Microsoft Copilot security directory

ServiceNow

Published by Microsoft

High risk

ServiceNow improves service levels, energizes employees, and enables your enterprise to work at lightspeed. Create, read and update records stored within ServiceNow including Incidents, Questions, Users and more.

Security assessment

Plutonium assessed this connector for permissions, capabilities, and security-relevant behavior.

  • Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
  • Can change or update your information: This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.
  • Can permanently delete data: This connector can erase records, files, or accounts. Once deleted the data may be unrecoverable - even an accidental request can cause permanent loss.
  • Stores long-lived access tokens: This connector requires persistent credentials. If those tokens leak or are stolen, whoever holds them gets the same access you granted.
  • Sends your data to outside companies: Anything you share with this connector flows to a third-party service. That company sees, stores, and may use the data according to their own policies.

Available capabilities

This add-on exposes 18 tools or capabilities.

  • Create Record
  • Delete an attachment (Preview)
  • Delete Record
  • Get Attachment Metadata (Preview)
  • Get catalog categories
  • Get catalog item
  • Get catalog items
  • Get catalogs
  • Get Knowledge Articles
  • Get Record
  • Get Record Types
  • List Records
  • Order item
  • Retrieve attachment content (Preview)
  • Retrieve attachment metadata (Preview)
  • Update Record
  • Upload a binary file as an attachment (Preview)
  • Upload a multipart file attachment (Preview)

The interactive security report will load automatically.