Know exactly what is running in every instance
The complete inventory
Everything Full Scan reports across every scope: debt, exposure, configuration risk, dormant code, adoption.
Health over time
Trend view. Debt created versus debt cleared per release, per team.
Release readiness
A defensible answer to whether you can go live, based on your gates rather than on how the last testing session felt.
Key person risk
When your most experienced developer leaves, the standard stays in the rule library and the history stays in the scan record.
Multi vendor governance
One standard applied to every team and every integrator working in your instance, with findings attributed.
Ask the estate
Insights Agent. Which scopes changed most this release? Where is the debt concentrated? Which team introduced the most high severity findings?
Independent engine
Our scanning runs outside the instance and does not consume your platform capacity.
Ask the estate a question. In your own words.
Insights Agent answers questions about your estate in plain language. No query builder, no report request, no waiting three days for somebody to pull the data. Ask it from your own LLM, from any MCP capable client, or from inside Now Assist.
417 configuration changes across 9 applications, from 23 developers. Six introduced high severity issues, and all six sit in Incident and Change.
Eleven customizations touch tables the upgrade replaces. Four of them have no owner recorded. Ranked by how much of the estate depends on each one.
Two teams account for most of the high severity findings this quarter. Both are working in scopes that were cloned rather than built, so the same pattern keeps repeating.
Sample answers shown. Every real answer is grounded in the scans you already run, and every number opens into the findings behind it.
The standard is yours, and so is the record.
Full Scan tells you what is in there. Governance is what stops it coming back. The inventory is the starting point, not the product.
Rule Builder
Your conventions written in plain English, then versioned like code. Naming, architecture, the pattern the team agreed and has quietly stopped following.
Rulesets per project
A project groups related ServiceNow instances under one context. The main instance carries the ruleset and the rest inherit it, and developer access is managed once for the group rather than environment by environment. It is how governance stays coherent as the estate grows.
Quality Gates
Set the bar once and it applies in the pull request and in the pipeline. You decide whether a failed gate blocks the promotion or simply reports.
Write-offs and peer review
Exceptions carry a reason and an approver and propagate across instances, so nobody argues the same finding twice.
Every finding carries a disposition. Every write-off carries a reason and an approver. Every rule change is recorded, with what changed and who approved it.
You now have agents changing your instances.
Now Assist and the agents your team builds in AI Agent Studio generate configuration continuously, and they do not wait for a review window. Anything that speaks MCP can call Quality Clouds mid-loop, so the agent is handed your rules before it writes rather than a rejection afterwards.
agent proposes → Quality Clouds returns the applicable rules and the violations → agent corrects → change lands
AI Virtual Agent Topics are scanned configuration in their own right, so the agents your team ships are governed the same way the code is. The question is no longer who wrote it, but whether the standard was enforced when it was written.
Related articles
Stay ahead of the curve in ServiceNow

AI Code Governance
ServiceNow
Event & Insights
ServiceNow Just Made App Governance Free. Here Is Why That Is Good News for Code Governance.

Albert Franquesa
5 min read
Learn what AEMC actually governs, what it does not, and why that gap makes AI Code Governance more urgent than ever

AI Code Governance
Agentic AI
Salesforce
AI Finds Zero-Days Autonomously. Who Is Accountable When AI Ships One into Production?

Albert Franquesa
5 min read
ServiceNow Build Agent will quadruple usage in twelve months. The CISO’s question has shifted from detection to accountability

ServiceNow
AI Code Governance
DevOps & CI/CO
How to Automate Code Reviews in ServiceNow: A Guide for Platform Teams — Quality Clouds

Albert Franquesa
10 min read
ServiceNow opens to any external AI tool on April 15, learn how Quality Clouds governs AI-generated code