Administrator guide
Install Warde
What your instance needs before you install Warde, how to install it, and what the install adds.
Warde is one scoped application, x_66256_warde. It needs no IntegrationHub, Now Assist, ITOM, Performance Analytics or HR Service Delivery subscription. Install it in a sub-production instance first, set it up there, then install it in production.
Before you install
Platform release
Warde supports the current ServiceNow family and the one before it: Australia and Zurich.
Plugins that must be active
These are active on almost every instance, but a customer can switch any of them off. If one is missing, the records for it fail to install and the feature built on them does not exist.
| Feature | Plugin IDs |
|---|---|
| Service Catalog | com.glideapp.servicecatalog, com.glideapp.servicecatalog.platform, com.glide.ui_policy_catalog |
| Flow Designer | com.glide.hub.flow_engine, com.glide.hub.designer_backend.model, com.glide.hub.flow_trigger |
| Service Portal | com.glide.service-portal |
| Next Experience workspaces | com.glide.uxbuilder, com.glide.ux.list, com.glide.ux.config |
| Platform Analytics dashboards | com.snc.par.dashboards |
| Connections and Credentials | com.snc.core.automation.connection_credential, com.snc.core.automation |
| Outbound REST | com.glide.web_service_consumer |
| Scripted REST APIs | com.glide.scripted_rest_services |
| Import Sets | com.glide.system_import_set |
Optional
Warde installs and runs without any of these.
| Feature | What it adds | Without it |
|---|---|---|
| Employee Center | Request items in topics and quick links, and review tasks on My Tasks | Items are published through catalog categories and portal menus. Reviewers open reviews from the email or My Access. |
Explicit roles plugin (snc_internal) | One role that means everyone who can log in, for the requester role to sit under. Entitlement and bundle owners can see their pre-approval work. | Grant the requester role to groups, or use the daily job Guided Setup offers. Entitlement and bundle owners cannot see their pre-approval work. |
| A MID Server | Reaches an engine the instance cannot reach directly, usually IdentityIQ on premises | Only engines reachable from the instance |
| Incident | An engine that goes down can raise an incident | Engine alerts stay on "Nothing is raised" |
| Event Management | An engine that goes down can send an event, and a clear when it recovers | Not offered |
| Now Assist in Virtual Agent, with AI Search | The conversational item Request a single access item | The item stays switched off |
Instance settings
| Setting | Why it matters |
|---|---|
glide.email.smtp.active | Warde's emails, and the platform's request and approval emails, go out only when outbound email is on |
glide.sc.enable_url_prefill | Lets the links on My Access fill in the person when a manager requests for someone on their team. Without it, the manager changes the person on the form. |
Check an instance before you install
Paste this into System Definition > Scripts - Background in the global scope. It only reads. Any line that starts MISSING names a plugin to activate first.
var checks = [
['required', 'Service Catalog', 'sc_cat_item'],
['required', 'Catalog UI policies', 'catalog_ui_policy'],
['required', 'Flow Designer', 'sys_hub_flow'],
['required', 'Service Portal', 'sp_widget'],
['required', 'Workspace framework', 'sys_ux_app_config'],
['required', 'Workspace lists', 'sys_ux_list'],
['required', 'Platform Analytics dashboards', 'par_dashboard'],
['required', 'Connections and Credentials', 'sys_alias'],
['required', 'Outbound REST', 'sys_rest_message'],
['required', 'Scripted REST APIs', 'sys_ws_definition'],
['required', 'Import Sets', 'sys_transform_map'],
['optional', 'Employee Center quick links', 'sn_ex_sp_quick_link'],
['optional', 'Employee Center to-dos', 'sn_hr_sp_todos_config'],
['optional', 'Topics', 'taxonomy_content_configuration'],
['optional', 'Standard Ticket', 'ticket_configuration'],
['optional', 'Incident', 'incident'],
['optional', 'Event Management', 'em_event']
];
for (var i = 0; i < checks.length; i++) {
var found = new GlideRecord(checks[i][2]).isValid();
var verdict = found ? 'present' : (checks[i][0] == 'required' ? 'MISSING' : 'absent');
gs.info(verdict + ': ' + checks[i][1] + ' (' + checks[i][2] + ')');
}
var role = new GlideRecord('sys_user_role');
role.addQuery('name', 'snc_internal');
role.setLimit(1);
role.query();
gs.info((role.hasNext() ? 'present' : 'absent') + ': explicit roles (snc_internal)');
gs.info('Build: ' + gs.getProperty('glide.war', 'unknown'));
gs.info('URL prefill: ' + gs.getProperty('glide.sc.enable_url_prefill', 'not set'));
gs.info('Outbound email: ' + gs.getProperty('glide.email.smtp.active', 'not set'));
Install
- Sign in to the instance as a user with the
adminrole. - Open System Applications > All Available Applications > All, and search for Warde.
- Select Install and accept the cross-scope privileges the install asks for. They are listed under What the install adds.
- When the install finishes, open Warde > Guided Setup and work through the 14 steps.
The install needs no further manual step before Guided Setup. Everything Guided Setup cannot write for you, it opens as a prefilled record for you to check and save.
What the install adds
| Count | |
|---|---|
| Tables | 31: 26 application tables and 5 import staging tables |
| Catalog items | 8: 6 that people order, and 2 hidden ones Warde orders itself |
| Flows | 2, using core actions only |
| Portal widgets | 6 |
| UI pages | 5: Guided Setup, Collection Onboarding, the Approval Policy Wizard, the setup launcher and Contact Support |
| Workspace | 1, the Admin Workspace, with 6 dashboards |
| Outbound REST messages | 3: SailPoint ISC, SailPoint IIQ and Microsoft Entra ID |
| Scripted REST APIs | 2, including the joiner, mover and leaver endpoint |
| Transform maps | 7 |
| Scheduled jobs | 12 |
| Email notifications | 10 |
| Roles | 5 |
| System properties | 90 |
Warde calls only the engines you connect, plus a weekly count of Warde users from production instances. See What leaves your instance.
Roles
Nobody holds a Warde role when the install finishes, except that every platform administrator holds the Warde administrator role so setup can start. You name your own administrators and remove that in Guided Setup step 1. See Roles and access.
Cross-scope privileges
The install asks for 135 cross-scope privileges: 70 platform tables, 2 script includes and 43 platform API calls. Warde creates or writes records in 14 platform tables and only reads the rest:
| Area | Tables Warde writes |
|---|---|
| Requests | sc_request, sc_req_item, sc_task, sc_item_option, sc_item_option_mtom, sysapproval_approver |
| Connections | basic_auth_credentials (the secret you enter in Guided Setup), sys_import_set |
| Roles | sys_user_has_role, sys_group_has_role, only when you grant a role in Guided Setup |
| Alerts | incident and em_event, only if you choose that engine alert |
| Administration | sys_properties (Warde's own settings), sys_auto_flush (the audit retention you set) |
Some platform tables refuse writes from any scoped application: connection aliases, HTTP connections, role containment, delegates, catalog item audiences, and the Employee Center and Standard Ticket configuration tables. For those, Warde either ships the record in the package or gives you a prefilled form to save.
Application administration
Warde turns on application administration. Holding the platform admin role does not by itself let someone see or change identity data once you have removed the administrator containment in Guided Setup step 1. A platform administrator then needs an explicit grant of x_66256_warde.idam_admin, which is a recorded sys_user_has_role row with a creator and a date.
Clones
Warde ships clone preservers for its engine records and the connection records behind them. When you clone production over a sub-production instance, the target keeps its own engines, endpoints and credentials, so a cloned test instance does not start calling your production identity system.
Upgrades
Upgrades come through the ServiceNow Store like any other application. Warde supports the current release and the one before it. Records you have changed, such as a transform map, are skipped by an upgrade as usual on the platform, and Guided Setup marks a changed import map so you can see it.