
ServiceNow CMDB
Use selected ServiceNow CMDB records in Pomerium policy through a custom external data source.
Overview
ServiceNow Configuration Management Database stores configuration items and their relationships. Its REST APIs can expose selected records. A customer-owned adapter can map reviewed CMDB fields to Pomerium Enterprise external data.
Selected ServiceNow CMDB data can add organization, inventory, or security context to an access decision. A small, reviewed record set is easier to understand and protect than a broad export of the source system.
Pomerium can evaluate selected ServiceNow CMDB records after a customer-owned adapter maps them to supported request or user keys. Pomerium does not call the vendor API directly and does not manage the source system.
How it works
Create a ServiceNow integration account with the required CMDB roles and access controls. Query only the needed configuration-item classes and relationships through the CMDB Instance API.
Map only the fields that policy needs. Each imported record must use a Pomerium-supported foreign key: user.id, user.email, request.ip, or request.client_certificate.fingerprint.
Publish the records through a protected JSON, CSV, tar, or ZIP source. Configure Pomerium Enterprise to poll that source. Evaluate the imported fields with a Pomerium Policy Language record matcher.
Example
An adapter reads an approved application ownership record and maps it to a verified user email. A route policy can use that imported organization fact. A CMDB relationship does not prove requester identity or live device posture.
Considerations
- Roles, access controls, domain separation, table classes, and query filters control which records the adapter can read.
- CMDB data quality, ownership, and update timing are customer responsibilities.
- This is a customer-owned connector pattern, not a built-in Pomerium connector.
- External data sources need Pomerium Enterprise and update on a polling schedule.
- A vendor device or asset ID does not prove which device made the current Pomerium request.
