---
sourceDocument: Brazil Platform security
sourceDocumentLink: https://www.servicenow.com/docs/r/platform-security

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Elevated privilege roles

# Elevated privilege roles {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Elevated privilege roles

Elevated privilege roles in ServiceNow require users to manually accept responsibility to access specific role features during a user session.
These roles are not granted automatically at login and must be actively elevated by the user.
The elevated role persists only for the duration of the session and is removed upon timeout or logout.
Show full answer Show less  
You can designate any role as an elevated privilege role and assign it to users to restrict immediate access to the role's rights after login.

## Key Features

* **Manual Elevation:** Users must manually elevate each elevated privilege role assigned to them, even if they have already elevated a related role.
* **Role Assignment:** Elevated roles are assigned like other roles but require manual activation for privileges.
* **Session-Based:** Elevated privileges last only for the current session.
* **Admin Role Restrictions:** Only users with the admin role can grant admin or securityadmin roles. Non-admin users cannot add users to groups containing these roles.
* **Securityadmin Role:** This is the base system's only elevated privilege role by default, granting access to Access Control Lists (ACLs) and High Security Settings. It is automatically assigned to the default System Administrator (admin) user.
* **Visibility of securityadmin Role:** To view or use the securityadmin role, users must first elevate to it. It does not appear in role lists unless elevated.
* **Forcing Manual Elevation:** An optional system property can require all users with the administrator role to manually select and elevate the specific role they want to activate.

## Key Outcomes

* Improved security by limiting automatic access to sensitive roles and functions.
* Control over who can grant critical roles such as admin and securityadmin, reducing risk of unauthorized privilege escalation.
* Session-based elevation reduces prolonged exposure to elevated privileges, minimizing security risks.
* Clear separation of duties and responsibilities through manual role elevation and restricted role assignments.
* Enhanced protection for high security settings and access controls by requiring explicit elevation to the securityadmin role.  
Elevated privilege roles require you to manually accept the responsibility of using the
role before you can access the features of the role.

By default, you do not have elevated privilege roles upon login. You must manually elevate to
the privilege of the role. An elevated privilege role lasts only for the duration of your user
session. Session timeout or logout removes the role.

You can designate any role as an elevated privilege role, and then assign that role to one or
more users. Do this when you want to restrict users from having access to the rights that the
role provides immediately after login. You can designate the privilege role on the Role form. See
[Create a role](https://www.servicenow.com/docs/access?context=t_CreateARole&version=brazil&pubname=brazil-platform-administration&ft:locale=en-US) for instructions.  
To use an elevated role, you must meet these conditions:

* The elevated role must be assigned to you.
* You must manually elevate to a specific elevated role to get its privileges, even if you are already elevated to a second elevated role that contains the first elevated role.For
  example, if elevated role A contains elevated role B, even if you elevate to role A, you must
  still elevate to role B to get its privileges.

{#c_ElevatedPrivilege__ul_uhx_3yz_k1b}

## The admin role {#c_ElevatedPrivilege__section_b1s_fw4_3gb}

To grant the admin role to a user, the granting user must also have the admin role. For example, a user with only the user_admin role cannot grant the admin role to other users.

* Non-admin users cannot add a user to a group that contains the admin role.
* To grant the security_admin role to a user, the granting user must also have the admin role and must elevate to the security_admin role before granting the security_admin role to other users. A user with only the admin role cannot grant the security_admin role to other users.
* A user without the security_admin role cannot add a user to a group that contains the security_admin role.

{#c_ElevatedPrivilege__ul_tsk_gt4_3gb}  
Warning:  
The use of elevated privilege on an admin role is not supported. Instead, require admins to manually elevate, see [Force administrators to manually elevate](https://www.servicenow.com/docs/thqonZt6ZPt~UJdHY5hZTA "A property is available to force all users with the administrator role to manually select the role that they want to elevate to.")

## The security_admin role {#c_ElevatedPrivilege__section_rlm_wtz_k1b}

In the base system, the security_admin role is the only role that has elevated privileges.
This role is automatically assigned to the user who is the default System Administrator (admin)
user. It provides access to [ACLs](https://www.servicenow.com/docs/n~MLU9OizdlQo7fDhOrk0Q "Access control lists (ACLs) restrict access to data by requiring users to pass a set of requirements before they can interact with it.") and [High Security
Settings](https://www.servicenow.com/docs/_g5o20kuRsWDHQZC7ejjuw "High Security Settings refer to several security options available in your instance.").  
Figure 1. Roles assigned to the System Administrator (admin) user  
Note:  
To see this role, you must actually elevate to the security_admin role first. If you are logged in as the System Administrator (admin) user only, you cannot see the security_admin record in the list of roles.
* **[Security_admin role](https://www.servicenow.com/docs/OTHWtB_IDh~n773xM8EE0w)**   
  The security_admin role is an elevated privilege role provided with High Security Settings that lets users create and change access controls and change High Security Settings.
* **[Elevate to a privileged role](https://www.servicenow.com/docs/pOLlLS816Bs_Thh7RBuPjg)**   
  The base system admin can elevate to a privileged role to have access to the features of High Security Settings.
* **[Force administrators to manually elevate](https://www.servicenow.com/docs/thqonZt6ZPt~UJdHY5hZTA)**   
  A property is available to force all users with the administrator role to manually select the role that they want to elevate to.

