---
sourceDocument: Yokohama IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/it-operations-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Explore

# Exploring Cloud Account Management {#ariaid-title1}

* Release version: Yokohama
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Exploring Cloud Account Management

The ServiceNow Cloud Account Management application within Cloud Workspace streamlines cloud account lifecycle processes such as creation, suspension, reactivation, and certification.
It automates administrative tasks to improve efficiency and compliance by confirming the integrity and security of user accounts in your cloud environment.
Show full answer Show less  
As an administrator, you have access to a Home tab dashboard that presents key account statistics, including critical and high severity accounts, suspended accounts, accounts pending certification, and accounts with undefined budgets.

## Key Features

* **Dynamic Entitlements:** Access to features depends on your license entitlements. The ITOM Cloud Accelerate license enables Cloud Account Management, while the Cloud Governance Suite (CGS) license is required to use Cloud Workspace. Combining CGS with Cloud Account Management entitlements (CGS + CAM) unlocks capabilities such as submitting and approving account requests, certifying accounts, viewing compliance dashboards, and configuring request policies.
* **Compliance Dashboard:** Provides a unified view combining data from ITOM Visibility and Cloud Account Management, facilitating security and compliance reporting.
* **Cloud Terminology Alignment:** The application aligns terminology with major cloud providers---Azure (subscriptions), AWS (management/member accounts), and GCP (projects)---and standardizes access mechanisms as IAM service accounts across platforms.
* **User Personas and Roles:** Supports defined roles including Requester, Approver, Admin, Certifier, Asset Viewer, and Account Manager, each with specific permissions to initiate requests, approve, configure, certify, or view account data.
* **Request Policies and Automation:** Enables creation of policies to automate account request approvals, budget checks, and the account lifecycle process.

## Benefits for ServiceNow Customers

* **Standardized and Compliant Account Creation:** Ensures consistent procedures and role-based permissions that align with security policies.
* **Lifecycle Management:** Simplifies suspending, reactivating, and adding unmanaged accounts, reducing manual effort and errors.
* **Visibility and Control:** Dashboards and reports provide actionable insights into account statuses and compliance, supporting governance and audit needs.
* **Security and Compliance Verification:** Data certification processes help verify legitimate account ownership and control, supporting regulatory requirements.

## Additional Considerations

Cloud Account Management integrates with other ServiceNow components and cloud provider APIs to facilitate permissions and provisioning modes. Understanding the predefined roles and responsibilities helps optimize the configuration and use of the application to meet organizational needs.  
The ServiceNow
Cloud Account Management in Cloud Workspace application provides a framework to streamline the cloud account creation and management process.

## Cloud Account Management overview {#exploring-cam__section_i4r_z1z_2bc}

The automation capabilities of Cloud Account Management in Cloud Workspace simplify administrative tasks related to account management, such as creation, suspension, reactivation, and certification. Data certification confirms the integrity and security of
user accounts within the organization's cloud environment.

As a Cloud Account Management admin, you can view the account statistics displayed on the Home tab, which include critical severity accounts, high severity accounts, suspended
accounts, accounts due for certification, and accounts with undefined budgets.

## About Cloud Workspace entitlements {#exploring-cam__section_qb5_czf_qfc}

Cloud Account Management dynamically adjusts the features available to you based on your entitlements.

* Cloud Account Management entitlement becomes available with the ITOM Cloud Accelerate license.
* The Cloud Governance Suite (CGS) license is a prerequisite to have Cloud Workspace. The CGS license provides the following capabilities:
  * Access the home page
  * Access the asset explorer, which provides an overview of your cloud assets and asset details
  {#exploring-cam__ul_ymt_t5x_rfc}
* The Cloud Governance Suite with the Cloud Account Management entitlements (CGS + CAM) provides the following additional capabilities:
  * View an overview of your accounts and account details
  * Submit, view, or approve account requests
  * Certify an account
  * View the compliance dashboard
  * Configure Cloud Account Management or view configuration details
  * Create request policies to automate the complete account creation and suspension process
  {#exploring-cam__ul_zmt_t5x_rfc}
{#exploring-cam__ul_xmt_t5x_rfc}

## Compliance dashboard in Cloud Workspace {#exploring-cam__section_nzs_3mj_rfc}

The compliance dashboard consolidates data from ITOM Visibility, Cloud Account Management to provide a unified view of cloud data and key metrics critical for security and compliance reporting.

For more details, see [Viewing the compliance dashboard](https://servicenow-prod.fluidtopics.net/Zrem128w5BO4dRluprmL~A "The Cloud Workspace compliance dashboard provides insights that help security teams identify cloud resources without ownership information and flag vulnerable or at-risk resources. This information helps team members conduct security audits and confirm compliance with industry regulations across cloud environments.").

## Cloud account terminology {#exploring-cam__section_vpz_s33_vcc}

Cloud Account Management uses the term "cloud account," but other cloud providers use different terms for similar concepts. The terms are as follows:

* Microsoft Azure Cloud (Azure) refers to subscriptions
* Amazon AWS Cloud (AWS) refers to management and member accounts
* Google Cloud Platform (GCP) refers to projects
{#exploring-cam__ul_lyc_yf5_s2c}  
Cloud providers offer two main access mechanisms for performing operations:

* Console user access
* Programmatic user access
{#exploring-cam__ul_pwf_jxj_52c}  
For Cloud Account Management, these operations are referred to as IAM service accounts. However, other cloud providers use different terminology:

* AWS refers to the IAM user
* Azure refers to service principals
* GCP refers to service accounts
{#exploring-cam__ul_av3_lxj_52c}

## Cloud Account Management user personas {#exploring-cam__section_f1v_b2j_dcc}

{#exploring-cam__table_bnd_shj_dcc__entry__2}

| User | Description |
|-|-|
| Requester | Initiates cloud account creation requests and requests for suspension or reactivation of their own accounts. |
| Approver | Reviews account requests and either approves or denies them. |
| Admin | Confirms that the Cloud Account Management configurations align with cloud configurations. Customizes the default data certification policy. Onboards accounts created outside the Cloud Account Management application. |
| Certifier | Approves an account as certified or failed. Acts as a verification entity by confirming the accuracy and integrity of the data. |
| Asset viewer | Can view all the configuration items (CIs) in Asset Explorer and access the compliance dashboard. |
| Account manager | Can view all account details and associated assets. Account managers have edit access to accounts with primary ownership and read-only access to those with secondary ownership. |
[Table 1. Personas used in Cloud Account Management]

{#exploring-cam__table_bnd_shj_dcc}

For more information about Cloud Account Management groups and responsibilities, see [Cloud Account Management ACL groups, roles, and responsibilities](https://servicenow-prod.fluidtopics.net/817sjeRdhwQYtpt20bYlgg "Access control lists (ACLs), groups, and roles in Cloud Account Management control how access permissions are organized and managed within a cloud environment.").

## Cloud Account Management Benefits {#exploring-cam__section_hgq_rnl_vzb}

The Cloud Account Management provides several benefits.
{#exploring-cam__table_wrb_pgq_dcc__entry__3}

| Benefit | Feature | Users |
|-|-|-|
| Simplifies subscription account creation by defining standardized procedures and user roles and permissions to promote consistency and compliance with security policies. | [Request a cloud account](https://servicenow-prod.fluidtopics.net/jJxyZQVyhQDX4AJ~A7aKbg "Request a cloud account as a requester. A notification email is sent when the requester creates an account request.") [Cancel a Cloud account request](https://servicenow-prod.fluidtopics.net/XcX7p4eyBirCzs4QCwM4cw "Cancel an account request that you have submitted.") | Requester |
| Enables suspending or reactivating accounts, and adding unmanaged accounts. Offers a visualization dashboard to manage accounts and request policies to automate account creation, approvals, and budget checks. | [Suspend a Cloud account](https://servicenow-prod.fluidtopics.net/3ItkOyaMtN~p~0eQVLIyCw "Suspend an account when there’s a budget constraint or the account owner isn’t available in the organization. Only admins and account owners can see the suspended accounts.") [Reactivate a cloud account](https://servicenow-prod.fluidtopics.net/HKKCrWaUsq1iu2H1IlY~wQ "Reactivate an account that was previously suspended if there is a need retrieve the account. After reactivating an account, the account status changes from suspended to active. Only Cloud Account Management managed accounts can be reactivated.") [Add an unmanaged cloud account](https://servicenow-prod.fluidtopics.net/ZZ98m2QOwwOA3aLwd2B5Bg "Managing a cloud account involves tracking budgets, checking for configuration violations, and validating certificates. The procedure helps you to onboard an unmanaged cloud account.") [Creating configurations](https://servicenow-prod.fluidtopics.net/A400XEoslN9gvaFReHvq0Q "Setting up the Cloud Account Management app is a prerequisite task before proceeding to create, suspend, or scan a service account. By configuring Cloud Account Management, you can ensure that the application is ready to effectively execute account management tasks and deliver the desired results.") [About data visualization in Cloud Account Management](https://servicenow-prod.fluidtopics.net/_W3UnyJTMtERljpj7vOm6w "The Cloud Account Management overview dashboard gives a clear view of all cloud accounts and their compliance status. Cloud Account Management pulls data from Cloud Configuration Governance to create a simple, visual overview of compliance. As an admin, you can take the necessary actions for the reported vulnerabilities.") [Review request policies](https://servicenow-prod.fluidtopics.net/fc7Ie_mRdo9zwRlBqpUamg "Review and update request policies to confirm they align with your cloud account request process. These policies enforce data checks and conditions, promoting consistency in creating cloud subscription accounts.") | Admin |
| Streamlines performing verifications that a person or entity has legitimate ownership or control over an account for security, compliance, and regulatory purposes. | [Certify an account](https://servicenow-prod.fluidtopics.net/iQ2PdLMLFN7oGJPkoTaicg "A certification task represents the work of verifying and certifying the data associated with a record. The certifier reviews tasks created after data validation against the published policy. Account certification helps resolve issues like outdated ownership, inactive user profiles, and improper permissions in cloud accounts.") | Certifier |
[Table 2. Cloud Account Management Benefits]

{#exploring-cam__table_wrb_pgq_dcc}
**Related concepts**   

* [About Amazon Web Services API permissions](https://servicenow-prod.fluidtopics.net/AuiEAq9UWChKGeYLVIk15A "Cloud Account Management interacts with Amazon Web Services to create and manage subscription accounts.")
* [About provision modes in Cloud Account Management](https://servicenow-prod.fluidtopics.net/GKQzD9nvmLCJLmc5KGETvg "Cloud Account Management supports both Terraform (Cloud and Enterprise) and cloud native interface provision modes.")  
**Related reference**   

* [Components installed with Cloud Account Management](https://servicenow-prod.fluidtopics.net/C435kMjL7Mqnl1fYyQ8snQ "Several user roles are installed with the Cloud Account Management app.")

