User Setup

Last Updated: April 28, 2026

Tenable for ServiceNow allows you to assign specific role privileges to users based on your organizational requirements. By configuring these roles, you ensure that users have the appropriate level of access to manage connectors, configurations, and scheduled jobs within your ServiceNow instance.

Note: The Integration Service Account only needs these roles to function: itil or incident_manager to create/update incidents and rest_service for API access.

Caution: The x_tsirm_tio_now.import_set_admin role is used to access import set tables across all the tenable apps. Tenable does NOT recommend to give this role to any user.

User Permissions For Non-Domain Separated Instances

User Role Permission Description
System Administrator admin

Installation of the integration application plugins
User Creation
Application Log
Create the Connection Alias
Create the connector
Configuration
Configure Scheduled Job
Resources
Process Monitor
Support

This user-role is the admin of the ServiceNow Instance and has privileges to perform all the integration-specific actions.
Tenable Application Admin

canvas_user
cmdb_inst_admin
connection_admin
x_tsirm_tio_itsm.admin
x_tsirm_tio_now.admin
x_tsirm_tio_vr.admin

Create the connector
Configuration
Configure Scheduled Job
Resources
Process Monitor
Support

This user-role is the admin of the application and is allowed to create the connector, update the configuration, and configure the scheduled job.
Tenable Application User canvas_user
cmdb_inst_admin
x_tsirm_tio_itsm.user
x_tsirm_tio_now.user
x_tsirm_tio_vr.user

Read access of configuration
Read access to Connectors, scheduled jobs
Support

This user-role is limited to read-only configurations. These users are not able to create or update any configurations.

User Permissions For Domain Separated Instances

User Role Permission Description
System Administrator admin
x_tsirm_tio_now.domain_separation_admin

Installation of the integration application plugins
User Creation
Application Log
Create the Connection Alias
Create the connector
Configuration
Configure Scheduled Job
Resources
Process Monitor
Support

This user-role is the admin of the ServiceNow Instance and has privileges to perform all the integration-specific actions.
Tenable Application Admin

canvas_user
cmdb_inst_admin
connection_admin
x_tsirm_tio_itsm.admin
x_tsirm_tio_now.domain_separation_admin
x_tsirm_tio_vr.admin

Create the connector
Configuration
Configure Scheduled Job
Resources
Process Monitor
Support

This user-role is the admin of the application and is allowed to create the connector, update the configuration, and configure the scheduled job.
Tenable Application User canvas_user
cmdb_inst_admin
x_tsirm_tio_itsm.user
x_tsirm_tio_now.user
x_tsirm_tio_vr.user

Read access of configuration
Read access to Connectors, scheduled jobs
Support

This user-role is limited to read-only configurations. These users are not able to create or update any configurations.