---
sourceDocument: Yokohama IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/it-operations-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Create an assume role configuration

# Create an assume role configuration {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Create a service account assume role configuration to facilitate cross-account access
that is from a management account to a member account or from a trusted account to a
trusting account.

## Before you begin

Make sure that the accessor account credentials are configured in the ServiceNow AI Platform.

Role required: sn_itom_ccg.scheduling_admin

## About this task

If permanent credentials aren't defined for the member account, Cloud Configuration Governance checks the Cloud Service Account Assume Role Config
\[sn_itom_ccg_service_account_assume_role_config\] table to identify the special
configuration associated with the management account, and then uses the management
account credentials to generate temporary credentials for the member accounts. If
the configuration exists in the table, Cloud Configuration Governance uses the
temporary credentials acquired by specifying a role and its configuration in the Amazon Web Services (AWS) Security
Token Services API AssumeRole action.

## Procedure

1. Navigate to AllCloud Configuration GovernanceAssume Role Config.
2. Select New.
3. Fill the values on the Service Account Assume Role Config form.  
   For a description of the form fields, see [Cloud Configuration Governance Service Account Assume Role Config form](https://servicenow-prod.fluidtopics.net/A3aBvaK1XdEaeYoCnLSS2Q "The Cloud Configuration Governance Service Account Assume Role Config form displays detailed information about the assume role configuration used to access the trusting account.").
4. Select Submit.

*[\>]: and then


