---
sourceDocument: Yokohama Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/governance-risk-compliance

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Assign Policy and Compliance Management roles to your users

# Assign Policy and Compliance Management roles to your users {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Before you can successfully implement or use the Policy and Compliance Management
application, you must assign roles to your users.

## Before you begin

Role required: admin

## Procedure

1. Navigate to AllUser AdministrationUsers.
2. Click the name of a user.
3. Click the Roles tab.
4. Click Edit.
5. Move the roles you want to assign to the user from the Collection side to the Roles List, then click Save.
6. Repeat these steps for each of your users.  
   For a comprehensive list of compliance users, see [Roles installed with GRC: Policy and Compliance Management](https://servicenow-prod.fluidtopics.net/~gShiUy2g2pFAN3Gu7VLNQ#r_RolesInstallWPolAndCompl "Roles are added with activation of GRC: Policy and Compliance Management.").
   {#assign-user-roles__table_o14_t2s_2mb__entry__2}

   | Role title \[name\] | Description |
   |-|-|
   | Compliance Reader \[sn_compliance.reader\] | The Compliance Reader has read-only access to all modules of the Policy and Compliance Management application. This role is typically assigned to users who need to see what policies and controls are within the organization. Users with the reader role are also often responsible for reporting and monitoring activities. The Compliance Reader role contains: sn_grc.reader. |
   | Compliance User \[sn_compliance.user\] | The Compliance User, often referred to as the Compliance Analyst, has permissions enough to fulfill virtually any policy- or control-related task. Users assigned this role are often responsible for: * Creating new policies * Requesting policy exceptions * Responding to acknowledgement requests * Creating controls objectives and relating them to policies * Testing and monitoring control effectiveness * Attesting controls * Remediating issues * Assisting with risk assessments and audit tasks {#assign-user-roles__ul_ak3_nfs_2mb} The Compliance User role contains: * sn_grc.reader * sn_grc.user * sn_compliance.reader {#assign-user-roles__ul_asj_lrv_xv} Note: Users with the Compliance User role can be assigned controls, and have read-only access to the Risk Management application and modules. |
   | Compliance Manager \[sn_compliance.manager\] | The Compliance Manager is responsible for managing the day-to-day compliance process. Users assigned this role are often responsible for: * Reviewing specific regulatory requirements and trends * Determining which regulations require a policy * Approving policies and policy exceptions * Setting up a policy acknowledgement campaign * Scoping controls using entity types and entities * Creating and assigning attestations * Continuously monitoring control effectiveness * Compiling and sharing reports highlighting data, such as non-compliant controls {#assign-user-roles__ul_vf2_mgs_2mb} The Compliance Manager role contains: * sn_grc.reader * sn_grc.user * sn_grc.manager * sn_compliance.reader * sn_compliance.user {#assign-user-roles__ul_vw5_mnz_pv} |
   | Compliance Administrator \[sn_compliance.admin\] | The Compliance Administrator administers the Policy and Compliance Management application. Users assigned this role are often responsible for: * Monitoring platform dependencies with other applications and modules * Controlling all compliance data {#assign-user-roles__ul_v5d_mhs_2mb} The Compliance Administrator role contains: * sn_grc.reader * sn_grc.user * sn_grc.manager * sn_grc.admin * sn_compliance.reader * sn_compliance.user * sn_compliance.manager {#assign-user-roles__ul_sf3_j5v_xv} |
   | Compliance Developer \[sn_compliance.developer\] | The Compliance Developer is responsible for maintaining various aspects of the platform, such as creating workflows, reports, dashboards, additional modules, and other platform-specific content that can enrich the application. The Compliance Developer role contains: * sn_grc.reader * sn_grc.user * sn_grc.manager * sn_grc.admin * sn_grc.developer * sn_compliance.reader * sn_compliance.user * sn_compliance.manager * sn_compliance.admin {#assign-user-roles__ul_yt2_m5v_xv} |
   | Attestation Creator sn_compliance.attestation_creator | The Attestation Creator is responsible for creating and maintaining attestations. Attestations are one of the platform components used to attest controls and it is essential for keeping them lean, precise, and up-to-date. |
   [ ]

   {#assign-user-roles__table_o14_t2s_2mb}

## What to do next

Return to the [Policy and Compliance Management setup checklist](https://servicenow-prod.fluidtopics.net/yUU~_WGfgLESrYkAjhJRyA "This checklist includes the setup tasks that you are required to complete in your ServiceNow AI Platform instance. When you have completed these tasks, the base system is ready for operation. Optional setup procedures are also included to enhance GRC: Policy and Compliance Management functionality.").

*[\>]: and then


