Reference

Policies for ServiceNow

See the ServiceNow inventory reference for the objects these templates work on.

Policy Description Severity Category Checks
ServiceNow AI agent is live and callable ⭐ Agents in an active state are callable, raising the likelihood that any weakness is exploited An ACTIVE AI agent is live and callable by users and workflows. Any weakness in a callable agent — a missing guardrail, an unapproved or deprecated model, an over-broad tool set — is far more likely to be exploited than in a draft or inactive agent. This raises the likelihood axis of the risk score. High Security ServiceNow AI Agent
ServiceNow AI agents with failed execution plans ⭐ Detects active AI agents that have execution plans in a failed state AI agents with failed execution plans indicate operational problems that may affect service delivery. Failed plans could represent broken tool integrations, permission issues, or configuration errors that need immediate investigation to restore agent functionality. Medium Operation ServiceNow AI Agent
ServiceNow AI agents active despite rejected approval ⭐ Detects AI agents in active state whose approval was rejected AI agents that remain active despite a rejected approval status represent a governance control failure. These agents were explicitly deemed unfit for operation yet continue to run, potentially introducing risks that the approval process was designed to prevent. High Security ServiceNow AI Agent
Stale ServiceNow AI agents (90+ days inactive) ⭐ Detects active AI agents that have not been updated in over 90 days Stale AI agents that have not been updated in over 90 days may be running on outdated models, lack current security patches, or no longer serve a business purpose. They consume resources and expand the governance surface unnecessarily. Low Declutter ServiceNow AI Agent
ServiceNow AI agents with excessive tool assignments ⭐ Detects active AI agents that have more than 10 tools assigned AI agents with an excessive number of tools have a broader capability surface area than necessary, violating the principle of least privilege. Each additional tool increases the potential impact of a compromised or misbehaving agent. Review tool assignments and remove those not required for the agent's defined purpose. Medium Security ServiceNow AI Agent
ServiceNow AI agent is reachable through an active use case ⭐ Active agents wired to a live use case are genuinely callable, raising the likelihood that any weakness is exercised An active AI agent that is wired to at least one active use case is genuinely callable by end users and workflows — not merely enabled. A reachable agent exercises whatever weaknesses it carries (missing guardrail, broad tool set, unapproved model) against real traffic, raising the likelihood axis of the risk score above that of an active-but-unwired agent. Medium Security ServiceNow AI Agent
ServiceNow AI agents without a description Detects active AI agents that have no description defined AI agents without descriptions make it difficult for administrators and auditors to understand the agent's purpose and scope. Proper documentation is essential for governance compliance, change management, and onboarding new platform administrators. Low Operation ServiceNow AI Agent
ServiceNow AI agents without approval ⭐ Detects active AI agents that have not been through an approval workflow AI agents operating without approval bypass governance controls and may introduce unauthorized capabilities, data access patterns, or compliance violations into the environment. High Security ServiceNow AI Agent
ServiceNow AI agents without guardrails ⭐ Detects active AI agents that have no guardrail configuration attached AI agents without guardrails can produce harmful, inaccurate, or non-compliant outputs. Guardrails enforce safety boundaries, data handling rules, and response quality standards essential for enterprise AI governance. High Security ServiceNow AI Agent
ServiceNow AI agents without a use case Detects active AI agents that have no use case assigned Active AI agents without an associated use case lack documented business justification. Every agent should be tied to a defined use case to ensure accountability, facilitate governance reviews, and demonstrate alignment with organizational objectives. Low Operation ServiceNow AI Agent
Deprecated ServiceNow AI models ⭐ Detects AI models in deprecated state that may still be referenced by agents Deprecated AI models may lose vendor support, miss security patches, or produce degraded outputs. Agents referencing deprecated models should be migrated to supported alternatives to maintain quality and security standards. Medium Operation ServiceNow AI Model
ServiceNow deprecated AI models still incurring spend ⭐ Detects deprecated AI models that are still being called and generating cost over the last 30 days A deprecated model that is still incurring spend means agents are actively calling a model the platform owners have retired. This wastes budget on an unsupported model that may lack current security patches or quality fixes. Migrate the referencing agents to a supported model to stop the spend and close the governance gap. Medium Costs ServiceNow AI Model
ServiceNow AI models with high 30-day spend ⭐ Detects AI models that accumulated more than $1,000 of estimated spend over the last 30 days An AI model accounting for more than $1,000 of estimated GenAI spend over the last 30 days is a major cost driver. Confirm the spend is expected, that the agents using it are right-sized, and that a cheaper or native model (e.g. Now LLM) could not serve the same use cases. The threshold is a starting point — tune it to your AI budget. Medium Costs ServiceNow AI Model
ServiceNow AI models not in approved state ⭐ Detects active AI model configurations that have not been explicitly approved AI models that are not in an approved state may not have been vetted for security, bias, or compliance requirements. Using unapproved models exposes the organization to regulatory and reputational risk. High Security ServiceNow AI Model
ServiceNow AI skills with unrestricted data access ⭐ Detects published Virtual Agent skills that have no data access scope defined AI skills with broad data access can read sensitive tables and expose confidential data through agent responses. Restricting data access scope is essential for protecting PII and maintaining compliance. Medium Security ServiceNow AI Skill
ServiceNow AI skill is published and reachable ⭐ Published Virtual Agent skills are live and exercised against real user input, raising the likelihood of exploitation A PUBLISHED Virtual Agent skill is live and reachable by end users at runtime. Any weakness in a published skill — unrestricted data access, a broad target scope — is exercised against real user input, making it far more likely to be exploited than a draft or inactive skill. This raises the likelihood axis of the risk score. Medium Security ServiceNow AI Skill
Stale draft ServiceNow AI skills (30+ days) Detects AI skills that have been in draft state for over 30 days AI skills that remain in draft state for extended periods indicate abandoned or stalled development efforts. These should be either completed and published or removed to prevent confusion about available capabilities. Low Declutter ServiceNow AI Skill
ServiceNow AI teams without agent members Detects AI teams that have no agent members assigned AI teams without any agent members serve no operational purpose and clutter the team management view. Empty teams should either be populated with appropriate agents or removed to maintain a clean governance inventory. Low Declutter ServiceNow AI Team
ServiceNow AI execution tasks in failed state Detects execution tasks that have failed Failed execution tasks represent individual steps within agent workflows that did not complete successfully. Patterns of failed tasks can reveal systemic issues with specific tools, permission gaps, or integration problems that degrade the AI agent experience. Low Operation ServiceNow AI Execution Task
External ServiceNow users with privileged roles ⭐ Detects external users who hold role assignments in ServiceNow External users with privileged roles such as admin, security_admin, or itil can access sensitive configuration and data. This creates significant risk if those external accounts are compromised or if the external relationship ends. High ExternalAccess ServiceNow User
ServiceNow groups without a manager ⭐ Detects active user groups that do not have a manager assigned Groups without a manager lack clear ownership and accountability. When issues arise, there is no designated person to make decisions about group membership, permissions, or policy compliance. Medium Operation ServiceNow User Group
ServiceNow AI guardrails with all protections in log-only mode Detects active guardrails where all four protection categories are set to log-only rather than enabled Guardrails configured entirely in log-only mode provide visibility but no active protection. While useful during initial rollout, leaving all protections in log-only mode long-term means harmful content, injection attempts, and PII leakage are detected but not blocked. Medium Security ServiceNow AI Guardrail
ServiceNow AI guardrails that are inactive Detects guardrail configurations that have been deactivated Inactive guardrail configurations indicate agents that may have lost their safety boundaries. If the associated agent is still active, it operates without content safety controls, creating risk for harmful outputs and compliance violations. Medium Security ServiceNow AI Guardrail
ServiceNow AI guardrails with prompt injection protection disabled ⭐ Detects active guardrail configurations where prompt injection protection is disabled Guardrails with prompt injection protection disabled leave AI agents vulnerable to adversarial prompt manipulation. Attackers can exploit this to bypass safety controls, extract sensitive data, or cause the agent to perform unauthorized actions. High Security ServiceNow AI Guardrail
ServiceNow AI guardrails without PII protection enabled ⭐ Detects active guardrail configurations where PII protection is disabled or in log-only mode Guardrails without full PII protection enabled risk exposing personally identifiable information in agent responses. Log-only mode detects but does not prevent PII leakage, leaving the organization vulnerable to data privacy violations and regulatory non-compliance. High Security ServiceNow AI Guardrail
Inactive ServiceNow users with assigned roles ⭐ Detects deactivated users that still have role assignments Inactive users who still hold role assignments represent a security risk. Their credentials could be compromised or their privileges could be exploited without detection since the user is not actively monitored. High Security ServiceNow User
ServiceNow instances over AI budget (30-day) ⭐ Detects instances whose aggregate GenAI spend exceeded $2,000 over the last 30 days A ServiceNow instance whose aggregate GenAI spend exceeds $2,000 over the last 30 days warrants a budget review. Confirm the spend maps to approved use cases, that high-cost models are justified, and that a resource/budget cap is in place. The threshold is a starting point — align it with the instance's allocated AI budget. Medium Costs ServiceNow Instance
ServiceNow AI tools without a description Detects AI tools that have no description defined AI tools without descriptions make it difficult for administrators to understand what actions agents can perform. Clear tool documentation is essential for governance reviews, security audits, and ensuring tools are used appropriately across agents. Low Operation ServiceNow AI Tool
ServiceNow instance with too many role assignments ⭐ Detects instances with more than 10 role assignments Too many admin users dilutes accountability and expands the attack surface. Each admin account is a high-value target for attackers. Limiting admin access ensures clear responsibility and reduces exposure. Medium Security ServiceNow Instance
Inactive triggers on ServiceNow AI use cases Detects triggers that are inactive Inactive triggers may represent misconfigured or accidentally disabled activation paths for AI agents. Review these triggers to determine if they should be reactivated or if the associated use case no longer requires this trigger channel. Low Operation ServiceNow AI Trigger
ServiceNow AI usage log entries with failures Detects AI usage log entries with failure or timeout status AI usage events that result in failure or timeout indicate reliability problems with model integrations. Persistent failures waste tokens, degrade user experience, and may signal misconfigured model endpoints or exhausted quotas that need administrative attention. Medium Operation ServiceNow AI Usage Log
ServiceNow AI usage with wasted spend on failed requests Detects AI usage events that consumed input tokens but failed or timed out, incurring cost with no result AI requests that fail or time out after the input has been submitted still consume input tokens, so they incur cost without delivering any result. A persistent volume of failed requests is wasted spend and usually points to a misconfigured model endpoint, an exhausted quota, or a broken tool integration. Investigate the root cause to stop the leak. Low Costs ServiceNow AI Usage Log
Stale ServiceNow AI use cases (180+ days inactive) Detects active use cases not updated in over 180 days Use cases that have not been updated in over 180 days may no longer reflect current business requirements. Stale use cases clutter the AI governance inventory and may mislead administrators about the actual scope of AI-driven automation. Low Declutter ServiceNow AI Use Case
ServiceNow AI use cases without an assigned agent ⭐ Detects active use cases that have no AI agent assigned Active use cases without an assigned AI agent represent defined business needs that are not being addressed by automation. These orphaned use cases should either be assigned to an appropriate agent or deactivated to maintain a clean governance inventory. Medium Operation ServiceNow AI Use Case
ServiceNow AI use cases without active triggers Detects active use cases that have no trigger configured Active use cases without any trigger configuration cannot be activated by users or events. These use cases either need trigger configuration to become functional or should be moved to draft/inactive state to reflect their actual status. Low Operation ServiceNow AI Use Case
ServiceNow external user is active and reachable ⭐ Active external users are externally-reachable identities and a more likely entry point for compromise An active external user is an externally-reachable identity that can authenticate against the instance. External accounts are outside the organization's direct lifecycle control and are a more readily exploited entry point if compromised, raising the likelihood axis of the risk score for any privilege those accounts hold. High ExternalAccess ServiceNow User
ServiceNow users not logged in for 180+ days ⭐ Detects active users who have not logged in for over 180 days Active user accounts that show no login activity for over 180 days represent dormant access that increases the attack surface. These accounts should be reviewed for deactivation to reduce security exposure and ensure license efficiency. Medium Declutter ServiceNow User
ServiceNow active user holds role assignments ⭐ Active users holding one or more roles are privileged, reachable identities and a more likely compromise vector An active user who holds one or more role assignments is a privileged, reachable identity. Privileged accounts are higher-value targets and any weakness in their access is more likely to be exploited than for a role-less account, raising the likelihood axis of the risk score. This compounds with the external-user signal for active external users that also hold roles. Medium Security ServiceNow User

Last updated: 7/19/2026