Skip to main content

SNOW-29.1: Domain Separation Drift (Missing sys_domain)

๐Ÿ”ด High ยท ServiceNow Domain Separation

Detects GlideRecordSecure queries in agent-facing scripts that lack sys_domain constraints. In domain-separated instances, omitting the domain filter allows cross-tenant data access even when ACLs pass.

Detailsโ€‹

FieldValue
Rule IDSNOW-29.1
SeverityHigh
CategoryServiceNow Domain Separation
Platformsservicenow
ComplianceSOC2_CC6, NIST_AI_RMF

Remediationโ€‹

Refer to the SquireX documentation for remediation guidance specific to SNOW-29.1.

See Alsoโ€‹