Skip to main content
Back to the connector catalogue

Connector

ServiceNow

Outbound ticketing integration: Vigicap files tickets into it.

Your actions go into ServiceNow as records, in the table you choose (incident by default) and under the client's company. The status is then read back: resolved or closed in ServiceNow, Vigicap proposes closing the action and never closes it by itself. No ReCyF level is proposed. Pushing a ticket does not measure a client's posture.

01

What to create in the tool

The access is created in ServiceNow, not in Vigicap. Vigicap never asks for an administrator's password: it expects an API credential that you create, that you can see, and that you can revoke without us.

Where to generate it

The instance URL is https://your-instance.service-now.com. Use a dedicated account with the itil role, restricted by ACL to the target table. The company sys_id comes from core_company.

Minimum role

Compte applicatif ServiceNow en authentification de base. ÉCRITURE : le rôle doit permettre la création dans la table visée (par défaut `incident`) — `itil` suffit et `admin` n'est pas nécessaire. LECTURE : le même compte relit l'enregistrement par son sys_id. ServiceNow permet de restreindre le compte par ACL et par table, ce qui est le bon endroit pour le faire : le mot de passe côté Vigicap ne porte aucune portée.

Taken from the vendor's own role model, and checked before publication.

02

What to enter in Vigicap

The exact fields of the connection form, in the order they appear. Values marked “secret” never travel back to the browser: they are encrypted at rest and deleted on disconnection.

The form starts with the instance address, entered separately from the fields below. The public catalogue does not yet publish whether this connector needs one, or what it looks like — so this list is exact about everything else, and silent about that first field.

  • Username
  • Passwordsecret

03

Per-client routing

These fields are filled in client by client: they say which account in the ticketing tool the ticket must land under. A wrong value does not fail the push — it succeeds against someone else, which is why Vigicap checks them the moment you type them.

  • Company (sys_id)

    The core_company record tickets are filed against for this client.

    32 hex characters

  • Tableoptional

    Defaults to incident. Any table extending task works (e.g. sn_customerservice_case).

    incident

04

What it does, and what it does not do

ReCyF objectives it pre-fills

This connector feeds no ReCyF objective, and that is not a gap: it does not measure a client's posture.

What goes out to the tool

This connector WRITES: it creates a ticket from an action in the plan.

What comes back

The state of an already-created ticket comes back: its status, its closing date, its last activity. A closed ticket becomes a PROPOSAL a consultant confirms — never an action closed of its own accord. An agency that closes its own ticket must not be able to mark its own homework in the document an auditor reads.

What is read, what is kept, for how long and with which rights: the same register, connector by connector, in the data inventory.

Verification

This connector was written from the vendor's documented API and has not yet been run against a real instance. It is marked “Beta” everywhere it appears.

The trademarks and logos mentioned belong to their respective owners and identify the tools Vigicap is compatible with — see the legal notice.