ServiceNow常用角色和分组

    A role is a category assigned to a user or group of users that defines access privileges to functionality in the Service-now platform. All groups or users assigned to a role are granted the same system access. Roles can also contain other roles, and any access granted to a parent role will be granted to any role that it contains. There are numerous roles in Service-now Incident and, depending on the size and function of your organization or department, these roles can overlap. A single individual can perform two or more of these roles as part of his or her responsibilities, but the functions assigned to a particular role remain the same.   The following is a list of default roles which are present in the system. Roles can be added or altered at any time.

RoleDescription
adminThe System Administrator role. This role has special access to all system features, functions, and data because administrators can override ACL rules and pass all role checks. Consider these implications when using admin overrides on ACLs.

If you have sensitive information, such as HR records, that you need to protect, you must create a custom admin role for that area and train a person authorized to see those records to act as the administrator. Also note the Special Administrative Roles.

Warning

Warning: Grant this privilege carefully.
agent_adminCan download and administer the system's built-in agent
approval_adminCan view and update all approvals, not just their own.
assignment_rule_adminCan manage Assignment Rules
assetCan manage hardware and software assets
catalogHas access to Services catalog requests
catalog_adminCan manage the Service Catalog application, including Catalog categories and items
category_managerCan create, edit, and delete model categories
contract_managerCan create, edit, and delete contract through the Contract Management application
ecmdb_adminCan administer the CMDB
filter_adminCan manage filters
filter_globalCan create global filters
filter_groupCan create filters that belong to groups of which the user is a member
gauge_makerCan create gauges from reports or charts
image_adminCan manage image files on the Images [db_image] table
impersonatorCan impersonate. Does not allow impersonation of admin users.
import_adminCan manage all aspects of Import Sets and imports
import_schedulerCan schedule imports
import_set_loaderCan load Import Sets
import_transformerCan manage Import Set Transform Maps and run transforms
inventory_adminCan create and delete stock information. Only users with the inventory_admin role can edit stock rules, stockrooms, and stockroom types.
inventory_userHas access to stock information. Can create and manage transfer orders.
itilCan perform standard actions for an ITIL helpdesk technician. Can open, update, close incidents, problems, changes, config management items. By default, only users with the itil role can have tasks assigned to them
itil_adminPossesses more privileges than the itil role and is intended for team leads. This role has the ability to delete incidents, problems, changes, and other related entities
knowledgeCan create, edit, and review Knowledge Base articles
knowledge_adminCan manage the  Knowledge Base
list_updaterCan use "Update Entire List" and "Update Selected" menu options on lists
maintReserved for ServiceNow use
mid_serverRole that any MID server user should be granted.  This role gives the MID server access to the tables it ordinarily uses.
model_managerCan create new CMDB models. Model manager can control the base models and any model extensions that are not hardware, software, or consumables. Hardware and consumable models are controlled by the asset manager role (asset). Software models are control by the software asset manager role (sam).
nobodyThe "nobody" role means that nobody has access - not even admin or maint.

Warning

Warning: Applying the nobody role may be irreversible if applied to some important system functions.
personalizeCan personalize forms, lists, rules, controls, scripts
personalize_choicesCan personalize choices and predefined responses for non-Journal fields designated as choice or suggestion fields
personalize_controlCan personalize controls on lists, such as filters, links, and buttons
personalize_dictionaryCan personalize dictionary entries and labels
personalize_formCan personalize forms
personalize_listCan personalize lists
personalize_responsesCan personalize predefined responses for Journal fields designated as suggestion fields
personalize_rulesCan personalize Business Rules and scripts. This role contains the following, specialized roles for granting selective, administrative access to rules and scripts:
  • business_rule_admin

  • client_script_admin

  • ui_policy_admin

  • ui_action_admin

personalize_stylesCan personalize field styles
personalize_uiCan personalize forms and lists
publicNo login is required to access features or functions with the public role
release_adminCan edit Release history for a Release
report_adminCan manage reports
report_globalCan create global reports
report_groupCan create reports and share reports with groups that the user is a member of. Users with this role can edit reports shared by other users in the group.
report_publisherCan make reports available on a public page
report_schedulerCan schedule a report to be emailed
script_fix_adminCan manage fix scripts (Calgary release).
soapCan query, create, update, and delete records on all tables, as well as execute scripts
soap_createCan create records on all tables and columns
soap_deleteCan delete records on all tables and columns
soap_eccCan query, create, and update on the ECC Queue table only
soap_queryCan query records on all tables and columns
soap_query_updateCan query and update records on all tables and columns
soap_scriptCan execute business rule endpoint function via script.do
soap_updateCan update records on all tables and columns
survey_adminCan manage Survey Masters, Questions, and Instances
survey_readerCan read Survey Instances and Responses
task_editorCan edit protected task fields
template_editorCan edit/modify templates. Included in the itil role out-of-box
template_editor_globalCan create templates for global use
template_editor_groupCan create templates for groups
template_schedulerCan schedule template-based record creation
text_search_adminCan customize Global Text Search groups and tables
timecard_adminEnables users to approve, modify, and delete the timecards of other users
ts_adminCan administer Zing text search.
userAvailable for customer use, has no function out-of-box
user_adminCan administer users, groups, locations, and companies
view_changerCan switch active views
workflow_adminCan create, edit, publish or delete graphical workflows
workflow_creatorCan create new graphical workflows
workflow_publisherCan publish graphical workflows



转载于:https://my.oschina.net/yotoo/blog/220606

  • 0
    点赞
  • 2
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值