---
sourceDocument: Yokohama Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/governance-risk-compliance

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Roles installed with Operational Resilience

# Roles installed with Operational Resilience {#ariaid-title1}

* Release version: Yokohama
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Roles installed with Operational Resilience

The Operational Resilience application in ServiceNow includes several predefined roles designed to manage operational resilience, business continuity management (BCM), and integrated risk management (IRM).
These roles enable users to configure scenarios, review reports, manage vulnerabilities, and access specialized workspaces depending on their responsibilities.
Understanding these roles helps organizations assign proper permissions and streamline operational resilience activities.
Show full answer Show less  

## Key Roles and Responsibilities

* **Operational Resilience Administrator (\[snoperres.admin\])**: Configures scenarios, entity types, filters, and reporting pillars; customizes dashboards; requires ITIL role for CMDB relationships; includes several admin-level roles for governance and vulnerability management.
* **Operational Resilience Manager (\[snoperres.manager\])**: Oversees operational resilience using dashboards and reports; includes roles for case management and risk review.
* **Operational Resilience User (\[snoperres.user\])**: Reviews dashboards and supporting data; completes impact tolerance and test plans; accesses vulnerability response data; can submit operational vulnerability reports.
* **BCM and Operational Resilience Roles**: Comprise Administrator, Manager, and User roles with permissions to access both Operational Resilience and BCM workspaces, depending on the role level. The User role can view BCM UIB Workspace but not IRM data.
* **IRM Operational Resilience Roles**: Include Administrator, Manager, and User roles focused on operational resilience within IRM, excluding access to BCM reports and data. These roles include compliance and risk reader permissions when applicable.
* **Incident Reporting Roles**: Roles such as Digital Resilience Incident Admin, Manager, and User support the reporting and management of digital resilience incidents.

## Role Families and Lite Apps

When Lite applications for BCM or IRM are installed, specific roles like `snoperres.bcmopresuser` and `snoperres.irmopresuser` become Lite operators. These roles allow access to corresponding Operational Resilience and BCM Configurable Workspaces but may restrict access to full Compliance or Risk Workspaces unless additional roles are assigned.

## Workspace Access

* Operational Resilience and BCM Configurable Workspace access is granted to users with BCM Operational Resilience roles.
* Operational Resilience Workspace access is available for IRM Operational Resilience roles.
* Risk and Compliance Workspaces require specific risk and compliance manager or analyst roles.

## Plugin Dependencies

* **BCM Professional**: Requires Business Continuity Planning, Business Impact Analysis, Crisis Management, and Data Relationships Framework applications. Vulnerability Response is optional.
* **IRM Professional**: Requires Advanced Risk Assessment, Data Relationships Framework, Policy and Compliance Management, and Risk Management applications. Vulnerability Response is optional.

## Practical Implications for ServiceNow Customers

Assigning the correct Operational Resilience roles ensures that users have appropriate access to configure scenarios, manage risks, view dashboards, and report incidents effectively. Understanding the distinctions between BCM and IRM roles, especially under Lite app installations, allows customers to tailor permissions to organizational needs. Additionally, awareness of plugin dependencies helps in planning installations and upgrades for full functionality within Operational Resilience.  
Several types of roles are installed with the Operational Resilience application.

## Roles that are installed with Operational Resilience {#roles-installed-with-op-res__section_esl_zl2_4tb}

Note:  
For more information on roles and FAQs, see [KB0555605](https://support.servicenow.com/nav_to.do?uri=/kb?id=kb_article_view&sysparm_article=KB0555605). {#roles-installed-with-op-res__table_rnp_cm2_4tb__entry__2}

| Role name | Description |
|-|-|
| Operational Resilience administrator \[sn_oper_res.admin\] | The Operational Resilience administrator is responsible for: * Configuring scenarios * Setting up entity types, entity filters, and reporting pillars based on dashboard requests from the business teams. * Customizing reports on the Operational Resilience dashboard. {#roles-installed-with-op-res__ul_rqc_k4r_lnb} The Operational Resilience administrator should have the ITIL role to add the CMDB relationship between the service and the process. The Operational Resilience administrator role contains the following roles: * sn_grc.admin * sn_oper_res.manager * Contains sn_grc_case_mgmt.grc_case_admin, who inherits the ability to set up the vulnerability type, state models, vulnerability assessment templates, and document templates. {#roles-installed-with-op-res__ul_h3v_v2s_2mb} |
| Operational Resilience Manager \[sn_oper_res.manager\] | The Operational Resilience Manager is responsible for: * Ensuring operational resilience in the organization using the dashboards and reports * Reviewing reports on the Operational Resilience dashboard, as well as supporting data. {#roles-installed-with-op-res__ul_jhq_m4r_lnb} The Operational Resilience Manager role contains the following roles: * sn_grc.manager * sn_compliance.reader * sn_oper_res.user * sn_risk.reader * Contains sn_grc_case_mgmt.grc_case_manager, who inherits the ability to submit operational vulnerability (A type of case). {#roles-installed-with-op-res__ul_vw5_mnz_pv} |
| Operational Resilience User \[sn_oper_res.user\] | The Operational Resilience User is responsible for: * Reviewing reports on the Operational Resilience dashboard, as well as supporting data. * Completing impact tolerance and test plans for individuals assigned to the service impact analysis. {#roles-installed-with-op-res__ul_krn_p4r_lnb} The Operational Resilience User can access the Vulnerability Response data. The Operational Resilience User role contains the following roles: * sn_incident.read * sn_grc.reader * task_editor * Contains sn_grc_case_mgmt.grc_case_business_user, who can be assigned tasks or issues in the operational vulnerability. {#roles-installed-with-op-res__ul_sf3_j5v_xv} |
| sn_oper_res.operational_resilience_business_user | Submits "Report operational vulnerability" from the employee center from: instancename/esc?id=emp_taxonomy_topic\&topic_id=14aedd93a314121051b1ab18951e6150\&in_context=true |
| BCM and Operational Resilience Administrator \[sn_oper_res.bcm_opres_admin\] | The BCM and Operational Resilience Administrator role contains the following roles: * sn_oper_res.bcm_opres_manager * sn_oper_res.admin {#roles-installed-with-op-res__ul_jtk_xtr_4zb} |
| BCM and Operational Resilience Manager \[sn_oper_res.bcm_opres_manager\] | The BCM and Operational Resilience Manager role contains the following roles: * sn_oper_res.bcm_opres_user * sn_oper_res.manager {#roles-installed-with-op-res__ul_dnb_35r_4zb} |
| BCM and Operational Resilience User \[sn_oper_res.bcm_opres_user\] | The BCM and Operational Resilience User role has the following permissions: * Can read the BCM UIB Workspace. * Cannot access the IRM reports or data. {#roles-installed-with-op-res__ul_q55_k4f_zzb}The BCM and Operational Resilience User role contains the following roles: * sn_bcm.viewer * sn_oper_res.user {#roles-installed-with-op-res__ul_szm_k5r_4zb} |
| IRM Operational Resilience User \[sn_oper_res.irm_opres_user\] | The Integrated Risk Management (IRM) Operational Resilience User role cannot access the BCM reports and data. It contains: * sn_grc.reader * sn_oper_res.user {#roles-installed-with-op-res__ul_lyy_mh4_d1c} The following user roles are contained only when policy and compliance management and risk management are installed: * sn_compliance.reader * sn_risk.reader {#roles-installed-with-op-res__ul_wsd_ph4_d1c} |
| IRM Operational Resilience Administrator \[sn_oper_res.irm_opres_admin\] | The IRM Operational Resilience Administrator role contains the following roles: * sn_oper_res.irm_opres_manager * sn_oper_res.admin {#roles-installed-with-op-res__ul_c3f_l5r_4zb} |
| IRM Operational Resilience Manager \[sn_oper_res.irm_opres_manager\] | The IRM Operational Resilience Manager role contains the following roles: * sn_oper_res.irm_opres_user * sn_oper_res.manager {#roles-installed-with-op-res__ul_jsl_l5r_4zb} |
[Table 1. Roles installed with Operational Resilience]

{#roles-installed-with-op-res__table_rnp_cm2_4tb} {#roles-installed-with-op-res__table_mqg_zbg_zzb__entry__3}

| Roles | Family | Comments |
|-|-|-|
| sn_oper_res.admin | IRM | None |
| sn_oper_res.manager | IRM | None |
| sn_oper_res.user | IRM | The sn_oper_res.user role is required to access Vulnerability profile records. |
| New roles introduced ||   |
| sn_oper_res.bcm_opres_admin | BCM | The sn_bcm.viewer role is required to access the BCM Configurable Workspace.​ A user with the sn_oper_res.bcm_opres_user+ role can access both Operational Resilience Workspace and BCM Configurable Workspace. |
| sn_oper_res.bcm_opres_manager | BCM | The sn_bcm.viewer role is required to access the BCM Configurable Workspace.​ A user with the sn_oper_res.bcm_opres_user+ role can access both Operational Resilience Workspace and BCM Configurable Workspace. |
| sn_oper_res.bcm_opres_user | BCM | The sn_bcm.viewer role is required to access the BCM Configurable Workspace.​ A user with the sn_oper_res.bcm_opres_user+ role can access both Operational Resilience Workspace and BCM Configurable Workspace. |
| sn_oper_res.irm_opres_admin | IRM | A user with the sn_oper_res.irm_opres_user+​ role can access the Operational Resilience Workspace, but cannot access the Compliance Workspace and Risk Workspace. ​ Extra roles are needed to access the Compliance Workspace and Risk Workspace. |
| sn_oper_res.irm_opres_manager | IRM | A user with the sn_oper_res.irm_opres_user+​ role can access the Operational Resilience Workspace, but cannot access the Compliance Workspace and Risk Workspace. ​ Extra roles are needed to access the Compliance Workspace and Risk Workspace. |
| sn_oper_res.irm_opres_user | IRM | A user with the sn_oper_res.irm_opres_user+​ role can access the Operational Resilience Workspace, but cannot access the Compliance Workspace and Risk Workspace. ​ Extra roles are needed to access the Compliance Workspace and Risk Workspace. |
[Table 2. Model types when Lite Apps are installed]

{#roles-installed-with-op-res__table_mqg_zbg_zzb}

## Roles created for BCM Professional and IRM Professional {#roles-installed-with-op-res__section_rpd_51v_zzb}

* The following roles are created for the BCM Professional users:  
  Note:  
  When the app-grc-bcm-lite applications are not installed, the users with these roles are counted as operators.
  * sn_oper_res.bcm_opres_admin
  * sn_oper_res.bcm_opres_manager
  * sn_oper_res.bcm_opres_user
  {#roles-installed-with-op-res__ul_hpy_by2_11c}
* The following roles are created for the IRM Professional users:  
  Note:  
  When the app-grc-bcm-lite applications are not installed, the users with these roles are counted as operators.
  * sn_oper_res.irm_opres_admin
  * sn_oper_res.irm_opres_manager
  * sn_oper_res.irm_opres_user
  {#roles-installed-with-op-res__ul_fj5_gy2_11c}
* When the following Lite applications are installed, the users with the sn_oper_res.bcm_opres_user, sn_oper_res.irm_opres_user, or sn_oper_res.user roles are counted as Lite operators.
  * BCM Lite application: app-grc-bcm-lite (Plugin id: com.snc.app_grc_bcm_lite)
  * IRM Lite application: app-grc-business-user-lite (Plugin id: com.sn_grc_lite)
  {#roles-installed-with-op-res__ul_jtd_3bv_zzb}
* The sn_oper_res.admin, sn_oper_res.manager, and sn_oper_res.user roles are included in IRM.
{#roles-installed-with-op-res__ul_z2k_fbv_zzb}

## Roles required for accessing the Workspaces {#roles-installed-with-op-res__section_xny_kcv_zzb}

A user with one of the following roles can access the Operational Resilience Workspace and BCM Configurable Workspace:

* sn_oper_res.bcm_opres_user
* sn_oper_res.bcm_opres_manager
* sn_oper_res.bcm_opres_admin
{#roles-installed-with-op-res__ul_jj1_jdv_zzb}  
A user with any following role can access the Operational Resilience Workspace:

* sn_oper_res.irm_opres_user
* sn_oper_res.irm_opres_manager
* sn_oper_res.irm_opres_admin
{#roles-installed-with-op-res__ul_ikc_ndv_zzb}  
A user with one of the following roles can access the Risk Workspace:

* sn_risk_workspace.business_op_risk_manager
* sn_risk_workspace.IT_risk_manager
* sn_risk_workspace.operatonal_risk_manager
{#roles-installed-with-op-res__ul_rdd_zcv_zzb}  
A user with one of the following roles can access the Compliance Workspace:

* sn_compliance_ws.corporate_compliance_analyst
* sn_compliance_ws.corporate_compliance_manager
* sn_compliance_ws.it_compliance_manager
{#roles-installed-with-op-res__ul_w5q_tcv_zzb}

## Roles used for reporting the incidents {#roles-installed-with-op-res__section_h4y_hnh_ydc}

The following roles are used for reporting incidents in the Digital resilience incident reporting module.{#roles-installed-with-op-res__table_shh_mnh_ydc__entry__2}

| Role | Description |
|-|-|
| sn_dri_inc_rptg.digital_resilience_incident_admin | Role for setting up administrative and Digital resilience incident activities. |
| sn_dri_inc_rptg.digital_resilience_incident_manager | Role for creating Operational Resilience and Digital resilience incident activities. |
| sn_dri_inc_rptg.digital_resilience_incident_user | Role for participating in Operational Resilience and Digital resilience incident activities. |
[Table 3. Roles used for reporting the incidents]

{#roles-installed-with-op-res__table_shh_mnh_ydc}

## Plugin dependencies for BCM Professional {#roles-installed-with-op-res__section_nnj_pvt_d1c}

For BCM Professional, the following mandatory applications are installed with Operational Resilience.

* Business Continuity Planning (com.snc.bcm.app_bcm_planning)
* Business Impact Analysis (com.snc.bcm.app_bcm_bia)
* Crisis Management (com.snc.bcm.app_bcm_exercise)
* Data Relationships Framework (com.sn_app_grc_relationship_config)
* Optional: Vulnerability Response (com.snc.vulnerability)
{#roles-installed-with-op-res__ul_onj_pvt_d1c}

## Plugin dependencies for IRM Professional {#roles-installed-with-op-res__section_pwh_v5t_d1c}

For IRM Professional, the following mandatory applications are installed with Operational Resilience.

* Advanced Risk Assessment (com.sn_risk_advanced)
* Data Relationships Framework (com.sn_app_grc_relationship_config)
* Policy and Compliance Management (com.sn_compliance)
* Risk Management (com.sn_risk)
* Optional: Vulnerability Response (com.snc.vulnerability)
{#roles-installed-with-op-res__ul_lqg_y5t_d1c}

