---
sourceDocument: Yokohama Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/governance-risk-compliance

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# access-control-by-legal-entity

# Access control through organizational structure {#ariaid-title1}

* Release version: Yokohama
* 
* Updated November 27, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Describes how access to processing activity records can be restricted by using Entity-Based Access (EBA).
User access to processing activity records and related data can be restricted based on an organizational structure. This structure may reflect a legal entity, jurisdiction, business unit, or any segmentation aligned with how your
privacy teams operate. This approach enables granular security and supports regulatory compliance for organizations functioning across multiple regions or subsidiaries.

Entity-Based Access (EBA) implements this control by enforcing data segregation according to the defined organizational structure. With EBA, users can only view and manage records for the entities or jurisdictions to which they have
been explicitly granted access. Records outside this defined scope remain hidden.

## Key characteristics {#access-control-by-legal-entity__section_j3f_3hf_lhc}

* Dynamic segmentation: Access can be assigned based on the organizational structure, such as legal entity, jurisdiction, business unit, or any defined grouping. So processing activity records are only visible to the appropriate teams.
* Regulatory alignment: Access controls can be mapped to organizational structures, helping organizations meet local regulatory requirements and maintain clear audit trails.

{#access-control-by-legal-entity__ul_nzg_khf_lhc}

For information about configuring access control, see [Configure access control](https://servicenow-prod.fluidtopics.net/FHCJpDCJXwLQGJ7kQNHqyw "Describes the step-by-step process for configuring Entity-based access control in Privacy Management, including property activation, hierarchy setup, record mapping, user assignment, bulk updates, and activating entity-based record access rules.").

## UI impact {#access-control-by-legal-entity__section_jjg_mtm_lhc}

* Processing activity details: Hidden for records outside the user's scope.
* Data lineage: Information for inaccessible entities is hidden, and navigation buttons on the side panel are disabled.
* Reports and dashboards: Visibility in reports such as processing activity, risk scan, and compliance is filtered based on entity configuration.
{#access-control-by-legal-entity__ul_hnj_dfn_lhc}

## Role capabilities {#access-control-by-legal-entity__section_a3z_g5m_lhc}

{#access-control-by-legal-entity__table_gyj_m5m_lhc__entry__2}

| Role | Capabilities |
|-|-|
| Privacy admin | * Create entity configurations * Perform bulk access updates {#access-control-by-legal-entity__ul_upz_p5m_lhc} |
| Privacy manager | View entity configurations |
| Privacy analyst | Access records for configured entities and their associated downstream entities |
| Privacy business user | Access records for configured entities and their associated downstream entities |
[Table 1. Role capabilities]

{#access-control-by-legal-entity__table_gyj_m5m_lhc}  
Note:  
Assigned roles such as assignee, reviewer, and analyst retain access to their assigned records even if those records fall outside the configured entity.
* **[Configure access control](https://servicenow-prod.fluidtopics.net/FHCJpDCJXwLQGJ7kQNHqyw)**   
  Describes the step-by-step process for configuring Entity-based access control in Privacy Management, including property activation, hierarchy setup, record mapping, user assignment, bulk updates, and activating entity-based record access rules.
* **[Configure Entity-based access](https://servicenow-prod.fluidtopics.net/3diUhMTQVZKwZAxPRvSb_g)**   
  Configure entity-based access by installing the Entity-based Access Configurations plugin and enabling properties for record types.
* **[Create an entity configurations](https://servicenow-prod.fluidtopics.net/y8EDl~hE8OrACYgHfQ2dZw)**   
  Create an organizational structure by configuring entity-based access for different levels such as headquarters, regional offices, and subsidiaries, and define access rules for users and groups.
* **[Add hierarchical relationships between entities](https://servicenow-prod.fluidtopics.net/XM3wRdmxKxPVPdd9ZxCilg)**   
  Define hierarchical relationships between entities (Global → Regional → Country-level) using Upstream and Downstream options. Adding an hierarchy creates a clear organizational structure.
* **[Set access restrictions using an entity based record access update utility](https://servicenow-prod.fluidtopics.net/0i3JmNK92X8YOx_quiqkbA)**   
  Set access restrictions for the existing records in bulk by using the Entity based record access update utility guided-experience. Use the workflow to enable or disable access to record types.
* **[Set Entity based record access rules](https://servicenow-prod.fluidtopics.net/wofOtNj6z8ONYPMORTt2~A)**   
  Use entity-based record access rules to secure records and enable continuous monitoring. These rules automatically apply restrictions to new or modified records, ensuring access settings stay enforced without manual updates. When entities or processing activities change, the system updates access controls automatically.

