ServiceNow Integration Permissions
This page covers the roles and permissions required to configure and use the ServiceNow integration in Qualytics.
Two Permission Layers
Permissions for the ServiceNow integration are split into two layers:
- Qualytics User Role (Admin, Manager, Member) controls who can manage the integration and perform global actions.
- Team Permission (Editor, Author, Drafter, Viewer, Reporter). For actions that touch a specific anomaly, the user must also have the right permission on the anomaly's datastore team.
Integration Configuration
Actions that manage the integration itself (connecting, viewing, disconnecting).
Single Integration
Only one ticketing integration can be active at a time. Connecting a ServiceNow integration while Jira is already connected will fail until the existing one is disconnected.
Ticket Operations on Anomalies
Actions that create or manage links between anomalies and ServiceNow incidents. These require both the right user role and the right team permission on the anomaly's datastore.
Team Permissions Hierarchy
Team permissions are hierarchical: Editor → Author → Drafter → Viewer → Reporter. Higher-tier permissions automatically include all lower-tier permissions. For example, a user with Editor permission automatically satisfies any action requiring Author, Drafter, Viewer, or Reporter.
See Team Permissions for details.
How Both Layers Work Together
For ticket operations on anomalies, both layers must be satisfied:
- The user must have the required Qualytics user role (e.g., Manager+ to create tickets).
- The user must have the required team permission on the anomaly's datastore (e.g., Reporter to view, Author to link).
Examples:
- A Member with Editor team permission cannot create a ServiceNow incident, because Member is blocked at the user-role layer.
- A Manager without team membership in the datastore cannot create incidents for anomalies in that datastore, because they are blocked at the team layer.
- An Admin bypasses team permissions entirely and has full access regardless of team membership.
UI Behavior Without Permission
ServiceNow-Side Permissions
The ServiceNow service account used for the integration must have the following roles:
See Requirements for the full list of service account requirements.
Full User Roles Reference
For the complete User Roles matrix across all Qualytics features, see the User Roles page.
See Also
-
How It Works
Data flow direction, what gets synced, field mapping, and what the integration can and cannot do.
-
Sync Behavior
What happens on each operation: creating and linking incidents, the incident states, and the two sync modes.
-
Requirements
The ServiceNow instance, the account Qualytics authenticates as, and what it must be allowed to do.
-
Best Practices
Reading the Tickets panel, and the choices that keep incidents and anomalies in step.