Default-Deny Unknown ServiceNow Tools
Maintains an allowlist of audited ServiceNow tool-name suffixes and denies any tool call whose name does not match an allowlisted entry.
Maintains an allowlist of audited ServiceNow tool-name suffixes and denies any tool call whose name does not match an allowlisted entry.
Fences off the most sensitive ServiceNow tables from two routes that reach them:
servicenowfence-sensitive-tablespiiingresssoc2hipaapci-dssgdpr-ccpa
Keeps agent-drafted ServiceNow comments off the customer/employee-visible journal by rewriting add comment calls to internal work notes.
servicenowforce-internal-commentscommentswork-notesingresssoc2finra
Freezes the identity-and-access mutation surface of the ServiceNow MCP server. The policy denies, by tool-name suffix:
servicenowfreeze-identity-planeingressidentitygroupssoc2iso27001-nist
Unconditionally denies the ServiceNow change-management control-gate tools — the ones whose names end in approve change, reject change, or submit change for…
servicenowrequire-human-approvalchange-managementseparation-of-dutiesingresssoc2
else fails closed
servicenowrole-gate-writesaccess-controlleast-privilegeingresssoc2gdpr-ccpa