Who built it and who shipped it? Proving segregation of duties in ServiceNow

Auditors want proof that developers do not promote their own changes. See how xtype Compliance checks every in-scope promotion and traces each result back to its ServiceNow record.
15 September 2026
5
minute read
2
questions that start almost every ServiceNow audit review
1
segregation-of-duties rule checked across the selected period
100%
of in-scope promotions evaluated rather than sampled
1 click
from each result to its underlying ServiceNow record

Every audit cycle I have worked on has come down to two questions.

The first: the person who built this change - did they also push it live?

The second: who holds elevated access to production, and should they still have it?

Neither question is complicated. Both can cost a compliance analyst the better part of a week. This two-part series looks at why, and then shows how xtype Compliance answers them from two dashboards. Part one focuses on segregation of duties: whether the person who built an update set also promoted it. Part two follows the access that can make an unapproved promotion possible.

01 · WHY THE QUESTION IS FAIR

Auditors want evidence instead of assurance

The question is not arbitrary. Segregation of duties in change management appears in nearly every framework a regulated company reports against. SOC 2 tests it. ISO 27001 names it. SOX ITGC testing walks it every year.

The standard for answering is not “tell me.” It is “show me.” An auditor does not want an assurance that developers do not deploy their own code. They want evidence that it did not happen over a defined period, across the full population rather than a convenient handful, with every item traceable to a source record.

A screenshot proves that one record looked a particular way on the day somebody captured it. It does not establish how that record was selected, what was left out, or whether the population was complete. The audit evidence gap

Most teams respond with screenshots and a written narrative. The narrative describes how a control is meant to work; it does not evidence that the control operated. Then there is the practical question that decides whether any of this happens on time: who can pull the evidence together?

Answering properly takes someone who knows which tables hold the data and has the rights to query them - usually a platform engineer or an administrator, not the compliance analyst who owns the deadline. That person is already committed to a sprint that has nothing to do with the audit.

02 · WHY THE USUAL ANSWER BREAKS

The data exists but it lives in different places

ServiceNow has the data. The problem is where it lives and who can reach it.

An update set - the XML record ServiceNow writes when a developer changes something - tells you who created it. The promotion tells you who moved it. Those are different objects. Answering “were those two the same person?” means joining them across however many instances you run and over whatever period the auditor asks about.

The question becomes a ticket. The ticket goes to the platform team. A CSV comes back two days later. The analyst opens it in Excel and starts reconciling by hand. Then the auditor asks a follow-up question, and the loop starts again. The platform team is on the other end of that loop, pulling exports against someone else's deadline.

That gap is what xtype Compliance is built to close. Its Segregation of Duties dashboard puts the first audit question in front of the analyst without a ticket or a custom report.

The developer who built a change should not promote it

xtype Compliance comparesthe developer recorded on each update set with the person recorded on thepromotion. A match is flagged as a possible violation, and every result linksback to the source record.

03 · THE DASHBOARD

Who built it and who shipped it

The Segregation of Duties dashboard opens on four donut charts: the proportion of promotions that may be violations, who performed them, which instance they happened on, and which applications they touched.

That layout is deliberate. Before reading a single row, you can see the shape of the review. If one name dominates the second chart, or one application dominates the fourth, you know where to start in a few seconds instead of after an afternoon of sorting.

Below the charts is the list, and every row is an update set. It is not a summary or a rollup. It is the actual artifact of the change.

The dashboard applies one rule in the current release: the developer who built the update set should not be the person who promoted it. It is a fixed rule rather than a policy engine you configure, but it addresses the incompatible pairing auditors care about most: developer and production deployer.

The same evidence supports segregation-of-duties testing under SOC 2, ISO 27001 A.5.3, and SOX ITGC program change controls.

Two filters narrow the review. Date range sets the period in scope. Promotion source lets you review everything together or separate promotions run through ServiceNow from those automated through xtype.

Click any row, and you are inside the update set: timestamp, originating activity, who did what, and a path to the underlying ServiceNow record. There is no ticket, no CSV, and no two-day wait.

Date range

Set the exact period inscope for the audit or control review. The dashboard evaluates the fullpopulation of promotions in that window.

Promotion source

Review every promotion together or separate promotions run through ServiceNow from those automated through xtype.

Evidence the reviewer can work with

The value is not another dashboard to look at. It is a reviewable population. The analyst can filter the exact period, inspect possible violations, and trace every result to the record that produced it.

Next: who holds elevated access to production, how they received it, and whether they should still have it.

Get the free ebook
xtype Multi-Instance Management Platform for ServiceNow Platform Teams
Get the eBook
Instant Demo
Check out how xtype provides the ability to meet ANY level of demand from the business on the ServiceNow platform.
Access Demo
News
Your one-stop destination for the latest and greatest happenings at xtype.
See the News

About the author

See xtype Compliance on your own estate

Book a 20-minute demo and see how xtype turns a sprawling multi-environment footprint into a single estate that observes, controls, and proves every change from a single pane of glass, and how xtype Compliance hands your auditor independent, framework-mapped evidence instead of a spreadsheet.
Research figures are drawn from xtype’s 2026 study of 50 organizations that report on compliance for data residing in ServiceNow, spanning financial services, healthcare, insurance, energy, government, manufacturing and technology. Framework mappings are indicative and should be confirmed against your own control set and assessor expectations. xtype Compliance reports segregation of duties and privileged-access controls across ServiceNow instances from data collected at install; immutable, signed audit-trail evidence and runtime control enforcement are on the xtype roadmap.

Frequently asked questions

What did the xtype research actually measure?
We surveyed 50 organizations across financial services, healthcare, insurance, energy, government, manufacturing and technology, every one of them reporting on compliance for data that lives in ServiceNow. The headline numbers: 100% report on compliance for ServiceNow data, 64% spend more than 21 hours a month on manual reporting, 76% build custom one-off reports just for ServiceNow, and 62% are driven by SOX. Read together, they describe a manual process that produces self-attested evidence.
What is configuration drift in ServiceNow, and why does it fail audits?
Drift is any divergence between the state your controls assume and what is actually running: a privileged role someone granted themselves, or an author who pushed their own change to production without a second set of eyes. On paper the process looks followed, so it never surfaces in the change record. xtype Compliance catches it by checking authors against deployers and every privileged grant against your policy, across every instance and through every clone, so it shows up as evidence rather than an audit surprise.

How do you get audit-ready in ServiceNow?
xtype Compliance runs the two reviews auditors test most, segregation of duties and privileged access, across every ServiceNow instance, and packages the results as auditor-ready evidence with every exception linked to its source record. Because it runs off data xtype already collects, you can produce that evidence the day after install, which is how xtype customers see up to a 75% reduction in audit preparation time.
Does xtype compete with ServiceNow GRC or IRM?
No, and you likely need both. GRC is where you manage your compliance program: policies, risks, and controls. xtype governs the ServiceNow platform those controls run on, capturing across every instance and through every clone what changed, who had access, and whether the control held. GRC documents the control; xtype provides the independent evidence it was enforced, and feeds GRC the platform evidence it cannot generate itself. xtype is a native ServiceNow application, backed by ServiceNow Ventures, and Simon Short, SVP of Customer Excellence at ServiceNow, sits on the xtype board.

How does xtype Compliance fit with our ServiceNow security and AI products?
It complements them. Native security and AI tooling governs what happens inside the front door of the platform, and xtype Compliance watches the platform itself, where direct edits do not generate a change record. As ServiceNow lets it rip on AI, xtype gives platform teams the speed with safety they need, consolidating a sprawling multi-environment footprint into a single pane of glass that answers one question: what happened on my ServiceNow platform today?
How does xtype help with ServiceNow compliance?
xtype Compliance is a standalone report for the teams who have to attest to ServiceNow. It checks the two controls auditors test most, segregation of duties (the person who built a change is not the person who deployed it) and privileged access (every admin and elevated grant authorized, never self-granted), across every instance and through every clone. The results feed a single, framework-mapped evidence package. It runs off data xtype already collects, so it works the day after install, and as you adopt xtype more fully those controls move from evidenced after the fact to enforced before a change reaches production. xtype customers see up to a 75% reduction in audit preparation time.
What changes does xtype track across instances?
xtype observes, controls, and proves the changes across all instances in real-time including update sets, scoped apps, store apps, plugins, records, XML files, scripts, and releases. For compliance specifically, xtype Compliance focuses that visibility on the two controls auditors test most, segregation of duties and privileged access. One view, every instance, from Dev through Prod.
Which compliance frameworks does xtype Compliance map to?
The strongest fits are SOX ITGC change-management and logical-access controls, SOC 2 CC6 and CC7, and ISO 27001 Annex A. It also supports HIPAA and GDPR access-control evidence, showing who held access to systems carrying protected data and whether it was authorized. Broader coverage for regulated industries, including DORA, PCI DSS, and GxP, is on the roadmap. Framework mappings are indicative and should be confirmed against your own control set and assessor expectations.
What does a ServiceNow compliance audit check, and how is that different from self-attestation?
A ServiceNow compliance audit checks that access and change controls were actually enforced: that privileged access was authorized and never self-granted, that duties stayed separated between who builds a change and who deploys it, and that production only changed through an approved process. Self-attestation is the platform team producing a report about its own work, which auditors increasingly flag as the absence of an independent control. xtype Compliance generates that evidence independently of the team being audited, across every instance, which is the definition of an independent control.
How quickly can we stand this up?
Fast. xtype Compliance is a native application that runs off data xtype already collects, so you get a working segregation-of-duties and privileged-access report the day after install, with no change to how you deploy and no dependency on the platform team. That is the land-and-expand path: start on the standalone report, then grow into the full xtype platform and runtime enforcement when you are ready.