For AI agents: a documentation index is available at https://docs.coverbase.com/llms.txt. This page is also available in markdown by appending .md to the URL.
The ServiceNow IRM connector is part of the Integration Hub. It writes Coverbase findings to GRC issues (sn_grc_issue) and vendor risk to risks (sn_risk_risk) through the Table API, and reads each record’s state back. It is separate from the ServiceNow VRM and ITSM integration, which creates records from workflows.
What it pushes
- Findings as issues: every open finding that has a vendor, plus every finding already pushed, so a closure reaches ServiceNow IRM too.
- Vendor risk: every vendor with a residual or inherent risk level, plus every vendor already pushed.
Every value is written as text. A value with a blank target is not written.
Status read back
After each push, Coverbase reads thestate of every record it holds, by display value, in batches of 100, and shows it on the record link. It does not change the finding in Coverbase.
Authentication
ServiceNow IRM uses OAuth 2.0 client credentials at<instance>/oauth_token.do.
- In ServiceNow, create an OAuth API endpoint for external clients with the client credentials grant, and note the client ID and secret.
- Give the integration user access to create, update and read the issue and risk tables.
- If you use tables other than
sn_grc_issueandsn_risk_risk, note their names.
Set up in Coverbase
- Open Configuration → External Integrations and click ServiceNow IRM, or open it from the GRC and ERM category of the Integration Hub.
- On Authentication, enter the Instance URL, Client ID and Client Secret. Under ServiceNow Tables, change the Issue Table and Risk Table if you use your own.
- Turn on Push findings and vendor risk to ServiceNow IRM, set the Sync Interval (Minutes), click Save, then Test connection.
- On Field Mappings, check the column for each value. The defaults write the issue title to
short_description, its description todescription, its due date todue_dateand its reference tocorrelation_id, and the risk title toname. Save mappings. - Click Sync now and read the Sync Log.
When a response is not what Coverbase expects
The Table API silently drops a column the table does not have, so every write asks for the mapped columns back, and a write that dropped one fails that record with the reason in the sync log.Related
Integration Hub guide
Field mappings and the sync log.
Integration platforms
Building your own sync on the API instead.
Findings and remediation
The findings pushed as issues.
Integration credentials and signing
How the credentials are stored.