Skip to main content
Connect ServiceNow to track human tasks as tasks or change requests. Each request is assigned to a person and includes the vulnerability, the agent’s recommendation, and the action your team needs to take.

Access required

Have a ServiceNow administrator configure an OAuth client for Antigen using the client credentials grant. The client needs access to create and update your chosen task or change request records, read assignees, and exchange comments. Limit access to the tables and operations required by that workflow. Your instance’s roles and access controls still apply. See ServiceNow client credentials for the instance requirements.

Connect ServiceNow

1. Configure the OAuth client

Have your administrator create an inbound OAuth client for Antigen, enable the client credentials grant, and associate it with an integration user that has the required permissions. Copy the client ID and client secret. See Configure an OAuth application user for assigning the user to the client.

2. Enter your instance details

Open Settings → Integrations → ServiceNow in Antigen. Enter your instance URL, such as https://example.service-now.com, and the OAuth client ID and secret.

3. Choose how tasks appear

Select the task or change request type your team uses, then configure its required fields and assignment group where applicable. Each human task is assigned to the responsible person’s ServiceNow account. Complete the connection after choosing the workflow.

Review and complete a request

Handle approvals through your existing ServiceNow process. If an agent proposes a production configuration change, your team reviews the recommendation, obtains any required approval, and makes the change. Add the outcome to the request and move it to the completed state in your workflow. Approval alone does not mean the requested change has been made. The agent uses the update to continue its work. See Issue tracking for how completing a task affects the vulnerability workflow.

Troubleshooting

Authorization fails

Have your administrator check that the client credentials grant is enabled, the client secret is current, and the OAuth application user is configured and active.

A task cannot be created or updated

Check the integration user’s access to the selected record type, required fields, and workflow transitions. The intended assignee must have an active account that can receive the request.