IT CanvassTalk to an advisor
Connectors · LessonBy , SailPoint Architect · Published · IdentityIQ 8.4 · all levels

ServiceNow

Governing ServiceNow roles and groups, and using ServiceNow for tickets.

Quick answer

SailPoint integrates with ServiceNow to aggregate users, roles and groups and can also open service tickets for manual provisioning.

Key takeaways
  • ServiceNow connector type: a REST/API-based connector
  • Onboarding: aggregate then correlate
  • SailPoint can manage ServiceNow roles/groups and raise catalog/incident tickets for fulfillment.
  • Common issues covered in troubleshooting

ServiceNow plays two roles in a SailPoint deployment: it is a governed target (with its own roles and groups) and, very commonly, the fulfilment channel for manual provisioning, where SailPoint raises a ticket for a human to action. Integrating it covers both.

Connector type and how it connects

The ServiceNow integration is a REST/API-based connector. It uses the ServiceNow Table and Import Set APIs with a service account. As with every connector, the flow is the same: authenticate to ServiceNow, read accounts and entitlements during aggregation, and write changes during provisioning.

Onboarding the source

  • 1. Configure the connection and credentials for ServiceNow.
  • 2. Map the account schema, mapping ServiceNow users, roles and groups to SailPoint accounts and entitlements.
  • 3. Set the correlation logic so ServiceNow accounts attach to the right identities (typically on a stable key such as employee ID or email).
  • 4. Run account aggregation and confirm accounts and entitlements load.
  • 5. Verify correlation, watching for uncorrelated/orphan accounts.

Provisioning capabilities

SailPoint can manage ServiceNow roles and group memberships directly, and, importantly, can open catalog or incident tickets in ServiceNow for access that must be fulfilled manually, then track those tickets to closure. This bridges automated governance with human fulfilment for systems without a write connector.

Entitlements and what to govern

Govern ServiceNow roles and groups for direct access. For the ticketing integration, the value is process, every manual grant becomes a tracked, auditable work item rather than an email.

Troubleshooting

When ServiceNow aggregation or provisioning fails, work through the usual causes in order:

  • Verify the ServiceNow service account and its roles for API access.
  • Confirm the instance URL and that the required tables/APIs are reachable.
  • Check any ACLs restricting the service account.
  • Validate role/group schema mapping and ticket templates.

Common pitfalls

  • Credential expiry (tokens/secrets) silently breaking the connector.
  • Insufficient rights on the ServiceNow service account for the operations you need.
  • Schema or correlation misconfiguration leaving accounts uncorrelated.

Practice challenge

+0 XPStreak ×0
Question 1 of 3
What type of connector is ServiceNow?

Frequently asked questions

What does the term ServiceNow connector refer to in SailPoint?
ServiceNow plays two roles in a SailPoint deployment: it is a governed target (with its own roles and groups) and, very commonly, the fulfilment channel for manual provisioning, where SailPoint raises a ticket for a human to action. Integrating it covers both.
What else is worth knowing about ServiceNow connector?
The ServiceNow integration is a REST/API-based connector. It uses the ServiceNow Table and Import Set APIs with a service account.
What is the practical takeaway on ServiceNow connector?
As with every connector, the flow is the same: authenticate to ServiceNow, read accounts and entitlements during aggregation, and write changes during provisioning.
What tends to go wrong with ServiceNow connector?
Credential expiry (tokens/secrets) silently breaking the connector. Insufficient rights on the ServiceNow service account for the operations you need. Schema or correlation misconfiguration leaving accounts uncorrelated.
Want this with a live instructor and a lab tenant?
SailPoint IdentityIQ training →
Already working on SailPoint and stuck on a live ticket?Get an expert SailPoint developer on screen-share to finish your daily tasks with you. Deliver on time, protect your reputation and your job. Monthly support only, no task-wise plans.Task assigned · no idea where to startStill stuck · your job on the lineExpert joins your screenDelivered on timeExplore On Job Support