Claude security directory

ServiceNow

Published by ServiceNow

Medium risk

Connect to ServiceNow directly in Claude via ServiceNow Action Fabric. Run governed cross-departmental workflows and actions across IT, HR, Customer Service, Security, Risk, and more, all while respecting your existing ServiceNow permissions and security controls. Use out-of-the-box, domain specific MCP Servers built by ServiceNow App teams. Build your own custom ServiceNow MCP Servers using platform capabilities your teams use today.

Security assessment

Plutonium assessed this web connector for permissions, capabilities, and security-relevant behavior.

  • Reads your private information: ServiceNow commonly contains sensitive IT, HR, Security, and Customer Service records (e.g., incidents, cases, employee data) that could be accessed depending on your ServiceNow permissions.
  • Can change or update your information: Action/workflow capabilities imply the connector may create or update tickets, cases, tasks, approvals, and related records within ServiceNow under your granted roles.
  • Stores long-lived access tokens: Connecting to ServiceNow typically requires OAuth/API credentials that may be stored for ongoing access, increasing impact if tokens are mishandled or over-scoped.

The interactive security report will load automatically.