ServiceNow MCP Server

384 tools. 154 can modify or destroy data without limits.

4 destructive tools with no built-in limits. Policy required.

Last updated:

154 can modify or destroy data
230 read-only
384 tools total

154 ServiceNow MCP Server tools can modify or destroy data, with no limits today. PolicyLayer puts allow, deny, and rate-limit rules on every call. Live in minutes.

SECURE SERVICENOW MCP SERVER →

Free to start. No card required.

Read (230) Write / Execute (150) Destructive / Financial (4)

Destructive tools (delete_attachment, delete_system_property, delete_uib_page) permanently delete resources. There is no undo. An agent calling these in a retry loop causes irreversible damage.

Write operations (add_comment, add_user_to_group, add_work_note) modify state. Without rate limits, an agent can make hundreds of changes in seconds — faster than any human can review or revert.

Execute tools (deploy-updateset, execute_background_script, ml_model_training_history) trigger processes with side effects. Builds, notifications, workflows — all fired without throttling.

Deny destructive operations
{
  "delete_attachment": {
    "deny_if": [
      {
        "conditions": [],
        "on_deny": "Blocked by default. Requires approval."
      }
    ]
  }
}

Destructive tools should never be available to autonomous agents without human approval.

Rate limit write operations
{
  "add_comment": {
    "limits": [
      {
        "counter": "add_comment_per_hour",
        "window": "hour",
        "max": 30,
        "scope": "grant"
      }
    ]
  }
}

Prevents bulk unintended modifications from agents caught in loops.

Cap read operations
{
  "ai_search": {
    "limits": [
      {
        "counter": "ai_search_per_minute",
        "window": "minute",
        "max": 60,
        "scope": "grant"
      }
    ]
  }
}

Controls API costs and prevents retry loops from exhausting upstream rate limits.

Get this policy live on your own ServiceNow MCP Server server in minutes. Tune the limits to your setup; PolicyLayer enforces it on every call.

ENFORCE ON MY SERVICENOW MCP SERVER →
WRITE 134 tools
Write add_comment Write add_user_to_group Write add_work_note Write approve_request Write bulk_set_properties Write close_change_request Write close_csm_case Write close_hr_case Write close_incident Write commit_changeset Write complete_task Write complete_update_set Write configure_offline_sync Write configure_workspace_list Write create_acl Write create_approval_rule Write create_asset Write create_business_rule Write create_catalog_item Write create_catalog_ui_policy Write create_catalog_variable Write create_change_request Write create_ci_relationship Write create_client_script Write create_csm_case Write create_dashboard Write create_devops_change Write create_epic Write create_flow Write create_flow_action Write create_grc_risk Write create_group Write create_hr_case Write create_hr_task Write create_import_set_row Write create_incident Write create_knowledge_article Write create_kpi Write create_mobile_app_config Write create_mobile_applet Write create_mobile_layout Write create_notification Write create_offboarding_case Write create_onboarding_case Write create_portal Write create_portal_page Write create_portal_widget Write create_problem Write create_report Write create_rest_message Write create_scheduled_job Write create_scheduled_report Write create_scoped_app Write create_script_include Write create_scrum_task Write create_security_incident Write create_solution_package Write create_story Write create_subflow Write create_ui_action Write create_ui_policy Write create_uib_component Write create_uib_data_broker Write create_uib_page Write create_update_set Write create_user Write create_ux_app_route Write create_ux_experience Write create_va_topic Write create_workspace Write create-incident Write ensure_active_update_set Write export_properties Write export_report_data Write export_update_set Write generate_summary Write generate_work_notes Write import_cmdb_data Write import_properties Write natural_language_update Write preview_update_set Write publish_changeset Write publish_flow Write publish_knowledge_article Write register_event Write reject_request Write resolve_incident Write resolve_problem Write retire_asset Write retire_knowledge_article Write rollback_deployment Write schedule_cab_meeting Write schedule_notification Write send_emergency_broadcast Write send_push_notification Write set_system_property Write submit_change_for_approval Write switch_instance Write switch_update_set Write switch-instance Write track_deployment Write update_acl Write update_asset Write update_business_rule Write update_catalog_item Write update_change_request Write update_client_script Write update_csm_case Write update_dashboard Write update_epic Write update_group Write update_hr_case Write update_hr_profile Write update_incident Write update_knowledge_article Write update_notification Write update_portal_widget Write update_problem Write update_report Write update_scheduled_job Write update_scoped_app Write update_script_include Write update_scrum_task Write update_security_incident Write update_story Write update_task Write update_ui_action Write update_uib_component Write update_uib_page Write update_user Write update_va_topic Write update_vulnerability Write updateset_name Write upload_attachment
READ 230 tools
Read ai_search Read analyze_data_quality Read bulk_get_properties Read categorize_incident Read category Read check_table_completeness Read ci_name Read ci-health Read clone_artifact Read cmdb_health_dashboard Read cmdb_impact_analysis Read compare_record_counts Read description Read find_artifact Read fire_event Read get_acl Read get_asset Read get_atf_failure_insight Read get_atf_suite Read get_atf_suite_result Read get_atf_test Read get_attachment_metadata Read get_business_rule Read get_catalog_item Read get_change_request Read get_changeset Read get_client_script Read get_cmdb_ci Read get_compliance_assessment Read get_csm_account Read get_csm_case Read get_csm_case_sla Read get_csm_contact Read get_current_instance Read get_current_update_set Read get_deployment Read get_devops_insights Read get_devops_pipeline Read get_email_log Read get_event_registry_entry Read get_flow Read get_flow_error_log Read get_flow_execution Read get_grc_risk Read get_group Read get_hr_case Read get_hr_case_activity Read get_hr_lifecycle_events Read get_hr_profile Read get_hr_service Read get_import_set Read get_incident Read get_knowledge_article Read get_license_compliance Read get_license_optimization Read get_mobile_analytics Read get_mobile_app_config Read get_ms_copilot_topics Read get_my_approvals Read get_notification Read get_pa_dashboard Read get_pa_indicator Read get_pa_job Read get_pa_scorecard Read get_pa_time_series Read get_performance_analytics Read get_pi_models Read get_portal Read get_portal_page Read get_portal_theme Read get_portal_widget Read get_problem Read get_process_automation Read get_property_history Read get_record Read get_report Read get_rest_message Read get_scheduled_job Read get_scoped_app Read get_script_include Read get_security_dashboard Read get_security_incident Read get_sla_details Read get_subflow Read get_sys_log Read get_system_property Read get_table_record_count Read get_table_schema Read get_task Read get_threat_intelligence Read get_transform_map Read get_ui_action Read get_ui_policy Read get_uib_page Read get_user Read get_ux_app Read get_va_conversation Read get_va_topic Read get_virtual_agent_topics Read get_vulnerability Read get_workspace Read instance Read knowledge-search Read list_acls Read list_action_instances Read list_active_events Read list_active_slas Read list_approvals Read list_asset_contracts Read list_assets Read list_atf_suites Read list_atf_test_results Read list_atf_tests Read list_attachments Read list_audit_results Read list_business_rules Read list_catalog_items Read list_change_requests Read list_changesets Read list_client_scripts Read list_compliance_policies Read list_credential_aliases Read list_csm_accounts Read list_csm_cases Read list_csm_contacts Read list_csm_products Read list_data_sources Read list_deployment_history Read list_deployments Read list_devops_pipelines Read list_discovery_schedules Read list_email_logs Read list_email_templates Read list_epics Read list_event_log Read list_event_registry Read list_flow_executions Read list_flows Read list_grc_controls Read list_grc_risks Read list_groups Read list_homepages Read list_hr_cases Read list_hr_document_templates Read list_hr_services Read list_hr_tasks Read list_import_sets Read list_instances Read list_job_run_history Read list_knowledge_bases Read list_mid_servers Read list_mobile_app_configs Read list_mobile_applets Read list_mobile_layouts Read list_my_tasks Read list_notification_subscriptions Read list_notifications Read list_oauth_applications Read list_pa_breakdowns Read list_pa_dashboards Read list_pa_indicators Read list_pa_jobs Read list_portal_pages Read list_portal_themes Read list_portal_widgets Read list_portals Read list_process_automations Read list_property_categories Read list_relationships Read list_reports Read list_rest_message_functions Read list_rest_messages Read list_scheduled_jobs Read list_scoped_apps Read list_script_includes Read list_scrum_tasks Read list_security_incidents Read list_security_playbooks Read list_software_licenses Read list_stories Read list_subflows Read list_system_properties Read list_transform_field_maps Read list_transform_maps Read list_ui_actions Read list_ui_policies Read list_uib_components Read list_uib_data_brokers Read list_uib_pages Read list_update_sets Read list_users Read list_ux_apps Read list_ux_pages Read list_va_categories Read list_va_conversations Read list_va_topics_full Read list_vulnerabilities Read list_widget_instances Read list_workspaces Read ml_detect_anomalies Read ml_evaluate_model Read ml_forecast_incidents Read ml_predict_change_risk Read ml_process_optimization Read ml_virtual_agent_nlu Read morning-standup Read my-changes Read my-tickets Read natural_language_search Read nlq_query Read order_catalog_item Read p1-alerts Read query_records Read scan_vulnerabilities Read search_catalog Read search_cmdb_ci Read search_knowledge Read search_system_properties Read service_mapping_summary Read sla-breaches Read suggest_resolution Read suite_name Read test_flow Read topic Read track_asset_lifecycle Read trend_query Read urgency Read validate_artifact Read validate_deployment Read validate_property
Can an AI agent delete data through the ServiceNow MCP Server MCP server? +

Yes. The ServiceNow MCP Server server exposes 4 destructive tools including delete_attachment, delete_system_property, delete_uib_page. These permanently remove resources with no undo. PolicyLayer blocks destructive tools by default so they never reach the upstream server.

How do I prevent bulk modifications through ServiceNow MCP Server? +

The ServiceNow MCP Server server has 134 write tools including add_comment, add_user_to_group, add_work_note. Set a rate limit in your policy -- for example, 10 calls per hour prevents an agent from making more than 10 modifications per hour. PolicyLayer enforces this at the gateway, before calls reach ServiceNow MCP Server.

How many tools does the ServiceNow MCP Server MCP server expose? +

384 tools across 4 categories: Destructive, Execute, Read, Write. 230 are read-only. 154 can modify, create, or delete data.

How do I enforce a policy on ServiceNow MCP Server? +

Register the ServiceNow MCP Server MCP server in PolicyLayer, apply the suggested rules above (adjust the limits to your use case), and point your AI client at the PolicyLayer proxy URL instead of the server directly. Your agents keep the same tools; PolicyLayer evaluates every call against policy before it executes. Nothing to install, live in minutes.

Other MCP servers with similar tools.

Starter policies for each. Same risk classification, live on your fleet in minutes.

Enforce policy on every ServiceNow MCP Server tool call.

Deterministic rules across all 384 ServiceNow MCP Server tools. Per-identity grants. Full audit log. Live in minutes. Nothing to install.

Free to start. No card required.

4,600+ MCP servers and 31,000+ tools scanned and risk-classified.

// GET IN TOUCH

Have a question or want to learn more? Send us a message.

Message sent.

We'll get back to you soon.