Cortex connects to many third-party vendors whose system interfaces frequently change. As a result, integration behavior or configuration steps may shift without notice. If you encounter unexpected issues, check with your system administrator or refer to the vendor’s documentation for the most current information. Additionally, integration sync times vary and are subject to scheduling overrides and timing variance.
- Import teams from ServiceNow and track ownership of entities
- Automatically import domains and domain relationships from ServiceNow
- Create Workflows to trigger ServiceNow actions, create tickets, or update records.
- Use the ServiceNow Incidents plugin to view ServiceNow incidents directly on entity details pages.
- Create Scorecards that track progress and drive alignment on projects involving your ServiceNow teams
Some Cortex users link business applications to ServiceNow projects, creating a clear map of ownership and project alignment. This enables visibility into which projects tie to which business apps, helping track migrations, risk programs, and compliance projects.
How to configure ServiceNow with Cortex
Prerequisites
Your ServiceNow user must have thesn_cmdb_user permission enabled.
You must have the Configure Integrations permission in Cortex.
Step 1: Configure the integration in Cortex
- In Cortex, navigate to the ServiceNow settings page:
- Click Integrations from the main nav. Search for and select ServiceNow.
- Click Add configuration.
- Configure the ServiceNow integration form:
- Instance name: Enter your instance identifier.
- This can be found in your instance URL, e.g.,
<instance-identifier>.service-now.com.
- This can be found in your instance URL, e.g.,
- Username and Password: Enter your ServiceNow username and password.
- Instance name: Enter your instance identifier.
- Click Save.
Step 2: Configure table mappings
You can add more than one table mapping for the same domain relationship. This is useful if your ServiceNow domain hierarchy has more levels than a single table can represent, for example a division that rolls up through several layers of committees before reaching a business unit. Add a separate table mapping for each level, and Cortex builds the full hierarchy from the combined mappings.
- On the ServiceNow integrations settings page, click Add table mapping on the right.
-
Configure the “Add table mapping” form:
- Choose a mapping type: Select whether your data will map to Domains, Services or Teams.
- Table name: Enter a descriptive name.
- Table filter query: Optionally, enter a table filter query.
- ID column name: Enter the column name that contains the ID of the record.
- Name column name: Enter the column name that contains the name of the record.
- Description column name: Enter the column name that contains the description of the record.
- Note: To import teams, you must configure table mappings for the team, its team members, and their relationships.
- Click Preview.
- From the preview screen, you will be able to view summary counts, warnings, entity tree, and raw table data that was found based on the the configuration details. Once you’ve confirmed the data looks correct, you can select save.
How to connect Cortex entities to ServiceNow
To import entities from ServiceNow, follow the steps described below.Import entities from ServiceNow
See the documentation on:- Importing teams
- Importing services
- Importing domains
- You can enable automated import of domains.
- Domain relationships cannot be manually imported; these are automatically imported via the automatic import setting described below.
Enable automated import of domains for ServiceNow
You must have theConfigure Settings permission.
Enabling automated domain import ensures that your domain structure in Cortex stays up-to-date with your ServiceNow configuration.
- In Cortex, go to the ServiceNow settings page.
- Toggle the setting on to enable the automated import of any domains and domain relationships from ServiceNow.
The automatic sync runs daily at 2 p.m. UTC.
Manually sync domains
You must have theEnable Relationship graph permission.
To force a sync of newly-discovered domains:
- Go to Tools > Relationship graphs and select Domains.
-
Click the 3 dots icon in the upper right, then click Sync.

Editing the entity descriptor
When an entity is connected to ServiceNow, the entity YAML will look like the following:Configuring your ServiceNow teams as owners
To import teams, configure the table mappings to pull teams, team members, and their relationships from ServiceNow. After doing so, follow the steps to import them. When an entity is owned by a ServiceNow team, the YAML will look like the following:name should be the name of the team as defined in ServiceNow (case-sensitive).
Learn more about ownership in Defining ownership.
Using the ServiceNow integration
Scorecards and CQL
With the ServiceNow integration, you can create Scorecard rules and write CQL queries based on ownership and team details. See more examples in the CQL Explorer in Cortex.All ownership details
All ownership details
A special built-in type that supports a null check or a count check, used to enforce ownership of entities.Definition:
ownership: Ownership | NullExampleAn initial level in a security Scorecard might include a rule to ensure an entity has at least one team as an owner:All owner details
All owner details
List of owners, including team members and individual users, for each entityDefinition:
ownership.allOwners()ExampleThe Scorecard might include a rule to ensure that entity owners all have an email set:Team details
Team details
List of teams for each entityDefinition:
ownership.teams(): List<Team>ExampleThe Scorecard might include a rule to ensure that an entity owners all have a description and are not archived:View integration logs
This feature is available in Cortex cloud.

Workflows
After integrating, you can set up Workflows to trigger actions in ServiceNow. See an example of this in Guides > Create ServiceNow incident.ServiceNow Incidents plugin
You can install a plugin that makes ServiceNow incidents more visible on your entity details pages:
Edit Plugins permission.
Background sync
Cortex conducts a background sync of ServiceNow domains, domain relationships, and services every day at 2 p.m. UTC.Still need help?↗
The following options are available to get assistance from the Cortex Customer Engineering team:- Email: help@cortex.io, or open a support ticket in the in app Resource Center
- Slack: Users with a connected Slack channel will have a workflow added to their account. From here, you can either @CortexTechnicalSupport or add a
:ticket:reaction to a question in Slack, and the team will respond directly.