You’re the PM for IT Workflow Platform at HelioBank, a US-based digital bank with 18,000 employees, operating in 12 countries, and regulated under SOX, PCI-DSS, and (for EU operations) GDPR. HelioBank runs most internal service operations on ServiceNow (ITSM + HRSD + CSM) with ~95,000 monthly active requesters and ~6,500 fulfillers/agents. The bank is on ServiceNow Washington, D.C. and has a strict policy to stay within one version of current to reduce security risk.
A board-level audit last quarter found inconsistent access provisioning and weak evidence trails. The CIO has mandated a new initiative: “Zero-Trust Access Requests”—a standardized workflow for requesting and approving access to sensitive systems (core banking, data warehouse, trading tools) with strong controls.
HelioBank’s internal users currently request access through a mix of:
Competitively, peer banks have moved to unified identity governance with tools like SailPoint/Okta Workflows, but HelioBank wants to avoid a multi-year rip-and-replace and leverage ServiceNow as the front door.
| Persona | Size | Primary Job | Pain Points |
|---|---|---|---|
| Employee Requester (Analyst) | 70k | Get access quickly to do job | “I don’t know which form to use; approvals take forever.” |
| System Owner (Director) | 1.2k | Approve access with least risk | “I need context: role, justification, SoD conflicts.” |
| IAM Engineer | 120 | Provision/deprovision access | “Requests are incomplete; too many exceptions.” |
| Internal Auditor | 60 | Verify controls & evidence | “Evidence is scattered; can’t prove who approved what and why.” |
Data from the last 90 days:
The CIO wants a new ServiceNow-based workflow that standardizes intake, enforces policy checks, and produces audit-ready evidence.
A senior stakeholder (Head of Risk) proposes a single requirement:
“When an employee requests access to any sensitive system, ServiceNow must automatically determine the correct approvers, run a real-time Segregation-of-Duties (SoD) check against HR role data and current entitlements, require step-up authentication for high-risk requests, and then provision access automatically across 40 target systems—all within 15 minutes end-to-end. The solution must be upgrade-safe and not require custom code.”
You’ve been given early discovery notes:
In this interview, walk through how you would evaluate whether this requirement is feasible within the ServiceNow platform and what you would do next.
You do not need deep ServiceNow admin knowledge; focus on product thinking, structured feasibility assessment, and pragmatic trade-offs.