Enhancement: Custom User Levels Usability Improvements

What’s New

We are introducing exciting quality of life enhancements to Custom User Levels. These include the following:

  • The ability to remove Identities in bulk
    Administrators can now unassign User Levels across multiple Identities in one process
  • Searching by Name and Description
    • Simplified search for User Levels to include Name and Description values
  • Improvements to Hierarchy UI
    • Improved UI experience when creating new Custom User Levels when selecting permission sets
  • Descriptions to Out-of-the-Box User Levels

All Feature Permissions are located within the Permissions Heading:

Search by Name and Description:


Who’s Affected

  • Applies to: Business and Business Plus

Important Dates

  • Sandbox – Jan 19, 2026
  • Prod – Jan 27, 2026

Resources

2 Likes

great improvement. We are already using to built a custom read-only role

Currently this user level can be only set manually to certain people. Is it also possible to assign this user level through an IdentityNow entitlement as for all the other built in user level?

Why is it not possible for a read only admin user level to exist?

This seems like missing functionality. There are plenty of use cases where someone needs to be able to look at admin level items without having the ability to change them, and without the requirement to query the API every time.

1 Like

We’ve started using 1 custom User Level. The feature is very welcome!

However, in a certification only the numerical ID is presented, not the DisplayName nor description, which is obviously very reviewer-unfriendly. Is an improvement planned in that regard?

I also second the need for a read-only admin user level, but that is an old and strongly-upvoted Idea, so you don’t need me for that.

Hi @christophe_choumert ,

The downstream for user level access is a custom object which would refer to UID instead of names of groups such as AD groups/Governance groups where the entitlement name will replicate the name of the downstream groups. Here you may need to manually update the name of the entitlement which falls under Custom User Level access.

Thanks, that does provide a workaround for my issue. I still think entitlements shouldn’t be created with an alphanumerical id in that case, but the workaround is good enough.

1 Like

Is there any way to add Search as a permission to the custom user level?

Do the Custom User Levels, like Access Revoker, apply to users using the ServiceNow Service Catalog Integration?

Also, anybody try adding Access Revoker to all users, to allow staff to be able to remove access for themselves or other staff as needed?