✕
Releases

Top 14 Brazil Features for ServiceNow Admins

By Mahathi Veena

When I wrote about the Australia release, the dominant theme was control. Granular roles, delegated administration, and stronger visibility gave platform teams better ways to manage the platform without handing out broad administrative access. 

After spending time reviewing the Brazil release notes, a different pattern emerged. Many of the most significant enhancements are not focused on helping administrators complete tasks faster. Instead, they focus on reducing the number of routine decisions that require admin intervention in the first place.

Across approvals, AI governance, security, authentication, and service operations, ServiceNow is steadily moving governance closer to the point where decisions are made. Policies can influence approval outcomes directly. AI governance controls can move beyond monitoring and into enforcement. Identity controls are becoming more proactive. Operational safeguards are increasingly built into the process itself.

That doesn’t make administrators less important. If anything, it makes the role more strategic. Administrators still define policies, establish governance guardrails, validate outcomes, and manage exceptions. The difference is that the platform is increasingly capable of applying those rules consistently at scale.

Here are five Brazil enhancements that best illustrate that shift, and nine more that will have a big impact.

1. Intelligent Approvals: Turning Policy into Action

Most organizations already have approval policies. The challenge is ensuring those policies are applied consistently and remain aligned with evolving business guidance. Intelligent Approvals addresses exactly that problem.

Official Brazil documentation describes Intelligent Approvals as a capability that evaluates incoming approval requests against natural-language policy documents. Straightforward requests can be automatically approved or rejected, while ambiguous scenarios are escalated for human review.

Key Capabilities

Brazil introduces two new ways to create approval logic – from a Knowledge Base article or through a ServiceNow Otto conversation – along with lifecycle safeguards: the system monitors the source article and automatically deactivates the approval if that article becomes outdated or retired.

Why It Matters

Traditionally, organizations maintained policy documents in one place and workflow logic somewhere else. A policy owner updates guidance. An administrator or developer then needs to interpret that change and update the workflow implementation accordingly. 

Over time, the two can drift apart. Intelligent Approvals reduces that gap by bringing policy content closer to the approval decision itself.

Real Admin Use Case

Imagine a Change Management policy that already defines which low-risk standard changes can proceed and which require additional review. Instead of routing every request through the same approval chain, Intelligent Approvals can evaluate requests against that policy and reserve human review for scenarios that genuinely require judgment. The objective is not less governance. It is more consistent governance.

How Is This Different from Australia?

  • Australia: Improved administrative control over who sits in an approval chain, via granular roles.
  • Brazil: Lets an uploaded policy document generate the approval logic itself, auto-resolving routine requests.
READ MORE: Is ServiceNow’s “Otto” a Solution to AI’s Implementation Problems?

2. AI Control Tower: From Visibility to Enforcement

AI governance has quickly evolved from a niche concern into a board-level discussion. Most organizations are now asking: Where are we using AI? The harder question is: What happens when an AI system violates policy, introduces risk, or should no longer be used?

AI Control Tower is ServiceNow’s answer. The platform provides a central workspace for maintaining AI inventories, tracking compliance posture, monitoring quality and safety, coordinating governance activities, and measuring business value. 

Brazil extends that capability even further – AI asset usage policies can now automatically respond to detected threats and can block AI agents, domains, or models when necessary.

Key Capabilities

  • Inventory of AI systems, models, datasets, and prompts.
  • Discovery across ServiceNow and connected external platforms.
  • Compliance monitoring against NIST AI RMF and EU AI Act.
  • AI asset usage policies.
  • AI threat response.
  • AI agent containment.
  • Quality and safety evaluations.
  • AI value measurement and adoption tracking.
  • Lifecycle governance and approval workflows.

Why It Matters

A dashboard can highlight a problem. Governance requires a mechanism for acting on it. Brazil moves AI Control Tower beyond inventory and reporting by introducing policy-driven responses that can react when risks are detected. Administrators and AI stewards become policy owners rather than relying entirely on manual intervention when issues arise.

Real Admin Use Case

An AI agent is identified as operating outside an approved governance policy. Historically, that might trigger emails, meetings, ownership checks, and remediation activities. 

With AI asset usage policies, governance can include an automated response while still maintaining human oversight over the final decision.

How Is This Different from Australia?

  • Australia: Gave admins visibility into which AI agents were active and what they were doing.
  • Brazil: Adds policy-based enforcement – agents, domains, or models can be automatically blocked or kill-switched.

3. ServiceNow Vault: Security as a Coordinated Capability

Security administration often becomes fragmented. Encryption is managed by one team. Data discovery by another. Access controls, code signing, and monitoring by someone else. The challenge is rarely a lack of security tooling. The challenge is operating those controls consistently.

ServiceNow Vault brings together several platform-security capabilities into a broader security operating model that includes encryption, data protection, privacy controls, access governance, code signing, and log-export capabilities.

Key Capabilities

  • Platform encryption.
  • Data protection.
  • Sensitive-data discovery.
  • Access governance.
  • Zero Trust-related controls.
  • Code-signing requirements.
  • Security monitoring.
  • Log-export capabilities.

Why It Matters

Security controls are most effective when they operate together. A fragmented approach creates duplicated effort, unclear ownership, and inconsistent reporting. 

Vault provides administrators with a more coordinated way to think about platform security and governance.

Real Admin Use Case

A new scoped application stores employee data, financial information, and compliance-sensitive records. 

Instead of evaluating security requirements as separate projects, administrators can assess the application against a broader security and governance framework that includes protection, access, auditability, and monitoring considerations. 

The benefit is not simply fewer configuration steps. It is more consistent security governance.

How Is This Different from Australia?

  • Australia: Improved hardening visibility on a tool-by-tool basis across the security stack.
  • Brazil: Bundles encryption, discovery, access governance, code signing, and log export into a single Vault Suite install.
READ MORE: ServiceNow Brazil Release: Key Dates and Preview Information

4. Authentication and Identity: Governing More Than Human Access

Authentication used to be a user login problem. Modern platform environments are far more complex. Today’s ServiceNow environments include employees, integrations, cloud workloads, AI agents, and MCP-connected clients, each requiring authentication, authorization, and governance. Brazil introduces several enhancements that address this evolving landscape.

Policy-based, identifier-first login experiences.

Key Capabilities

  • Policy-based, identifier-first login experiences.
  • SAML signing and encryption certificate expiry alerts.
  • Basic Authentication restriction controls.
  • Federated identity for Azure and Google Cloud connections.
  • Trusted token issuers for MCP clients.
  • Endpoint-specific SSL/TLS certificate policies.

Why It Matters

Many identity incidents are entirely predictable: certificates expire, legacy authentication stays enabled, static credentials go unrotated, and non-human identities accumulate excessive permissions over time. 

Brazil provides administrators with tools that make these risks easier to identify and address before they become outages or audit findings.

READ MORE: ServiceNow Brazil Release: Key Dates and Preview Information

Real Admin Use Case

A SAML certificate approaches expiry. Instead of discovering the issue after users experience login failures, administrators receive visibility before SSO is disrupted and can remediate proactively.

How Is This Different from Australia?

  • Australia: Strengthened human admin access through granular, delegated roles.
  • Brazil: Extends that governance to machines – federated identity for cloud workloads, IdP-based MCP client auth, and role masking for AI agents.

5. Change and Incident Governance: Governance at the Point of Operation

Change and Incident Management do not always generate the same excitement as AI. They are, however, some of the most heavily used capabilities on the platform. 

Brazil continues improving the operational governance around these processes, with concrete, named enhancements across Incident Management, Change Management, and Service Operations Workspace.

Key Capabilities

  • Change Lockdown Conflict Detection: automatically flags any change request that overlaps an active lockdown period, rather than relying on a reviewer to catch the conflict manually.
  • New Compliance Scheme capability: captures risk and compliance data using Dynamic Schema, so the data model can adapt per business unit without a schema change project.
  • New risk conditions: Downtime and Long Rollback now factor directly into change risk scoring.
  • Scaled Change and Major Change enhancements.
  • Business-day-based waiting periods: for both caller response on incidents and Auto-Close Resolved Incidents, so nothing silently ages or auto-resolves over a weekend when no one was actually available to respond.
  • Automatic resolution of incidents awaiting caller information, after a configurable number of response attempts.
  • Service Operations Workspace auto-installs where entitlements allow, with Attached Knowledge now shown by default when knowledge is linked to an incident.
READ MORE: A Practical Guide to Incident Management in ServiceNow

Why It Matters

Operational processes often rely too heavily on people remembering rules. The strongest governance model is one in which key controls are embedded into the process itself and consistently applied under pressure.

Real Admin Use Case

An emergency lockdown during a major incident used to rely on people remembering not to submit competing changes. 

With Conflict Detection active, a change submitted during an active lockdown is automatically flagged instead of slipping through and colliding with the incident response – governance enforced by the system, not by memory.

How Is This Different from Australia?

  • Australia: Strengthened who could act on Change and Incident records.
  • Brazil: Automates the enforcement underneath – lockdown conflicts are flagged automatically, and response timers run on business days instead of calendar days.

Bonus Brazil Enhancements Worth an Administrator’s Attention

6. Flow Roles in Workflow Studio

Flow Roles allow admins to assign specific roles to flows and subflows, enabling user-initiated automations to run with a controlled execution context rather than relying solely on the permissions of the triggering user. 

ServiceNow restricts assignment of highly privileged roles such as admin, security_admin, and application-specific administrator roles. This is not a new restriction introduced in Brazil – it is existing platform behavior, but it pairs naturally with the new Identity role-masking capability: one enforces least-privilege at the flow level, the other at the AI agent level. Worth auditing both together.

High Security Roles assigned to operate Flows.

7. AI Admin Center

AI Admin Center provides a more centralized administrative experience for AI readiness, setup, and governance activities, sitting alongside broader AI capabilities such as Agent Studio, Otto, AI Agent Advisor, and AI Control Tower.

Beyond centralizing setup, it includes an automated instance-readiness assessment for AI adoption and surface automation-opportunity discovery, helping administrators identify where AI capabilities could apply before manually hunting for use cases.

9. MCP Server Console

As MCP becomes increasingly important in agentic architectures, admins need stronger controls for client authentication, authorization, governance, and tool exposure. 

Brazil embeds OAuth client registration directly into the server-creation wizard, adds configurable tool annotations so connected clients apply the correct permission policy automatically, and ships a preconfigured QuickStart Server for common lookups like incidents and cases – reducing MCP server setup from a multi-step configuration task to a guided flow.

10. Playbook Stage Permissions

Stage-level permissions allow governance to be applied at individual points within a workflow rather than across an entire playbook, supporting stronger separation of duties. 

They ship alongside several other playbook governance updates in Brazil: consolidated XML update sets (so a playbook deploys as one package instead of scattered across several), nested playbook output configuration, and the ability to mark individual activities as optional rather than mandatory – together, a meaningfully more mature deployment and governance model for playbooks.

11. Log Export Service

Log Export Service enables system and application logs to be exported into external monitoring and analytics platforms at scale, supporting security monitoring, investigations, compliance, and troubleshooting. Logs are forwarded near-real-time either through a MID Server or a direct Kafka connection – worth a line to security teams already standardizing on Kafka-based pipelines.

READ MORE: How to Install a ServiceNow MID Server – And Why You Need One

12. Live Connect

Live Connect provides read-only SQL access (ODBC/JDBC) to ServiceNow data for BI tools like Power BI and Tableau, without building and maintaining a separate data sync job. 

The governance question is not whether to use it, but which tables and fields it should be allowed to expose. Review security, entitlements, and reporting requirements before adoption.

13. Localization Workspace

For global organizations, localisation is as much a governance challenge as a translation challenge. Brazil continues to strengthen platform localisation capabilities and governance workflows.

14. Self-Service Environment Provisioning (Developer Sandboxes and Clone Admin Console)

Authentication options in Clone.

Two historically ticket-driven admin tasks move to self-service: Developer Sandboxes now allocate instantly from a pre-provisioned pool instead of a 15-minute-to-1-hour wait, and Clone Admin Console adopts OAuth 2.0 for clone targets – removing the need to distribute local admin credentials for every clone request. 

It is less a governance story than an operational-efficiency one, but worth a line given how much admin time these processes typically consume.

Before You Upgrade

Service Creator (com.glide.service_creator) is deprecated in Brazil, with no replacement plugin currently identified. If your org uses Service Creator, audit usage before upgrading – this is the one deprecation in this release with no clear migration path yet.

Beyond that, take time to:

  • Review product-specific release notes.
  • Check Store application compatibility.
  • Validate licensing and activation requirements.
  • Review integration and authentication dependencies.
  • Regression-test business-critical processes.
  • Confirm AI governance ownership.
  • Review remaining lifecycle and deprecation notices.
  • Test business outcomes, not only technical completion.

Here are some useful starting points:

Final Thoughts

Australia gave admins more precise control over the platform. Brazil changes where that control is applied.

  • Knowledge content becomes an active input into approvals.
  • AI governance policies move closer to enforcement.
  • Security becomes more coordinated.
  • Identity governance extends beyond human users.
  • Operational controls become more closely embedded into the processes they govern.

Admins remain central to all of this. The difference is that their role is increasingly focused on defining policies, ownership, boundaries, and exceptions rather than repeatedly applying the same controls manually.

Australia delivered the admin advantage. Brazil delivers built-in governance.

The Author

Mahathi Veena

Mahathi is a Certified Technical Architect and a two-time ServiceNow MVP (2025 and 2026), acknowledged for her technical leadership and community contributions.

Leave a Reply