logo

NJP

ITOM Office Hours Q&A August 2026 | APAC Session

New article articles in ServiceNow Community · Aug 16, 2026 · article

About This Document

 

This document contains 57 questions and answers from the APAC ITOM Office Hours session held on August 5, 2026.

 

Note:  Answers were processed using AI transcription and extraction. While we have made every effort to ensure accuracy, these answers may contain inaccuracies or miss nuances from the original spoken response.

 

Questions & Answers

| # | Question | Answer |
| 1 | From your experience, what are the key CMDB governance and  data quality, practices organisations should have in place before implementing Discovery and Service Mapping? | The key CMDB governance and data quality capabilities in ServiceNow can be grouped into several areas:

CMDB Governance

1. Data Ownership and Accountability

CI Owners

Support Groups

Managed By Groups

Application Owners

Service Owners

Data Certification Owners

These establish accountability for maintaining and validating CMDB data.

  1. CMDB Data Manager

    Provides lifecycle governance for CIs through:

    Retire Policies – identify and retire obsolete CIs.

    Archive Policies – archive aged CMDB records.

    Delete Policies – permanently remove archived records when appropriate.

    Enforcement Policies – automate lifecycle management activities.

  2. Data Certification

    Allows designated owners to periodically review and certify that CI records remain accurate and valid.

  3. Data Attestation

    Provides attestation campaigns where stakeholders confirm ownership, relationships, classifications, or other CI

  4. CMDB Governance Rules

    Controls what data is allowed into the CMDB by enforcing:

    Naming standards

    Attribute requirements

    Relationship requirements

    Class-specific governance policies

  5. CSDM Governance

    Ensures:

    Correct service hierarchy

    Valid application-service mappings

    Proper service ownership

    Compliance with Common Service Data Model standards |
    | 2 | From your experience, what are the service modelling practices organisations should have in place before implementing Discovery and Service Mapping? | Regarding Service Modeling.

    We naturally align to the ServiceNow CSMD V5 standards.

    Service Modeling provides a standardized, blueprint-driven approach for defining and managing services within the CMDB, ensuring consistent service structures aligned with CSDM. It uses service models and templates to define required attributes, ownership, and relationships between business services, applications, technical services, and infrastructure components. By enforcing approved service patterns, Service Modelling improves governance, accelerates service onboarding, and enhances impact analysis for operational processes such as Incident and Change Management. It works closely with CMDB, Discovery, Service Mapping, and CMDB Health to maintain accurate and well-structured service data.

We have 3 main approaches:

1.Manual Modelling: involves iteractive modelling workshops with Service owners, SME, Service Architects. Techniques include White boarding a service, decomposing a service into offerings and associating infra CIs

2.Extract, Transform, Load: this is often used for migrating existing service structure into a ServiceNow CSDM compliant way. As the ”as is”situation can vary enormously, this is a case-by-case situation. Typically this approach involve an extract/transform, manual review, transform/load.

3. On-platform Tools: this leverages the emerging Service Modelling tool to guide Service Owners through creating/updating a Service Model in a controlled guided workflow. Service Modeller is currently in innovation lab, but general release is planned for later this year. |
| 3 | For organisations moving from legacy platforms such as SCSM, what are the most common lessons learned or pitfalls to avoid during the transition to ServiceNow? | Biggest gotchas include:

- CMDB class and attribute mapping between OEM CMDB and ServiceNow.

- CSDM alignment

- CMDB/CI Health & Governance maturity

- Custom table/classes/attributes |
| 4 | Please share the level of readiness in CMDB should we have before implementing ITOM Assist | CMDB is a not a one-off exercise, it’s a journey that every customer embarks at different stage. Assuming you mean NowAssist for ITOM when saying ITOM Assist, you can pretty much leverage it regardless of your CMDB journey. |
| 5 | What are the prerequisites for AI features deployment to ITOM | The foundation ie CMDB needs to be well populated and governed before i would use AI in anger.Is there a specific AI feature you were looking at? |
| 6 | Does we do OOB discovery Patterns to discover On Premises AI Agents and Models to insert the data in AI Application Table? |

Currently we support, AWS bedrock and Azure Foundry.  are you referring OpenClaw on Prem AI agent? 

From the community:

https://www.servicenow.com/community/cmdb-blog/understanding-the-ai-inventory-data-model-in-servicenow-product/ba-p/3546771

I think Mark Bodman was showcasing this at Knowledge ’26.

|
| 7 | Can we use Express List in Service Operation Workspace without AIOps capability? | Express List is tied to events/alerts ingested into Event Management. Therefore you’ll need a data source to populate the relevant event management tables to leverage Express List |
| 8 | I want to understand how SolarWinds sends events to ServiceNow. In SolarWinds, there are different event severity levels, but I only see a few types of events appearing in ServiceNow. Is there a filter or configuration somewhere that determines which events are forwarded? | Multiple ways, i just set one up last year.

you have the ‘pull’ method, where ServiceNow hits the SolarWinds REST API and drags events (see https://www.servicenow.com/docs/r/it-operations-management/event-management/t_EMConfigureSolarwindsConnectorJS.html

you can setup limited filters using the connector properties,

or (and i like this better personally)

use a web hook to push a REST payload to a generic event push connector instance |
| 9 | We are using Agent based discovery (ACC-V) for Servers - Physical & VM's. While we are performing SNMP discovery for Netgear associated devices.

So is it possible to get a relationship discovered between Physical Server & IP Switch in such a scenario? | Yes, we do create relationships on the L2 physcial layer. https://www.servicenow.com/docs/r/zurich/it-operations-management/itom-visibility/c_Layer2Discovery.html |
| 10 | I have deployed certificate inventory and management module recently and integrated with DigiCert. I would like to understand who the certificate task (manual) is for? thanks | When a certificate is first discovered, the fields for “Assigned to” and “Change Group” are blank. You should set the “Assigned to” field as the certificate's owner. You should set the “Change group” to the support group responsible for actioning the certificate renewal.These values will then appear in the task |
| 11 | We are doing deep down discovery as well well with credentials. do you think we should switch to SGC or continue with CPG(Cloud Provisioning and Governance) | I would suggest then Cloud pattern-based discovery |
| 12 | I would like to get further information on Data Attestation and at what point of the CMDB/CSDM cycle should it be carried out. | Attestation is normally a go-live/discovery activity when the CI is discovered/found and needs to be validated.

The task is to ‘attest’ that this CI does actually exist and is in scope.

this is different from data certification, which is normally a BAU activity to maintain data and reduce stale (normally non-discoverable) attributes like owners, support groups. |
| 13 | Why is environment field hidden OOB from the renew certificate (automated) catalog item?  | i think that’s because many of our customers do not use the environment field up front. Nothing is stopping you from showing it 🙂 |
| 14 | When we are discovering IP Switch, in some cases it is updating the serial number of another ci, for example, if we are running discovery for abc switch discovery updating serial number of xyz ci to abc and which is causing duplicate ci. | The out-of-the-box ServiceNow pattern for Cisco Firepower (ASA) firewalls can't collect the serial number. Cisco confirmed this is a known bug on their side — the ASA Management IP doesn't expose the required SNMP OID for the serial number, and there's no fix release yet.

The complication: The serial number actually lives in FXOS (the underlying chassis OS), but querying via the FXOS Management IP only returns the serial number — it misses make, model, and all other relevant attributes, which are only accessible via the ASA management interface.

The workaround: Since serial number-based identification is off the table, Yew Hoong recommended customising the Identification and Reconciliation Engine (IRE) rules to use an alternative unique identifier (hostname or IP) to avoid duplicate or overwritten CIs.

Action item: Review IRE/identification rule documentation —  CMDB Fundamentals courses on ServiceNow as a starting point. |
| 15 | Does ITOM license consumes if use SGC? | Yes, the only exception is with the SCCM-SGC |
| 16 | Does we have OOB patterns for discovery Hitachi Storage devices? | The answer: Not yet. Current OOB patterns rely on SMI-S/CIM protocols. There is no REST-based storage discovery pattern available today.

The roadmap:  confirmed REST-based storage discovery is actively being built. IBM FlashSystem is planned to be released in Q4, and Hitachi (at least one device — a hybrid DS model) is also planned for Q4. Other Hitachi models are on the sequential roadmap as the older protocols are being deprecated by vendors.

In the meantime: Customer confirmed the Hitachi VSP still supports SMI-S/CIM today, so the existing OOB patterns will work for now. Custom patterns would only be needed if those protocols aren't available. |
| 17 | In ServiceNow Event Management, what is the right way to populate Assignment group on the Alert ? | There’s multiple ways to do this. My preferred option is to use the OOTB feature - https://www.servicenow.com/docs/r/it-operations-management/event-management/alert-assignment-group.html. |
| 18 | When is Azure key vault integration to fully automate the renewal available? | It is in roadmap. we will pass the information to PM |
| 19 | Does ITOM license count if an incident is created directly rather created from alerts? | If you’re creating incidents and linking it to CI’s - this does not consume ITOM licenses. |
| 20 | Is there a way to discover Logical Data Centers as part of Nutanix Prism Central discovery? | Hi, can you confirm this is not collected in https://www.servicenow.com/docs/r/it-operations-management/discovery-and-service-mapping-patterns/nutanix-pattern.html? |
| 21 | For cloud discovery we see many patterns are still not available to discover for eg Azure cloud functions, etc should we need to wait until they are released, what should be our approach | There’s a really awesome spreadsheet in the docs for cloud discovery listing all the APIs and rights required (updated 12-Mar-2026) for cloud discovery. i’d keep checking that for new functions and making sure you’re on the latest discovery patterns and classes.

https://www.servicenow.com/docs/r/it-operations-management/discovery/cloud-discovery-setup.html

the current version of “Discovery and Service Mapping Patterns” is: 1.31.2 |
| 22 | Our current ITSM capabilities are spread across SCSM, Jira, SAM registers and separate asset registers. From your experience, what should organisations consolidate first when moving to ServiceNow to establish a trusted data foundation? | Map before you build — understand what each tool (Jira, SCSM, etc.) actually does today before migrating, since tools like Jira often serve multiple purposes.

Data Foundation first — users, groups, locations, cost centres must be established before anything else.

One process at a time — don't try to consolidate everything at once.

Recommended sequence: CMDB population → link incidents to CIs → mature the catalogue → then SAM Pro (noting that basic ITSM asset management is insufficient for true software asset management).

Change management matters — appoint champions in each team; training is available free on ServiceNow University.

Some on demand courses :

Configuration Management Database (CMDB) Fundamentals On Demand

https://learning.servicenow.com/lxp/en/it-operations-management/configuration-management-database-cmdb?id=learning_course_prev&course_id=c03ca22847ec66547faa0415f16d43f4&s=1&ssa=3

I understand SCSM is an ITSM (Inc, Problem, Change) product.

As ITSM functions target Configuration Items (CI) which may be different from Assets.

I recommend improving the health and accuracy of you CI’s within the CMDB first.

In ServiceNow we differentiate between CIs and Assets.

Configuration Item (CI) represents a component that supports the delivery of a business or technical service and is managed within the CMDB to understand relationships, dependencies, and operational impact.

An Asset represents something the organisation owns, leases, or tracks for financial and lifecycle management purposes, focusing on procurement, contracts, costs, and inventory rather than service relationships. |
| 23 | We recently upgraded to ITOM Advanced entitlement. What should be the most logical first step to start the ITOM Assist journey. | If you are Impact customer,I’d suggest a session with ServiceNow Impact team assigned to your account. I believe they have NowAssist ITOM Quickstart package they can go through with customers |
| 24 | Is API Discovery available for Storage Hitachi VSP one block Devices | it is in roadmap not in q4 timeline. HP DS in Q4 |
| 25 | How do I add filter to the digicert CA Trust discovery? I only want to discover the certificate that was issued this year. | I haven’t seen any OOTB settings that will restrict to a time period when integrating with a CA |
| 26 | How AI wil help in ITOM governance and compliance discovery? | Governance shifts from reactive auditing to always-on assurance, with AI doing the heavy lifting on pattern recognition and prioritisation so your team focuses on decisions, not data collection. |
| 27 | Hello, What Are Some Ways to Integrate Cisco VManage & ServiceNow.

The Goal: We Want To Discover SDWAN Devices On ServiceNow.

Problem We Are Trying To Solve Is:

We Have events generated by SolarWinds Ffor BFD sessions which go down or when A Logical interface goes down, so when an event Is created on ServiceNow, so, for the field where fhe Configuration Item has to be napped, the Event rules try to look up SDWANs on CMDB. As we don't have any SDWANs, the Configuration Item is always empty, which  makes it tough for our ITOM team to  identify what is actually down & associate the relationships. | You could use the event for creating the binding CI as needed.

There is no dedicated, out-of-the-box native application specifically for Cisco vManage (now part of Cisco Catalyst SD-WAN Manager) in the ServiceNow Store, though integrations can be built using vManage REST APIs and web hooks. |
| 28 | What are the most important competences/experts do we need to successfully implement an On Prem ITOM? | The ITOM PEx team has a video of what’s required to be an ITOM SME per product

https://youtu.be/D8KGTPAbFCU

on top of that, the ServiceNow Success site has many collaterals for starting up |
| 29 | We have some new requirement to integrate tools such as Aruba central, Pure, VeloCloud etc with ServiceNow event management. What would you recommend as the best way to do the integration ? | 1. Check to see if we have existing push/pull connectors available within the SN instance and the SN store.

2. Also check the vendor, at times they may provide a connector which may not be published in the SN store.

3.If there isn’t an option, SN provides either a push or pull option to retrieve events. You’ll need to investigate this option to create a custom integration. I would recommend a push connector over a pull. |
| 30 | We are observing the ACC-8003 error on few of the agents. As part of our investigation, we engaged the Linux administration team, who confirmed that the server is CIS-hardened and has the noexec mount option configured on the relevant filesystem.

Despite the requested execution permissions being granted on the target servers, some servers are still not being discovered.

Could you please advise on the possible causes and the checks we should perform from the ServiceNow side to determine why discovery is failing? | in this specific case, the best course of action is to raise a case with NowSupport. Thank you |
| 31 | How to route alerts to different assignment groups depending on which data source the alert comes from.  | Two approaches:

Set the assignment group at the data source level — when defining each integration (pull or push), you can specify an assignment group directly on that data source, and a system property controls whether that value is used to populate the alert's assignment group field.

Use additional info via event rules — have the data source include extra labels in its payload, parse that data through an event rule into the additional info field, then use that value to drive the assignment group. |
| 32 | Why are the data centres are duplicating during Cloud Discovery? | Data model like that, we have many to many mapping each service account. |
| 33 | Referring to cmdb_ci_certificate. the state field from this table does not reflect to CSDM life cycle stage and life cycle stage status by default. the customer enabled the CSDM life cycle sync | It looks like there is no OOTB lifecycle mapping for certificates. There may be configurations that need to be done to enable the sync. Has it been done for certificate? |
| 34 | For database discovery will ServiceNow provide pattern for new database such as Doris, OceanBase. | will surely look at it |
| 35 | Hello, What Are Some Ways to Integrate Cisco VManage & ServiceNow. | There is no dedicated, out-of-the-box native application specifically for Cisco vManage (now part of Cisco Catalyst SD-WAN Manager) in the ServiceNow Store, though integrations can be built using vManage REST APIs and web hook |
| 36 | Do we have any KB articles to understand the Dynamic IRE algorithms. In present doc's we do have only basic Information. | There’s not much so far, as of Knowledge ’26 there was only a limited release on hardware CI right now (even I only found out about it at K26).

It’s not AI but algorithms and the explanation I got was that it was a multi attribute map.

There’s some more info in community here:

https://www.servicenow.com/community/in-other-news/what-is-cmdb-dynamic-ire-in-australia-release/ba-p/3555166

but i don’t have the exact algorithm. |
| 37 | Currently  Kubernetes deep down Discovery brings Kubernetes clusters along with pods, containers, namespace, nods, daekonsets etc, but they are mostly ephemeral. is it recommended to bring all of them from cmdb governance perspective

 what is your recommendation | Bring them in but ensure lifecycle policies and deletion strategies are in place to manage their lifecycle to your organisations requirements. OOTB there are already deletion strategies in place for such resources.

Further to this, we don’t recommend using such ephemeral CIs for say your ITSM processes. |
| 38 | Why the OOB alert correlation rules don't work to achieve - below logic.

Network alert - Circuit down - Parent alert

Network alert - Router down - Child alert

network alert - Core switch - Child

access switch - child

Hypervisor server - child

VM - child

physical server - child.

create incident only for Parent alert? | This is pretty common where you want an incident only for the parent alert. There was a feature released late last year where you can put a delay/wait time, so it revisits the condition to ensure that the alert is considered a primary before creating an incident. https://www.servicenow.com/docs/r/it-operations-management/event-management/delay-incidents.html?contentId=M6VkIIqE5H14GSfdxGSg2g |
| 39 | What is the expected timeline for deprecating Basic Authentication for MID Servers? | we don’t have an official timeline at this stage, but you should check with your security team if they’re comfortable with this type of authentication |
| 40 | Does current AI Service Graph connectors have capability to get the Tags as well (AWS)? to do tag based service mapping. | it doesn’t but Cloud Pattern based discovery does it. you need to look at AI Agent topology Mapping app. |
| 41 | We use VR tenable to bring in On Prem resource and wiz for bringing in cloud vulnerabilities. but tenable and wiz push them in cloud resource class where as cloud patterns push them in very specific CMDB classes. how should this be handled as same ci goes in different classes | dual-path problem: cloud vulnerabilities from Tenable (On Prem) and VIS (Azure) are pushing CIs into the generic cloud resource class, while cloud patterns are simultaneously pushing the same CIs into their specific CMDB classes — resulting in duplicates and, critically, missing ownership information on the cloud resource class CIs.

root cause: the CI lookup rules aren't matching incoming vulnerability data to existing CMDB CIs, so the system creates new CIs in a fallback class instead. He pointed to a common culprit — mismatched CI names (e.g. a fully qualified domain name appended where the CMDB only stores the short name), or missing serial numbers forcing a name-based lookup that fails.

Recommended approach: investigate and fine-tune the CI lookup rules so that incoming vulnerability data matches existing CMDB CIs correctly. Once matched, the vulnerability attaches to the right CI (with ownership intact) rather than creating a duplicate in the cloud resource class. |
| 42 | We currently populate our CMDB through a few custom integrations, and we are in the pathway of Implementing ITOM Discovery, which will discover many of the same devices. My question is how the classes created by the integrations will line up with the classes discovered by ITOM without ending up with duplicate or misclassified CIs. Is IRE the only thing needed to keep these aligned, or is there anything else we should have in place? Thanks! | IRE is a great start to define the class matching attributes and using CMDB 360 (or multi-source CMDB) to manage which sources are the primary source of truth for each attribute, though one thing i’ve found SUPER useful are the properties for class upgrades/downgrades.

https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB0812249

e.g. system property: glide.identification_engine.update_without_downgrade_enabled

* and these properties can be set individually in IRE payload and IntegrationHub RTE records.

i’ve experienced multiple sources like SGCs trying to downgrade or switch classes as it only knows the CI as a base CI class (like netgear). Or SolarWinds discovering a firewall as a linux server and trying to switch classes.

Also check out Dynamic IRE (new feature) but it’s only on [cmdb_ci_hardware] right now |
| 43 | I had to create a separate life cycle mapping for the certificates. it doesn't come OOB. I want to understand why this was not considered. | As you know, CMDB has hundreds of classes that inherits the lifecycle fields from base cmdb_ci class. By default, ServiceNow provides a list of commonly used classes for mapping, not all classes. |
| 44 | Where a service goes across cloud and on-prem is it possible to combine a service map that shows tag based discovery and on Prem discovery mapping in a single view? | Yes, we now have a composite mapping feature from Australia where you can combine service maps of different population methods. https://www.servicenow.com/docs/r/it-operations-management/service-mapping/multi-source-service-mapping.html |
| 45 | I haven't touched on Discovery for a while, but wondering whether the patterns support Active/Active clusters better than in the past?

Had an issue in one environment a while back (still existing under Yokohama) where an active/active cluster would have the secondary node marked as inactive by discovery.

That was primarily F5 load balancers (in particular) but also experienced it with other patterns as well.

Ended up being the way the OOB patterns established what was active (in the CMDB), not what was active (according to the cluster) | i’m not aware of major changes in the way patterns support active/active clusters. |
| 46 | Is there a licensing cost associated with assigning the pki_user role? | ITOM license is not tied to user role assignment. It uses subscription unit metric to measure the usage. If you’d like to understand more, please contact the ServiceNow account team for your organisation, and they will be able to tee up a session to go through all details relating to ITOM licensing with you |
| 47 | Are There any documents from ServiceNow, which describe the integration of Cisco VManage with ServiceNow using web hooks, API? | I’ve only been able to locate this https://www.cisco.com/c/en/us/support/docs/routers/sd-wan/225422-integrate-catalyst-sd-wan-with.html which looks like using web hook. |
| 48 | Will SGC-Tanium discovery help to build automatic CI Relationships? or we need to Build it manually? | I don’t believe SGC-Tanium builds CI relationship. If CI relationship and dependency is your main focus, it’s strongly recommended to go with ServiceNow native discovery and service mapping as primary method which will provide you with CSDM compliant relationship data for the most comprehensive, accurate and up to date CMDB |
| 49 | What is the reason of having a two way synch between Asset and CI record, shouldnt one be source of truth and data flow in one direction? Can we change this? | Assets source of truth should be procurement, which through model categories would create a shell CI, which in turn gets additional data from Discovery.

Logical CI’s do not have asset equivalent.

You can change this by looking at model categories where assets and CI classes are linked.

https://www.servicenow.com/docs/r/it-service-management/product-catalog/c_ModelCategories.html

Additionally, granularity in terms of which attributes can be sync is available. https://www.servicenow.com/docs/r/it-asset-management/asset-management/t_CreateAssetandCIFieldsMapping.html |
| 50 | Is there any recommended best practice it e-bond CI's and events across service providers to a customer? | You’d now be looking at the ‘Service Exchange’ (formelly knows as Service Bridge/e-bonding) product here including ‘Foundation Data Services’

https://www.servicenow.com/docs/r/service-exchange/tmt-service-bridge-both-landing-page.html

https://www.servicenow.com/docs/r/service-exchange/service-bridge-v2-explore-foundation-data-sync.html

and here's the ServiceNow best practice guide for a service bridge implementation guide

https://mynow.servicenow.com/now/best-practices/assets/service-bridge-implementation-guide

i’d start with keeping the integration as simple as possible - start with just string fields and slowly work on references. Most of my issues came from trying to keep reference fields synced,especially when they don;t exist on both sides

But there is a new property in the Service Exchange that allows you to ignore updates using script transforms (as of Apr 2026)

and FDS allows you to sync (now bi-dir as of Apr 2026) CIs between istances. |
| 51 | Is there way to build hybrid service maps for example the application is hosted on azure and we are discovering cis using ACC so can we include both tag and top down in single map. Is there a possibility in future release? | It’s available now - https://www.servicenow.com/docs/r/it-operations-management/service-mapping/multi-source-service-mapping.html |
| 52 | We got certain type of printers called plotters (HP manufacturer) is not getting discovered successfully. its been said by ServiceNow technical support team that, customisation need to developed. By default, the OOTB leveraging SNMP Probes and queries not patterns. Will custom patterns development help to discover those HP devices? | Yes, you can create SNMP classifiers for these HP printers (if we cant discover them or classify them OOTB), and then trigger a pattern that you create. eg https://www.servicenow.com/community/itom-articles/create-a-simple-snmp-classifier-the-patterns-edition/ta-p/2296472 |
| 53 | Nowadays I am seeing lot of gap between ci status like operational, hardware, install status mismatch between server ci and vm instance CI statuses. I see documentation removed after Yokohama release and business rule disabled. Are we moving to lifecycle status? Any implementation plan | yes, CSDM lifecycle is the way to go. test it in Dev

https://mynow.servicenow.com/now/best-practices/assets/cmdb-lifecycle-stage-and-status |
| 54 | What is the best practice to map the certificate state to CSDM life cycle? |
Currently don’t see any BRs or other mechanisms that aligns the certificate state to the CSDM lifecycle status and stages. Not sure why not implemented but don’t think it would be hard via BRs. I will check with PM in the mean time to see if there are any future plans to include this.
|
| 55 | Routing policy does not look at the API url, shouldn't this be added to the routing policy check? | If you look at the doc, part of routing policy creation includes putting in the CA and CA API URL. |
| 56 | How do I add filter to the DigiCert CA Trust discovery? I only want to discover the certificate that was issued this year. |
You can potentially customised the OOTB DigiCert - Certificate Management pattern to restrict it via a filtering step. But what about certificates issued not in this year but still valid and expiring in the future? I assume you would still want visibility into those?
|
| 57 | Still on certificate, I believe in order to close the manual task, you need pki_user role. I believe this role will give the user an ability to close other certificate tasks. is the design assuming that certificate owners need to go into the workspace to complete their task? |
Anyone with the pki_admin (which includes pki_user) or pki_user role will have read/write access to the Certificate Tasks
|

View original source

https://www.servicenow.com/community/itom-articles/itom-office-hours-q-amp-a-august-2026-apac-session/ta-p/3586621