Connector guides
ServiceNow tasks and accounts
Use Warde for applications with no identity engine, where ServiceNow catalog tasks carry out each change, and how the ServiceNow accounts engine works.
Not every application sits behind an identity engine. For those, Warde still runs the request, the approval, My Access and the access review, and a ServiceNow catalog task goes to the team that owns the application to make each change by hand.
Warde installs two engines for this. Neither needs a connection or a credential.
| Engine | Connector | What it does |
|---|---|---|
| ServiceNow tasks | ServiceNow (manual fulfilment) | Carries out changes as catalog tasks for a person |
| ServiceNow | ServiceNow (local instance) | Treats each user who holds the Warde requester role as an account on this instance |
The ServiceNow tasks engine
Work goes to this engine when:
- a collection is Unmanaged: no identity engine is bound to it;
- an entitlement cannot be fulfilled by its engine;
- the engine cannot make that kind of change, such as creating an account;
- the access cannot be removed through the engine.
The engine ships active and appears in Guided Setup step 2 with nothing to configure. It is not synced, health checked or alerted on.
What the task looks like
Each change is one sc_task under the requested item:
| Field | Value |
|---|---|
| Short description | Grant <access> to <person> or Remove <access> from <person> |
| Description | The collection's or entitlement's fulfilment instructions, then the person, account, access and request |
| Assignment group | The collection's support group, a fixed group or a field on its configuration item. If that gives no active group with active members, the fallback group from Guided Setup step 8. |
| Template | The entitlement's, else the collection's, else the instance default |
| Due date | The collection's provisioning window, or 2 business days, on the Warde fulfilment hours schedule |
Write the fulfilment instructions in Collection Onboarding step 3 so the person picking up the task knows exactly what to do in the application.
Closing the task
Make the change in the application, then close the task Closed Complete. Warde checks open tasks every hour and records the change. Closed Incomplete or Closed Skipped fails the change and leaves the access as it was. See Fulfilment and manual tasks.
Set up an application with no engine
- In the Admin Workspace, create a collection under Catalog > Collections for the application.
- Add its entitlements on the collection's related list.
- Optionally, bind the collection to the ServiceNow engine (below), so people's access is held on their ServiceNow account and only people with the requester role can hold it.
- Open the collection in Collection Onboarding and work through the steps. Set a support group and fulfilment instructions, then go live. A collection with no engine bound goes live as Unmanaged; one bound to the ServiceNow engine goes live as Managed, and every change is still a task.
Requests, removals and reviews for the collection now produce tasks for its support group. Collections you create by hand are never retired by a sync.
The ServiceNow accounts engine
The ServiceNow engine treats this instance as an identity system. Its accounts are the users who hold x_66256_warde.requestor, directly or through a group or role:
- a user who holds the role has an active account, keyed on the user's sys_id;
- a user who is made inactive, or loses the role, has their account disabled. Nothing is deleted.
The Warde ServiceNow accounts job keeps the accounts in step every 15 minutes, reading only what changed, with a full read at the full-sweep interval. It stops at 100,000 accounts (x_66256_warde.snow.account_ceiling).
The engine imports no catalog. Warde does not read ServiceNow roles or groups as entitlements, because it cannot remove a role grant from a scoped application. Bind a hand-made collection to this engine when you want its access held on people's ServiceNow accounts; every change is still a task.
The health check confirms the requester role exists. Separation of duties is not checked for this engine.