0
3.0.0
Australia Patch 5, Australia Patch 3, Australia Patch 1, Australia, Zurich Patch 4, Zurich Patch 1
Generative AI
ServiceNow Otto for Vault lets you classify, encrypt, and govern access to sensitive data through AI skills and agentic workflows built into the Vault console. It proposes data classes for columns and custom apps, generates data patterns from plain language, and encrypts fields with the access policies each role needs.
- Generate a custom data pattern — creates a custom regular expression data pattern from your description and adds it as an active data pattern
- Check role access for an encrypted column — identifies the user roles that have access to encryption and decryption keys in your instance
- Schedule a data discovery job — schedules one-time or recurring data discovery jobs to detect sensitive data such as PII or PHI
- Securing custom apps with Vault agents — proposes data classifications and available protections for a custom application
- Field encryption and auto-generate access policies — encrypts a table field and creates a module access policy for each role that needs access to it
- Field encryption with Vault module — encrypts specific fields and configures secure access for users with designated roles
- Access observer configuration — views, creates, deactivates, and deletes Access Observer settings for a particular field
- Summarize access observer logs — reviews and summarizes access logs for a specific field, identifying access sources, users, and their roles
New
- Conversational anonymization policy creation. Create a new anonymization policy through the agent — set the policy details and data class, assign an anonymization technique per column, and, for user-specific policies, choose the user reference column. The validated policy is saved and ready for scheduling
- Conversational anonymization job creation and scheduling. Using a new or previously published policy, configure a run-once, weekly, or monthly job through the agent, add optional record-level conditions, confirm the schedule, and monitor execution status from the job schedule summary
- Real-time anonymization policy creation through the agent. The agent confirms that real-time anonymization is supported, then lets you select target tables and active data patterns, name the policy, and choose the target and child columns. Once created, the policy anonymizes sensitive data as records are created or updated
- Field encryption and auto-generate access policies agentic workflow. Request encryption for a table field, review the roles that currently have access to it, and confirm the final list. The workflow creates a module access policy for each confirmed role and then encrypts the field, so you no longer review access control lists or Access Observer logs to build the role list yourself
- Data Privacy setup agent. Configure channel-based data privacy through the agent, including policy creation, data pattern selection, and anonymization technique, so that sensitive data is masked before it is sent to the LLM
Changed
- The security_admin role is no longer used as the role masking agent for the Access Observer and Field Encryption agentic workflows. Following least-privilege principles, these workflows run without elevating to security_admin
- Now Assist for Vault is now ServiceNow Otto for Vault. The application name and its references in the product have changed; functionality is unaffected
Not applicable for this application version.
Australia and above.
ServiceNow Vault and Pro Plus license.