---
sourceDocument: Yokohama Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/governance-risk-compliance

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# User hierarchy access control for issue and remediation task records

# User hierarchy access control for issue and remediation task records {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

If a user is assigned to an issue or a remediation task, then the manager of the user
and the manager above in the hierarchy also get access to the issue or remediation task
record.

The user reference in the Assigned to field, Opened by field, or Owner field are configurable in the User
hierarchy configurations \[sn_grc_user_hierarchy_configuration\] table. Therefore, you can
configure the fields in the table and enter the user reference, for example Assigned to or Issue Manager as User reference field 1 or User
reference field 2. However, you can configure only two fields in a table.

The manager of the user in the user reference field and the manager above in the hierarchy can
be configured as User hierarchy field 1 and User hierarchy field 2, respectively. If one of them
is no longer the manager of the user in the user reference field, then that user in the hierarchy
loses access to the record. You can view the hierarchy of users in the User Hierarchy
\[sn_grc_user_hierarchy\] table.  
The prerequisites to enable user hierarchy access control are:

* Users in the hierarchy must have at least the GRC business user (sn_grc.business_user) role.
* The sn_grc.enable_user_hierarchy_access_control system property must be set as true.
{#user-hierarchy-risk-remed-task__ul_f1q_nlp_nsb}

The concept of user hierarchy is helpful as it provides more visibility to the users in the
hierarchy in tracking its completion when it is assigned to a user in a team. User hierarchy
fields are not visible in the Issue or Remediation task form, however internally this feature
enables you to restrict access to records based on those users in the hierarchy who can access
them.

