Who has elevated access and should they still have it? Reviewing privileged access in ServiceNow

Elevated access can arrive through direct grants, group membership, or inherited roles. xtype Compliance shows the effective access, flags the accounts that need attention, and traces each finding to source.
17 September 2026
6
minute read
3
paths to elevated access: direct, group-based, and inherited
2
findings worth checking first in every access review
2
dashboards that connect risky access with production change
1
export that stays traceable to the underlying source records

The second question in almost every ServiceNow audit is simple to ask and hard to answer: who holds elevated access to production, how did they get it, and should they still have it?

Part one of this series looked at segregation of duties in change management - whether the person who built a change also promoted it. Part two follows the access behind that change. The same account can acquire privilege through several paths, and a direct-role report shows only one of them.

01 · WHAT EFFECTIVE ACCESS MEANS

Direct assignments are only one path to privilege

Someone can hold an elevated role because it was granted directly. They can also receive it through a group that carries the role, or through another role that contains it two or three levels down.

A report that reads only direct assignments is not slightly incomplete. It is structurally blind to one of the most common ways people end up with more access than anyone intended.Why effective access matters
Diagram showing direct assignment, group membership, and nested roles converging into one account and its effective elevated access.

That is why elevated-access evidence takes time to assemble. The reviewer has to resolve the account's effective roles, not simply export a direct-assignment table. The work usually becomes a ticket to the platform team, followed by a CSV, manual reconciliation, and another ticket when the auditor asks a follow-up question.

02 · THE DASHBOARD

Who could go around you entirely

The Elevated Access dashboard uses the same shape as Segregation of Duties: donut charts across the top, a list below, similar filters, and the same export. What changes is the subject. This view shows elevated roles, who holds them, and whether those accounts are set up the way they should be.

When an account needs a second look, you can see what it worked on - which systems and applications - and follow the finding to the underlying record.

Effective access includes direct group and inherited roles

A direct-assignment report misses the way many people acquire privilege. xtype Compliance resolves each path so the review shows the access an account can actually use.

03 · THE FINDINGS TO CHECK FIRST

Start with dormant privilege and self-elevation

Two findings deserve immediate attention. The first is elevated access on an account that never logs in. The second is an account that granted elevated access to itself. Use the two lower column cards for these findings so a reader can compare them before continuing to the combined change-and-access scenario.

Elevated accounts that never log in

Admin rights can remain on a leaver, migration artifact, or integration account that outlived its purpose. Dormant elevated access deserves review even when nobody intended harm.

Accounts that elevated themselves

The person granting access and the person receiving it should not be the same. A self-elevation finding shows the identity, the access path, and the source record behind it.

04 · WHERE THE TWO DASHBOARDS MEET

Change evidence and access evidence show the full sequence

Picture a user who elevated their own access and then used it to promote their own update set. On the Segregation of Duties dashboard, that promotion appears as a possible violation. On the Elevated Access dashboard, the same name appears again with the self-elevation that made it possible.

A change report by itself shows an exception without a cause. An access report by itself shows a risky account with nothing attached to it. Together, the two dashboards show the sequence a reviewer needs in order to decide whether the activity matters.

The same two screens work for an incident

This is useful outside audit season. Suppose something changed in production that should not have: a configuration broke a downstream process, or an activity looked wrong during a review. The opening questions are familiar. What changed? Who promoted it? Were they supposed to be able to?

Reconstructing that by hand takes four investigations: find the update set, find the promotion, pull the account's roles, and work out how the account acquired them. Here, the same two screens used for the audit reconstruct the sequence. Find the change, see who promoted it, then look up that person on the other dashboard to see what access they held, whether they granted it to themselves, and what else they touched.

These are compliance dashboards, not detection tooling. They do not tell you an incident is underway. They compress the reconstruction afterward from days of cross-referencing into a couple of screens, which matters when someone senior is waiting for an answer.

05 · EVIDENCE YOU CAN HAND OVER

A filter and an export replace the ticket loop

Both dashboards export to a spreadsheet, and that detail matters more than it sounds.

The export is sortable, so a reviewer can work it instead of only reading it. It can attach directly to an incident record or compliance request, so it stays with the rest of the audit trail instead of sitting in someone's downloads folder. Every row traces back to a source record, so “show me where this came from” becomes a click instead of another ticket.

That is the difference between a screenshot and evidence that stands up in a walkthrough.

06 · WHAT THE DASHBOARDS DO

They support a control review without claiming to make you compliant

Compliance is a judgment reached about an organization based on whether its controls were designed appropriately and operated as described. No product delivers that verdict.

xtype Compliance does something narrower:

  • It answers two specific control questions directly from the records ServiceNow already keeps.
  • It covers every promotion and elevated account in the selected period rather than a sample assembled by hand.
  • It flags possible violations against a defined rule instead of leaving the reviewer to spot them by eye.
  • It keeps every row traceable to its source record, so the export does not contain assertions the reviewer cannot substantiate.

The practical effect is that evidence collection stops consuming a week and becomes a filter and an export. The analyst can spend that time on the work that requires judgment: deciding which exceptions matter and what to do about them.

Get the free ebook
xtype Multi-Instance Management Platform for ServiceNow Platform Teams
Get the eBook
Instant Demo
Check out how xtype provides the ability to meet ANY level of demand from the business on the ServiceNow platform.
Access Demo
News
Your one-stop destination for the latest and greatest happenings at xtype.
See the News

About the author

See xtype Compliance on your own estate

Book a 20-minute demo and see how xtype turns a sprawling multi-environment footprint into a single estate that observes, controls, and proves every change from a single pane of glass, and how xtype Compliance hands your auditor independent, framework-mapped evidence instead of a spreadsheet.
Research figures are drawn from xtype’s 2026 study of 50 organizations that report on compliance for data residing in ServiceNow, spanning financial services, healthcare, insurance, energy, government, manufacturing and technology. Framework mappings are indicative and should be confirmed against your own control set and assessor expectations. xtype Compliance reports segregation of duties and privileged-access controls across ServiceNow instances from data collected at install; immutable, signed audit-trail evidence and runtime control enforcement are on the xtype roadmap.

Frequently asked questions

What did the xtype research actually measure?
We surveyed 50 organizations across financial services, healthcare, insurance, energy, government, manufacturing and technology, every one of them reporting on compliance for data that lives in ServiceNow. The headline numbers: 100% report on compliance for ServiceNow data, 64% spend more than 21 hours a month on manual reporting, 76% build custom one-off reports just for ServiceNow, and 62% are driven by SOX. Read together, they describe a manual process that produces self-attested evidence.
What is configuration drift in ServiceNow, and why does it fail audits?
Drift is any divergence between the state your controls assume and what is actually running: a privileged role someone granted themselves, or an author who pushed their own change to production without a second set of eyes. On paper the process looks followed, so it never surfaces in the change record. xtype Compliance catches it by checking authors against deployers and every privileged grant against your policy, across every instance and through every clone, so it shows up as evidence rather than an audit surprise.

How do you get audit-ready in ServiceNow?
xtype Compliance runs the two reviews auditors test most, segregation of duties and privileged access, across every ServiceNow instance, and packages the results as auditor-ready evidence with every exception linked to its source record. Because it runs off data xtype already collects, you can produce that evidence the day after install, which is how xtype customers see up to a 75% reduction in audit preparation time.
Does xtype compete with ServiceNow GRC or IRM?
No, and you likely need both. GRC is where you manage your compliance program: policies, risks, and controls. xtype governs the ServiceNow platform those controls run on, capturing across every instance and through every clone what changed, who had access, and whether the control held. GRC documents the control; xtype provides the independent evidence it was enforced, and feeds GRC the platform evidence it cannot generate itself. xtype is a native ServiceNow application, backed by ServiceNow Ventures, and Simon Short, SVP of Customer Excellence at ServiceNow, sits on the xtype board.

How does xtype Compliance fit with our ServiceNow security and AI products?
It complements them. Native security and AI tooling governs what happens inside the front door of the platform, and xtype Compliance watches the platform itself, where direct edits do not generate a change record. As ServiceNow lets it rip on AI, xtype gives platform teams the speed with safety they need, consolidating a sprawling multi-environment footprint into a single pane of glass that answers one question: what happened on my ServiceNow platform today?
How does xtype help with ServiceNow compliance?
xtype Compliance is a standalone report for the teams who have to attest to ServiceNow. It checks the two controls auditors test most, segregation of duties (the person who built a change is not the person who deployed it) and privileged access (every admin and elevated grant authorized, never self-granted), across every instance and through every clone. The results feed a single, framework-mapped evidence package. It runs off data xtype already collects, so it works the day after install, and as you adopt xtype more fully those controls move from evidenced after the fact to enforced before a change reaches production. xtype customers see up to a 75% reduction in audit preparation time.
What changes does xtype track across instances?
xtype observes, controls, and proves the changes across all instances in real-time including update sets, scoped apps, store apps, plugins, records, XML files, scripts, and releases. For compliance specifically, xtype Compliance focuses that visibility on the two controls auditors test most, segregation of duties and privileged access. One view, every instance, from Dev through Prod.
Which compliance frameworks does xtype Compliance map to?
The strongest fits are SOX ITGC change-management and logical-access controls, SOC 2 CC6 and CC7, and ISO 27001 Annex A. It also supports HIPAA and GDPR access-control evidence, showing who held access to systems carrying protected data and whether it was authorized. Broader coverage for regulated industries, including DORA, PCI DSS, and GxP, is on the roadmap. Framework mappings are indicative and should be confirmed against your own control set and assessor expectations.
What does a ServiceNow compliance audit check, and how is that different from self-attestation?
A ServiceNow compliance audit checks that access and change controls were actually enforced: that privileged access was authorized and never self-granted, that duties stayed separated between who builds a change and who deploys it, and that production only changed through an approved process. Self-attestation is the platform team producing a report about its own work, which auditors increasingly flag as the absence of an independent control. xtype Compliance generates that evidence independently of the team being audited, across every instance, which is the definition of an independent control.
How quickly can we stand this up?
Fast. xtype Compliance is a native application that runs off data xtype already collects, so you get a working segregation-of-duties and privileged-access report the day after install, with no change to how you deploy and no dependency on the platform team. That is the land-and-expand path: start on the standalone report, then grow into the full xtype platform and runtime enforcement when you are ready.