Ch. 17 · ServiceNow

ServiceNow ACLs and Record Access Decisions

ServiceNow ACLs and Record Access Decisions. Learn the reasoning, a practical example, common mistakes and an interview exercise.

~2 min readintermediateupdated Oct 3, 2026

Access controls protect operations at table and field boundaries. Form visibility does not substitute for record and field authorization.

Before you start

You should understand tables, records and the difference between client-side and server-side scripts. Work in a development instance with representative permissions. Identify execution scope, transaction timing and the current user before attributing behavior to a platform script or business rule.

The practical goal is to reason through this situation: A user may see a record but lack permission to read one sensitive field. Read the walkthrough first, then try the interview exercise before opening its answer. The important part is explaining the decision and its consequences, rather than remembering a definition alone.

Step-by-step walkthrough

Step 1: Separate record and field access

Reading a record does not imply reading every sensitive field.

Step 2: Use representative roles

Administrator behavior can bypass the restrictions ordinary users encounter.

Step 3: Test alternate interfaces

Forms and API access must preserve the intended boundary.

Worked scenario

A user may see a record but lack permission to read one sensitive field.

A support agent sees an incident but not a restricted personal-data field. Hiding the field visually is insufficient if the agent can retrieve it through another interface. Verify the actual table and field authorization for the intended roles, including denied reads and writes.

Common mistake

Testing only with an administrator can hide missing access restrictions.

Verify the behavior

Test allowed and denied operations as ordinary users through supported interfaces.

Interview exercise

Verify a sensitive field.

Answer and reasoning

Test representative nonprivileged roles across form and API access, checking both permitted and rejected operations.

Continue learning

Compare the scenario with the ServiceNow interview questions and test your understanding with the ServiceNow MCQs. For terminology and implementation details, consult the reference material.

More in ServiceNow

read ✓ServiceNow · hard

ServiceNow ACL Scripting and Access

Enforce access with ACLs, use scripted conditions carefully, and test as the actual user to verify.

~2 min readread →
read ✓ServiceNow · hard

ServiceNow Caching and Invalidation

Understand what the platform caches, when a change takes effect, and how to flush caches consistently across nodes.

~2 min readread →
read ✓ServiceNow · mid

ServiceNow Dictionary and Field Audit

Define fields in the dictionary, use per-table overrides, and enable audit on the fields that need a history.

~2 min readread →
esc