WardeDocs Administrators Connectors People using Warde warde.app

Administrator guide

Install Warde

What your instance needs before you install Warde, how to install it, and what the install adds.

Warde is one scoped application, x_66256_warde. It needs no IntegrationHub, Now Assist, ITOM, Performance Analytics or HR Service Delivery subscription. Install it in a sub-production instance first, set it up there, then install it in production.

Before you install

Platform release

Warde supports the current ServiceNow family and the one before it: Australia and Zurich.

Plugins that must be active

These are active on almost every instance, but a customer can switch any of them off. If one is missing, the records for it fail to install and the feature built on them does not exist.

FeaturePlugin IDs
Service Catalogcom.glideapp.servicecatalog, com.glideapp.servicecatalog.platform, com.glide.ui_policy_catalog
Flow Designercom.glide.hub.flow_engine, com.glide.hub.designer_backend.model, com.glide.hub.flow_trigger
Service Portalcom.glide.service-portal
Next Experience workspacescom.glide.uxbuilder, com.glide.ux.list, com.glide.ux.config
Platform Analytics dashboardscom.snc.par.dashboards
Connections and Credentialscom.snc.core.automation.connection_credential, com.snc.core.automation
Outbound RESTcom.glide.web_service_consumer
Scripted REST APIscom.glide.scripted_rest_services
Import Setscom.glide.system_import_set

Optional

Warde installs and runs without any of these.

FeatureWhat it addsWithout it
Employee CenterRequest items in topics and quick links, and review tasks on My TasksItems are published through catalog categories and portal menus. Reviewers open reviews from the email or My Access.
Explicit roles plugin (snc_internal)One role that means everyone who can log in, for the requester role to sit under. Entitlement and bundle owners can see their pre-approval work.Grant the requester role to groups, or use the daily job Guided Setup offers. Entitlement and bundle owners cannot see their pre-approval work.
A MID ServerReaches an engine the instance cannot reach directly, usually IdentityIQ on premisesOnly engines reachable from the instance
IncidentAn engine that goes down can raise an incidentEngine alerts stay on "Nothing is raised"
Event ManagementAn engine that goes down can send an event, and a clear when it recoversNot offered
Now Assist in Virtual Agent, with AI SearchThe conversational item Request a single access itemThe item stays switched off

Instance settings

SettingWhy it matters
glide.email.smtp.activeWarde's emails, and the platform's request and approval emails, go out only when outbound email is on
glide.sc.enable_url_prefillLets the links on My Access fill in the person when a manager requests for someone on their team. Without it, the manager changes the person on the form.

Check an instance before you install

Paste this into System Definition > Scripts - Background in the global scope. It only reads. Any line that starts MISSING names a plugin to activate first.

var checks = [
    ['required', 'Service Catalog', 'sc_cat_item'],
    ['required', 'Catalog UI policies', 'catalog_ui_policy'],
    ['required', 'Flow Designer', 'sys_hub_flow'],
    ['required', 'Service Portal', 'sp_widget'],
    ['required', 'Workspace framework', 'sys_ux_app_config'],
    ['required', 'Workspace lists', 'sys_ux_list'],
    ['required', 'Platform Analytics dashboards', 'par_dashboard'],
    ['required', 'Connections and Credentials', 'sys_alias'],
    ['required', 'Outbound REST', 'sys_rest_message'],
    ['required', 'Scripted REST APIs', 'sys_ws_definition'],
    ['required', 'Import Sets', 'sys_transform_map'],
    ['optional', 'Employee Center quick links', 'sn_ex_sp_quick_link'],
    ['optional', 'Employee Center to-dos', 'sn_hr_sp_todos_config'],
    ['optional', 'Topics', 'taxonomy_content_configuration'],
    ['optional', 'Standard Ticket', 'ticket_configuration'],
    ['optional', 'Incident', 'incident'],
    ['optional', 'Event Management', 'em_event']
];
for (var i = 0; i < checks.length; i++) {
    var found = new GlideRecord(checks[i][2]).isValid();
    var verdict = found ? 'present' : (checks[i][0] == 'required' ? 'MISSING' : 'absent');
    gs.info(verdict + ': ' + checks[i][1] + ' (' + checks[i][2] + ')');
}
var role = new GlideRecord('sys_user_role');
role.addQuery('name', 'snc_internal');
role.setLimit(1);
role.query();
gs.info((role.hasNext() ? 'present' : 'absent') + ': explicit roles (snc_internal)');
gs.info('Build: ' + gs.getProperty('glide.war', 'unknown'));
gs.info('URL prefill: ' + gs.getProperty('glide.sc.enable_url_prefill', 'not set'));
gs.info('Outbound email: ' + gs.getProperty('glide.email.smtp.active', 'not set'));

Install

  1. Sign in to the instance as a user with the admin role.
  2. Open System Applications > All Available Applications > All, and search for Warde.
  3. Select Install and accept the cross-scope privileges the install asks for. They are listed under What the install adds.
  4. When the install finishes, open Warde > Guided Setup and work through the 14 steps.

The install needs no further manual step before Guided Setup. Everything Guided Setup cannot write for you, it opens as a prefilled record for you to check and save.

What the install adds

Count
Tables31: 26 application tables and 5 import staging tables
Catalog items8: 6 that people order, and 2 hidden ones Warde orders itself
Flows2, using core actions only
Portal widgets6
UI pages5: Guided Setup, Collection Onboarding, the Approval Policy Wizard, the setup launcher and Contact Support
Workspace1, the Admin Workspace, with 6 dashboards
Outbound REST messages3: SailPoint ISC, SailPoint IIQ and Microsoft Entra ID
Scripted REST APIs2, including the joiner, mover and leaver endpoint
Transform maps7
Scheduled jobs12
Email notifications10
Roles5
System properties90

Warde calls only the engines you connect, plus a weekly count of Warde users from production instances. See What leaves your instance.

Roles

Nobody holds a Warde role when the install finishes, except that every platform administrator holds the Warde administrator role so setup can start. You name your own administrators and remove that in Guided Setup step 1. See Roles and access.

Cross-scope privileges

The install asks for 135 cross-scope privileges: 70 platform tables, 2 script includes and 43 platform API calls. Warde creates or writes records in 14 platform tables and only reads the rest:

AreaTables Warde writes
Requestssc_request, sc_req_item, sc_task, sc_item_option, sc_item_option_mtom, sysapproval_approver
Connectionsbasic_auth_credentials (the secret you enter in Guided Setup), sys_import_set
Rolessys_user_has_role, sys_group_has_role, only when you grant a role in Guided Setup
Alertsincident and em_event, only if you choose that engine alert
Administrationsys_properties (Warde's own settings), sys_auto_flush (the audit retention you set)

Some platform tables refuse writes from any scoped application: connection aliases, HTTP connections, role containment, delegates, catalog item audiences, and the Employee Center and Standard Ticket configuration tables. For those, Warde either ships the record in the package or gives you a prefilled form to save.

Application administration

Warde turns on application administration. Holding the platform admin role does not by itself let someone see or change identity data once you have removed the administrator containment in Guided Setup step 1. A platform administrator then needs an explicit grant of x_66256_warde.idam_admin, which is a recorded sys_user_has_role row with a creator and a date.

Clones

Warde ships clone preservers for its engine records and the connection records behind them. When you clone production over a sub-production instance, the target keeps its own engines, endpoints and credentials, so a cloned test instance does not start calling your production identity system.

Upgrades

Upgrades come through the ServiceNow Store like any other application. Warde supports the current release and the one before it. Records you have changed, such as a transform map, are skipped by an upgrade as usual on the platform, and Guided Setup marks a changed import map so you can see it.

Warde is a ServiceNow scoped application, x_66256_warde. These guides describe the current release. Questions go to hello@warde.app.

ServiceNow is a trademark of ServiceNow, Inc. SailPoint, IdentityIQ and Identity Security Cloud are trademarks of SailPoint Technologies, Inc. Microsoft and Microsoft Entra are trademarks of the Microsoft group of companies.