Skip to main content
See All Integrations

ServiceNow CMDB

Use selected ServiceNow CMDB records in Pomerium policy through a custom external data source.

Custom customer-owned connector

Category
Context Data Sources

Overview

ServiceNow Configuration Management Database stores configuration items and their relationships. Its REST APIs can expose selected records. A customer-owned adapter can map reviewed CMDB fields to Pomerium Enterprise external data.

Selected ServiceNow CMDB data can add organization, inventory, or security context to an access decision. A small, reviewed record set is easier to understand and protect than a broad export of the source system.

Pomerium can evaluate selected ServiceNow CMDB records after a customer-owned adapter maps them to supported request or user keys. Pomerium does not call the vendor API directly and does not manage the source system.

How it works

Create a ServiceNow integration account with the required CMDB roles and access controls. Query only the needed configuration-item classes and relationships through the CMDB Instance API.

Map only the fields that policy needs. Each imported record must use a Pomerium-supported foreign key: user.id, user.email, request.ip, or request.client_certificate.fingerprint.

Publish the records through a protected JSON, CSV, tar, or ZIP source. Configure Pomerium Enterprise to poll that source. Evaluate the imported fields with a Pomerium Policy Language record matcher.

Example

An adapter reads an approved application ownership record and maps it to a verified user email. A route policy can use that imported organization fact. A CMDB relationship does not prove requester identity or live device posture.

Considerations

  • Roles, access controls, domain separation, table classes, and query filters control which records the adapter can read.
  • CMDB data quality, ownership, and update timing are customer responsibilities.
  • This is a customer-owned connector pattern, not a built-in Pomerium connector.
  • External data sources need Pomerium Enterprise and update on a polling schedule.
  • A vendor device or asset ID does not prove which device made the current Pomerium request.

Sources and official resources

  • Use selected Snipe-IT asset data in Pomerium policy through a custom external data source.

  • Use selected Workday HCM workforce records in Pomerium policy through a customer-owned external data source.

  • Use selected Rippling workforce data in Pomerium policy through a custom external data source.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo