes

    Add, remove, group, ungroup, expand, collapse, and delete shapes

    Yes Yes Yes Yes

    Add related records to shapes; add labels to connector lines

    Yes Yes Yes Yes

    Reorder shapes in a category; show or hide the Shapes panel; toggle between grid and list view; filter shapes

    Yes Yes Yes Yes

    Save a diagram as new; duplicate a diagram

    Yes Yes Yes Yes

    Submit a diagram for approval; synchronize a diagram and individual shapes

    Yes Yes Yes Yes

    Share a diagram; download a diagram; add or edit diagram version details; delete a diagram

    Yes Yes Yes Yes

    Create and manage custom shape libraries, custom shape elements, and custom shape actions; store images in the database for custom shapes

    Yes Yes Yes Yes

    Modify BPMN diagrams

    Yes Yes Yes Yes

    View diagrams and diagram details

    Yes Yes Yes Yes Yes

    Application rationalization

    Application rationalization helps users assess and manage business applications through bubble chart and list views.

    Capability admin sn_apm.apm_admin sn_apm.apm_analyst sn_apm.apm_user sn_apm.apm_read Notes

    Analyze business applications in the bubble chart view by capability

    Yes Yes Yes Yes

    Create demands from the bubble chart view and list view

    Yes Yes Yes Yes

    Set the planned disposition of a business application

    Yes Yes Yes Yes

    Add and edit business application lifecycle data

    Yes Yes Yes Yes

    Edit business application details from the bubble chart and list views

    Yes Yes Yes Yes

    Edit demands and projects associated with a business application

    Yes Yes Yes Yes

    Update the system property to change the number of bubbles displayed

    Yes Yes Yes Yes

    Apply filters on the application rationalization view

    Yes Yes Yes Yes

    Export application rationalization list data

    Yes Yes Yes Yes

    View application rationalization data in bubble chart and list views

    Yes Yes Yes Yes Yes

    Data certification

    Data certification provides a governance mechanism to promote that architecture data is accurate and complete.

    Capability admin sn_apm.apm_admin sn_apm.apm_analyst sn_apm.apm_user sn_apm.apm_read Notes

    Create data certification policies using the certification policy wizard

    Yes Yes Yes Yes

    Requires system admin, CMDB admin, and sn_apm.apm_analyst

    Publish draft certification policies

    Yes

    Run data certification policies

    Yes

    Activate and deactivate certification policies; delete certification policies

    Yes

    Track certification progress across policies

    Yes

    Review and certify data certification tasks assigned to them

    Yes Yes Yes Yes

    User must be assigned a certification task

    Fail records that do not meet certification standards

    Yes Yes Yes Yes

    User must be assigned a certification task

    Reassign certification tasks to other users or groups; request reassignment

    Yes Yes Yes Yes

    User must be assigned a certification task

    Submit completed certification reviews

    Yes Yes Yes Yes

    User must be assigned a certification task

    View certification policies and certification status

    Yes Yes Yes Yes Yes

    Dashboards

    Dashboards provide visibility into application health, assessment scores, and portfolio performance.

    Capability admin sn_apm.apm_admin sn_apm.apm_analyst sn_apm.apm_user sn_apm.apm_read Notes

    View and monitor the Applications Assessment dashboard

    Yes Yes Yes

    View and monitor the Application 360 dashboard

    Yes Yes Yes

    View the workspace home dashboard and portfolio overview and health section

    Yes Yes Yes Yes

    Apply filters on the portfolio overview and health view

    Yes Yes Yes Yes

    View dashboards

    Yes Yes Yes Yes Yes

    Total Cost of Ownership (TCO)

    Total Cost of Ownership tracks and manages direct and indirect costs associated with business applications.

    Capability admin sn_apm.apm_admin sn_apm.apm_analyst sn_apm.apm_user sn_apm.apm_read Notes

    Activate the App TCO plugin

    Yes

    Create TCO sources, TCO source cost types, and TCO cost types

    Yes

    Set properties for TCO dashboards

    Yes

    View all TCO records for business applications

    Yes Yes Yes Yes

    create TCO records

    Yes Yes Yes Yes

    View TCO records

    Yes Yes Yes Yes Yes

    Publishing Center

    The Publishing Center lets administrators publish TRM catalog data to a knowledge base for consumption through a service portal.

    Capability admin sn_apm.apm_admin sn_apm.apm_analyst sn_apm.apm_user sn_apm.apm_read Notes

    Create and modify TRM catalog publishing configurations

    Yes Yes Yes Yes

    Requires sn_apm.apm_admin and knowledge_admin

    Configure TRM data to publish; manage article configurations

    Yes Yes Yes Yes

    Requires sn_apm.apm_admin and knowledge_admin

    Associate portals with a TRM catalog knowledge base

    Yes Yes Yes Yes

    Requires sn_apm.apm_admin and knowledge_admin

    Enable automatic synchronization of published catalogs

    Yes Yes Yes Yes

    Requires sn_apm.apm_admin and knowledge_admin

    Publish and republish TRM catalogs to the knowledge base

    Yes Yes Yes Yes

    Requires sn_apm.apm_admin and knowledge_admin

    Retire and archive published TRM catalogs; view publishing run logs

    Yes Yes Yes Yes

    Requires sn_apm.apm_admin and knowledge_admin

    Access published TRM catalog content through the service portal

    Yes Yes Yes Yes Yes

    Architecture Analyzer

    The Architecture Analyzer lets users explore and visualize relationships between architectural entities on an interactive canvas.

    Capability admin sn_apm.apm_admin sn_apm.apm_analyst sn_apm.apm_user sn_apm.apm_read Notes

    create explorations on the Architecture Analyzer canvas

    Yes Yes Yes Yes

    Add entities to the canvas by selecting entity type and specific record

    Yes Yes Yes Yes

    Add upstream and downstream related entities to a selected entity on the canvas

    Yes Yes Yes Yes

    Show or hide the left navigation pane and the Add to canvas panel

    Yes Yes Yes Yes

    Clear all entities from the canvas

    Yes Yes Yes Yes

    Download an exploration canvas as an image

    Yes Yes Yes Yes

    Rename an exploration; delete an exploration

    Yes Yes Yes Yes

    View existing explorations

    Yes Yes Yes Yes Yes

    AI systems — AI Control Tower integration

    The AI systems integration surfaces AI governance data from AI Control Tower directly on business application records. Viewing full AI system records in AI Control Tower requires roles from the AI Control Tower application in addition to EA Workspace roles.

    Capability admin sn_apm.apm_admin sn_apm.apm_analyst sn_apm.apm_user sn_apm.apm_read Notes

    View the AI systems tab on a business application record

    Yes Yes Yes Yes

    View AI system details including lifecycle phase, state, lifecycle status, and risk classification

    Yes Yes Yes Yes

    Add an existing AI Control Tower AI system to a business application

    Yes Yes Yes Yes

    Remove an AI system association from a business application

    Yes Yes Yes Yes

    Open and view the full AI system record in the AI Control Tower workspace

    Yes Yes Yes Yes

    Requires sn_ai_governance.ai_governance_workspace_user (AI Control Tower role)

    View full AI system governance details in AI Control Tower, including related models, datasets, prompts, approval history, and lifecycle tasks

    Yes Yes Yes Yes

    Requires sn_aig.ai_steward or sn_aig.ai_asset_owner (AI Control Tower roles)

    Manage AI system associations with business applications from the AI Control Tower side

    Yes Yes Yes Yes

    Requires sn_aig.ai_steward or sn_aig.ai_asset_owner (AI Control Tower roles)

    View the AI systems tab on a business application record

    Yes Yes Yes Yes Yes

    My Entities

    My Entities provides a personalized view of the records you own or manage, across all portfolio types.

    Capability admin sn_apm.apm_admin sn_apm.apm_analyst sn_apm.apm_user sn_apm.apm_read Notes

    View and manage your business capabilities, business processes, and business applications

    Yes Yes Yes Yes

    View and manage your application services, information objects, and architectural artifacts

    Yes Yes Yes Yes

    View and manage your TRM products, digital integrations, and digital interfaces

    Yes Yes Yes Yes

    View your assigned entities

    Yes Yes Yes Yes Yes