{
  "id": "servicenow",
  "name": "ServiceNow AI Platform (Now Assist + AI Control Tower + Workflow Data Fabric)",
  "subtitle": "Mapped to the 4+1 Layer AI Infrastructure Model",
  "version": "v1.0 - 4+1 v2: Authority Split",
  "date": "September 5, 2026",
  "source": "ServiceNow Zurich (GA September 2025) and Australia (early availability March 12, 2026; GA May 5, 2026; Patch 4 July 9, Patch 5 August 2026) release notes, change summary, and product docs (AI Agent Studio tools and execution modes; ACLs, role masking, and user identities; AI Search semantic index configuration and content security; Workflow Data Fabric Hub and Zero Copy Connectors (Yokohama); Data Catalog release notes; RaptorDB Professional V2 Live Archive; Now Assist data usage policy; LLM providers); Knowledge 2026 press releases (May 5 to 7, 2026): AI Control Tower expansion, Autonomous Workforce, Autonomous Security and Risk, real-time data foundation, NVIDIA Enterprise AI Factory governance integration; AI Control Tower June 2026 release notes and Australia release notes (AI Gateway application deprecated, MCP governance consolidated); Action Fabric MCP Server Console, MCP Client, and A2A documentation (June 2026); the AI Agents build, operations, and governance guide (Australia); Now Assist external-LLM and BYOK documentation; the July 2026 model update; Private Stack launch post; the L1 Service Desk AI Specialist launch article; FY2025 Form 10-K; NVIDIA's Apriel Nemotron post; Apriel 2.0 release (October 28, 2025); acquisition closes: Moveworks (December 15, 2025), Veza (March 2, 2026), Armis (2026), data.world (2025); Q2 2026 results (July 22, 2026). Peer-reviewed cell by cell through the labs claims ledger (servicenow-<layer>-chatgpt, ChatGPT gpt-5.5, 26 claims) and as a whole row by Antigravity (servicenow-row-agy); totals and the escalated items are in labs/reviews/servicenow-judgment.md.",
  "status": "complete",
  "summary": {
    "title": "Summary Finding",
    "paragraphs": [
      "ServiceNow is a workflow platform that built an agent runtime and then a governance plane for everyone else's agents, and the row reads that way: strong where agents are built and run (Layer 2B) and where the buyer's work gets done (Layer 3), moderate through the data foundation, retrieval, pipelines, and the reasoning plane, and a gap at the two infrastructure layers by design. Authority is the software-as-a-service (SaaS) shape throughout: nothing at Layer 0 or 2A is the customer's, and nearly everything scored above is ServiceNow intellectual property (IP) and Ceded, with two Delegated seams, zero-copy federation and the customer's own model keys, and one Retained reading at 1C, where the platform executes integrations the enterprise wrote without judgment of its own.",
      "The capture is coupled and visible: the value accumulates in the Now Platform's tables, flows, subflows, agents, and specialists, and the buyer can see it living there. The quieter surface is zero copy. The warehouse data stays in Snowflake or Databricks, which is true and reassuring, while the Data Fabric tables, the access configuration, and every action taken on that data accumulate in ServiceNow, the decoupled pattern Salesforce carries at the same layer. Decision authority follows the code where there is code: the enterprise's flows and integrations decide at 1C; the model decides inside the agent loop at 2B, and supervised execution asks the human for input without a documented gate on the specific effect, so that reading is Ceded; ServiceNow's engine decides placement and ranking on policy the enterprise writes at 1A and 1B; ServiceNow alone decides how its platform is orchestrated and what its applications surface at 2A and Layer 3; and at 2C the enterprise's own governance policy is the last word over a plane whose identity and gateway legs are the row's open questions.",
      "The buyer gets a constructible, multi-model agent runtime with deterministic execution and two years of production behind it, the broadest agent inventory and containment surface on the map, a real-time data foundation with a catalog and lineage, and the workflow applications a company runs its operations on. In exchange: no data plane of its own beyond the system of record for work, no retrieval infrastructure, no serving stack, no compute surface, and a platform whose artifacts run nowhere else. What moves this row: product documentation settling that the consolidated Model Context Protocol (MCP) governance in AI Control Tower enforces per request and that AI-user principals carry agent-typed audit (2C to strong); a general data-management surface (1A to strong); an arbitrary-endpoint model connector for agents (2B's label back to any-model)."
    ]
  },
  "layers": [
    {
      "id": "layer0",
      "label": "Layer 0",
      "shortName": "Compute",
      "title": "Compute & Network Fabric",
      "purpose": "Raw compute, networking, and acceleration fabric",
      "status": "gap",
      "statusLabel": "Not ServiceNow's Layer (By Design)",
      "authority": {
        "decides": "vendor",
        "visible": false,
        "overridable": false,
        "boundary": "vendor",
        "direction": "Ceded"
      },
      "nvidia": [
        {
          "component": "ServiceNow Compute Hubs (NVIDIA GPUs, Azure Bursting)",
          "detail": "Now Assist workloads go to one of three centralized ServiceNow compute hubs with GPUs for AI workloads, and ServiceNow may use Azure-hosted GPUs for Now large language model (LLM) Service capacity bursting inside its own network boundary. Invisible to the customer, not a substrate the customer buys."
        },
        {
          "component": "Apriel Co-Development (NVIDIA DGX Cloud on AWS)",
          "detail": "Apriel Nemotron 15B was post-trained on NVIDIA DGX Cloud hosted on Amazon Web Services (AWS); Apriel 2.0 is co-developed with NVIDIA. A development fact, not a customer substrate."
        }
      ],
      "gap": "Layer 0 isn't ServiceNow's layer, and that's the pitch: the buyer picks a region and never thinks about silicon. Per its FY2025 Form 10-K, ServiceNow delivers the service through its own private cloud and through public cloud providers supplying infrastructure as a service, with data centers in North America, South America, Europe, Asia, and Australia configured in pairs, and the architecture also supports deployment in customer-managed or third-party data centers where regulation requires it. Now Assist workloads run in three centralized ServiceNow compute hubs with graphics processing units (GPUs), with Azure GPUs available for bursting inside ServiceNow's network boundary. The one customer-operated exception is Private Stack, available today: the same application software deployed in the customer's data center, sovereign cloud, or air-gapped environment, where the customer or a partner operates hardware, database, load balancers, networking, and operating system, and generative AI runs on the customer's own GPUs, through a bring-your-own-key connection to Azure OpenAI, Amazon Bedrock Claude, or Google Gemini, or through a customer-provided model with limited function.\n\nThe exposure test governs, as it did for Salesforce: an underlay capability the vendor doesn't surface as a purchasable, customer-administered product isn't that vendor's capability. ServiceNow's compute sits invisibly behind a software-as-a-service (SaaS) interface on either cloud. Private Stack puts the customer's hardware under the platform, but ServiceNow sells no hardware, fabric, or GPU there either; it hands over deployment guidance, upgrade packages, and sizing workshops.\n\nCalibration: Salesforce, Snowflake, Databricks, and Qlik read gap by design with the substrate absorbed beneath the service; Elastic reads gap with authority Absent because half its base self-manages. ServiceNow is the Salesforce shape with a Private Stack exception the row names rather than scores.",
      "borrowedJudgment": "Total at Layer 0 and irrelevant to the value proposition by design. On the SaaS path ServiceNow's private-cloud and public-cloud substrate judgment is inherited invisibly, the Ceded-invisible reading every SaaS-only row carries. On Private Stack the substrate judgment stays with the customer, and the cell names that path without scoring it, because ServiceNow offers nothing at the layer on either path.",
      "notes": "Private Stack is named, not scored: ServiceNow provides application software and guidance, the customer provides and operates every layer beneath it. Public evidence that moves the cell: a ServiceNow-sold appliance or a customer-administered GPU offer.",
      "components": []
    },
    {
      "id": "layer1a",
      "label": "Layer 1A",
      "shortName": "Storage",
      "title": "Data Storage & Governance",
      "purpose": "Durable, governed data foundation — the Governance Catalog that Layer 2C queries",
      "status": "moderate",
      "statusLabel": "Workflow System of Record + Zero-Copy Reach + Data Catalog; No Data Management Plane",
      "authority": {
        "decides": "vendor",
        "visible": true,
        "overridable": true,
        "boundary": "vendor",
        "direction": "Delegated"
      },
      "nvidia": [
        {
          "component": "No NVIDIA Layer 1A Dependency",
          "detail": "The data foundation is ServiceNow's database and platform; nothing here depends on NVIDIA."
        }
      ],
      "gap": "The buyer's data foundation here is the system of record for work: the Now Platform tables, the Configuration Management Database (CMDB) that the company calls the AI governance foundation, and the access control lists (ACLs), data filtration, and Vault encryption that govern reads. Underneath, RaptorDB Pro (PostgreSQL-based with proprietary enhancements) runs transactions and column-store analytics on one engine as instances migrate off MariaDB, with Live Connect exposing a Structured Query Language (SQL) API and Live Archive tiering cold records to object storage. Reach beyond the platform comes from Workflow Data Fabric Hub (Yokohama, March 2025): Zero Copy Connectors, a separately subscribed Store application, let workflows and agents read Snowflake, Databricks, BigQuery, Redshift, and Oracle in place, and the Knowledge Graph gives agents a semantic layer over platform and fabric data. The catalog leg the purpose line names is now shipped: ServiceNow Data Catalog, a new Store application in the Australia release built on the data.world acquisition, collects metadata from fourteen or more external platforms, shows lineage across connected systems, carries a business glossary and column-level classifications, and accepts data-quality results from external tools through a Data Quality API. Veza (closed March 2, 2026) adds an access graph across human and non-human identities.\n\nThe governance is an authorization authority, with documented edges. ACLs in AI Agent Studio govern who may invoke an agent; what the agent may do once running is set by its identity, a dynamic user inheriting the invoker's roles under mandatory role masking, or an AI user, a dedicated identity with fixed roles that can exceed the invoker's. The deciding line is the one that separated Salesforce (strong) from Qlik (moderate): authorization authority enforced at runtime, and a general data plane. On the first, yes. On the second, no. Salesforce read strong only because Informatica bought it master data management, quality enforcement, and lineage across every domain. ServiceNow's foundation is workflow-shaped, Zero Copy is reach rather than exit, and the catalog carries quality information without enforcing it; Autonomous Data Governance (observability, quality, privacy) is expected in the second half of 2026. That's the Salesforce-without-Informatica case the Salesforce cell says would read moderate.\n\nCalibration: Snowflake and Databricks read strong on a governed lakehouse plus a catalog; Salesforce strong on authorization authority plus Informatica; Qlik moderate on an open lakehouse with a captive trust layer; Elastic moderate on a tiered store with access control and no catalog. ServiceNow sits above Elastic (catalog, lineage, semantic layer) and below Salesforce (no mastering, no quality enforcement). Moderate, with the catalog credited and the missing data-management plane named as the gate.",
      "borrowedJudgment": "Low for the governance logic, which is ServiceNow IP and Ceded; RaptorDB is PostgreSQL underneath but the schema, ACLs, and platform semantics don't lift. The zero-copy federation interface is Delegated, the tables stay in the customer's warehouse under a multi-vendor pattern, and the Data Fabric tables, mappings, and access configuration built over it are Ceded, the Salesforce split. The runtime tradeoff is ServiceNow's engine placing and serving data on policy the enterprise writes: vendor decides, visible, overridable per object through ACLs and data filtration, Delegated, the Snowflake and Databricks reading.",
      "notes": "ESCALATED: the grade sits on the Salesforce boundary. Recommendation moderate; the alternative reads strong on catalog plus lineage plus quality metadata plus runtime authorization, treating master data management as the one missing leg. What settles it: whether the catalog's quality information and lineage count as the data-management plane the Salesforce cell required, or whether enforcement (expected 2H 2026 as Autonomous Data Governance) is the bar. Watch-list, notes only: Autonomous Data Governance (observability, quality, privacy; expected second half 2026); Workflow Data Network Partner Passport (second half 2026). Instrument follow-up: Salesforce 1A reads vendor / Ceded on enterprise-authored sharing rules; under the override rule that shape reads Delegated.",
      "components": [
        {
          "component": "Now Platform Data Model + CMDB + ACLs (System of Record for Work)",
          "detail": "Tables, the CMDB, access control lists, data filtration, and Vault encryption. ACLs govern invocation; runtime scope is set by the agent's identity (dynamic user under role masking, or an AI user with fixed roles). Decades of accumulated schema and access logic that lifts nowhere.",
          "dapm": "Ceded"
        },
        {
          "component": "RaptorDB Pro (PostgreSQL-Based Hybrid Transactional and Analytical Processing (HTAP) Engine, Live Connect, Live Archive)",
          "detail": "ServiceNow's database, built on PostgreSQL with proprietary enhancements, running transactions and column-store analytics on one engine; Live Connect adds a SQL API and Live Archive tiers records to object storage in compressed columnar form with ACLs intact (both available now with RaptorDB Pro). Sold as a Pro tier; instances are migrating from MariaDB. Open engine underneath, captive platform on top.",
          "dapm": "Ceded"
        },
        {
          "component": "Zero Copy Federation Interface (Snowflake, Databricks, BigQuery, Redshift, Oracle)",
          "detail": "Workflow Data Fabric Hub (Yokohama, March 2025) with the separately subscribed Zero Copy Connectors application reads warehouse data in place without copying. The data stays in the customer's warehouse under the warehouse's governance; switching warehouses re-points the connector. The federation interface is Delegated; what's built on it is the next chip.",
          "dapm": "Delegated"
        },
        {
          "component": "Data Fabric Tables + Mappings + Access Configuration (Zero Copy Semantic Integration)",
          "detail": "The ServiceNow-side surface over federated data: Data Fabric tables, schema and column mappings, access controls in the connection, and the workflow and agent actions that consume the data as if it were local. Accumulated ServiceNow opinions, the Salesforce 'Zero Copy Semantic Integration' reading.",
          "dapm": "Ceded"
        },
        {
          "component": "Knowledge Graph (Semantic Layer over Platform and Fabric Data)",
          "detail": "A semantic layer mapped through the Knowledge Graph Designer over platform tables and Data Fabric sources, exposed to agents and, since May 2026, to external clients through the MCP Server Console. ServiceNow objects with no second implementer.",
          "dapm": "Ceded"
        },
        {
          "component": "ServiceNow Data Catalog (data.world Lineage, Collectors, Glossary, Quality API)",
          "detail": "A new Store application in the Australia release: metadata collectors for fourteen or more external platforms, lineage across connected systems, business glossary, column-level classifications, and data-quality information submitted by external tools through the Data Quality API. The governance catalog the purpose line names; the curation and policy opinions rebuild elsewhere.",
          "dapm": "Ceded"
        }
      ]
    },
    {
      "id": "layer1b",
      "label": "Layer 1B",
      "shortName": "Retrieval",
      "title": "Context Management & Retrieval",
      "purpose": "Low-latency retrieval for RAG — vector/hybrid search, context windows",
      "status": "moderate",
      "statusLabel": "Platform-Scoped Hybrid Retrieval with Embedding Choice; No Infrastructure Surface",
      "authority": {
        "decides": "vendor",
        "visible": true,
        "overridable": true,
        "boundary": "vendor",
        "direction": "Delegated"
      },
      "nvidia": [
        {
          "component": "No Customer-Side NVIDIA Dependency",
          "detail": "Embeddings and retrieval run in the Now LLM Service on ServiceNow's compute hubs or at the customer's chosen embedding provider. Nothing the customer administers here touches NVIDIA."
        }
      ],
      "gap": "Retrieval is built into the platform and the buyer never stands up a vector database. AI Search runs hybrid retrieval, keyword ranking on Best Match 25 with proximity plus dense passage retrieval over a semantic vector index that's enabled automatically, and Now Assist in AI Search turns results into generated answers (Genius Results) across knowledge articles, Virtual Agent topics, and catalog items. The Semantic Index Configuration form (Australia) lets the admin pick the embedding model: ServiceNow's fine-tuned E5 by default, Azure OpenAI, Google Gemini, or a custom model brought through the bring-your-own-model path. Retrieval filters results for the logged-in user, preserving role-based field-level ACLs, non-scripted conditional ACLs, scripted table-level ACLs, before-query business rules, domain separation, and user criteria on knowledge and catalog tables; scripted and conditional field-level ACLs aren't supported. The Knowledge Graph adds structured context, and Zero Copy lets an agent ground on warehouse data in place. For the buyer, retrieval-augmented generation (RAG) is a feature that's already on.\n\nWhat the buyer doesn't get is retrieval infrastructure. There's no customer-facing vector store, no retrieval application programming interface (API) an enterprise builds a non-ServiceNow application on, and no bring-your-own vectors. The index and the retrieval surface serve ServiceNow experiences; the embedding choice changes whose space the vectors live in, not who can query them. Rule 4 reads this as fixed-function: the pipeline's shape is set by the product, and an enterprise whose retrieval need isn't a ServiceNow experience deploys another tool beside it.\n\nCalibration: Salesforce reads strong because Data 360 exposes retrievers, a vector surface, and an API the enterprise builds on. Qlik reads moderate because retrieval is a closed product feature with no API or model choice. Elastic reads strong as the retrieval engine itself. ServiceNow sits with Qlik, above it on hybrid retrieval, documented access control list (ACL) filtering, embedding choice, and the Knowledge Graph, and on the same side of the line: a product feature, not a surface. Moderate.",
      "borrowedJudgment": "Low and split at the embedding. AI Search, the semantic index, and the Knowledge Graph are ServiceNow IP and Ceded. The default E5 embedding is ServiceNow's fine-tune and Ceded; Azure OpenAI and Gemini embeddings through the platform are Ceded to their owners under the channel-substitution rule; a custom model the enterprise brings is Delegated on the open-source seam, the Snowflake Arctic and Elastic Eland reading. The runtime tradeoff is the platform's ranking on relevance configuration the admin writes: vendor decides, visible, overridable per object, Delegated under the override rule.",
      "notes": "Public evidence that moves the cell: a customer-facing vector store or retrieval API. The semantic index requires the AI Search Semantic Controller plugin and at least one Otto application installed.",
      "components": [
        {
          "component": "AI Search: Hybrid Retrieval (BM25 + Dense Passage Retrieval, Automatic Semantic Index)",
          "detail": "Keyword ranking with proximity plus semantic vector search over an index that's enabled automatically with no configurable settings; search profiles and sources are the admin's relevance surface. Platform-internal index: Ceded.",
          "dapm": "Ceded"
        },
        {
          "component": "Embedding Model Choice: ServiceNow E5 (Default), Azure OpenAI, Google Gemini",
          "detail": "The Semantic Index Configuration form selects the embedding model. ServiceNow's fine-tuned E5 is ServiceNow's model; Azure OpenAI and Gemini embeddings are their owners' spaces served through ServiceNow's paper. The embedding carve-out and the channel-substitution rule: Ceded.",
          "dapm": "Ceded"
        },
        {
          "component": "Custom Embedding Model (Bring-Your-Own-Model Path)",
          "detail": "An administrator can create a custom embedding model for semantic indexing and select it as the preferred model. The enterprise's own model on ServiceNow's serving surface; the vectors recompute wherever the same weights run. Delegated on the open-source seam.",
          "dapm": "Delegated"
        },
        {
          "component": "Now Assist in AI Search (RAG, Genius Results) with Documented ACL Filtering",
          "detail": "Generated answers over retrieved knowledge, Virtual Agent topics, and catalog items, filtered for the logged-in user with the supported ACL and security types preserved and scripted or conditional field-level ACLs excluded. A product feature with no external API. ServiceNow IP.",
          "dapm": "Ceded"
        },
        {
          "component": "Knowledge Graph + Zero Copy as Agent Context",
          "detail": "Structured context for agents from the semantic layer and from warehouse data read in place. The graph is ServiceNow's; the warehouse reach is scored at 1A and referenced here.",
          "dapm": "Ceded"
        }
      ]
    },
    {
      "id": "layer1c",
      "label": "Layer 1C",
      "shortName": "Pipelines",
      "title": "Data Movement & Pipelines",
      "purpose": "Move/transform data — ETL/ELT, lineage, cost-aware movement, KV cache tiering",
      "status": "moderate",
      "statusLabel": "Integration Fabric + Lineage + Cost-Aware Archive; No Enterprise ETL, No CDC",
      "authority": {
        "decides": "code",
        "visible": true,
        "overridable": true,
        "boundary": "vendor",
        "direction": "Retained"
      },
      "nvidia": [
        {
          "component": "No NVIDIA Layer 1C Dependency",
          "detail": "Nothing in the integration fabric depends on NVIDIA."
        }
      ],
      "gap": "Data movement on the Now Platform is integration, and the buyer gets a lot of it: IntegrationHub with hundreds of prebuilt spokes and a Flow Designer canvas for building integrations without code, Stream Connect for Kafka, IntegrationHub extract, transform, load (ETL) for importing and transforming source data into the CMDB, and Data Stream actions. Zero Copy Connectors are the movement-avoidance half: read the warehouse in place rather than replicate it. Two things the purpose line names are now shipped on ServiceNow paper. Lineage: ServiceNow Data Catalog (Australia) collects metadata from fourteen or more external platforms and shows lineage and impact across connected systems through the Data Catalog Graph Explorer. Cost-aware movement: Live Archive, exclusive to RaptorDB Professional V2, moves records and attachments to object storage in compressed columnar form under the existing archive rules (any field-based condition), keeps them queryable and reportable, and applies ACLs, roles, and row-level security to archived records as to live ones. Everything is authored in Flow Designer or archive rules and executed by the platform.\n\nWhat it isn't is a data-engineering platform. There's no change data capture (CDC) from operational databases into a lakehouse, no general extract, load, transform (ELT) engine with arbitrary transformations and choosable destinations, no KV-cache tiering. Rule 4's day-two test fails for tabular data: when the second requirement is replicating a schema into Snowflake, another tool arrives. IntegrationHub ETL transforms in one direction, into ServiceNow, and Live Archive moves ServiceNow's own records.\n\nCalibration: Salesforce reads strong because MuleSoft and Informatica are general integration and data-management platforms sold on Salesforce paper. Qlik reads strong on CDC plus Talend; Snowflake and Databricks on general pipeline engines. NetApp reads moderate with best-in-class movement and tiering (FabricPool) and a fixed-function AI pipeline. Elastic reads moderate as a general telemetry pipeline that's a slice of the layer. ServiceNow is the Elastic shape with NetApp's tiering leg: general in kind for workflow integration, lineage and cost-aware archive present, a slice of the layer's function. Moderate.",
      "borrowedJudgment": "Low. IntegrationHub, the spokes, Stream Connect, the fabric, the catalog, and Live Archive are ServiceNow IP and Ceded; Zero Copy is Delegated at 1A. The runtime is the platform executing flows, integrations, and archive rules the enterprise authored, deterministically, with no vendor judgment about what moves where: code decides, visible, overridable, Retained, the reading Elastic and VAST carry under the override rule.",
      "notes": "Data Catalog is scored here for its lineage and collectors and at 1A for its governance catalog; two functions of one product, stated in both cells. The Universal MCP Client (agent tool and resource access) is a 2B and 2C fact, not movement, and isn't scored here. Public evidence that moves the cell: a general ELT or CDC product on ServiceNow paper; Autonomous Data Governance (expected second half 2026) adding quality enforcement.",
      "components": [
        {
          "component": "IntegrationHub + Spokes + Flow Designer Integrations",
          "detail": "Hundreds of prebuilt spokes and a no-code canvas for integrations and automations; the platform's integration fabric. Flow definitions are ServiceNow objects that rebuild elsewhere.",
          "dapm": "Ceded"
        },
        {
          "component": "Workflow Data Fabric Movement: Stream Connect (Kafka), IntegrationHub ETL, Data Stream Actions",
          "detail": "Kafka streaming in and out, ETL into the CMDB with transformation, and streaming data actions. Real movement, one direction of transformation, platform-bound definitions.",
          "dapm": "Ceded"
        },
        {
          "component": "ServiceNow Data Catalog: Metadata Collectors and Lineage (Australia)",
          "detail": "Automated metadata collection from fourteen or more external platforms, lineage and impact across connected systems in the Graph Explorer, classifications, and quality information through the Data Quality API. The lineage the purpose line names, on ServiceNow paper. Proprietary catalog.",
          "dapm": "Ceded"
        },
        {
          "component": "Live Archive (RaptorDB Professional V2, Cost-Aware Tiering to Object Storage)",
          "detail": "Archive rules move qualifying records and attachments to object storage in compressed columnar format behind an S3 facade across data center pairs; archived data stays queryable with ACLs intact. Exclusive to RaptorDB Professional. The NetApp FabricPool shape: a captive tiering engine.",
          "dapm": "Ceded"
        }
      ]
    },
    {
      "id": "layer2a",
      "label": "Layer 2A",
      "shortName": "Orchestration",
      "title": "Infrastructure Orchestration",
      "purpose": "GPU scheduling, quotas, RBAC, fair-share scheduling, utilization optimization",
      "status": "gap",
      "statusLabel": "Managed SaaS Lifecycle Only; No Orchestration Surface, No GPU Plane",
      "authority": {
        "decides": "vendor",
        "visible": false,
        "overridable": false,
        "boundary": "vendor",
        "direction": "Ceded"
      },
      "nvidia": [
        {
          "component": "No Customer GPU Plane; NVIDIA AI Factory Governance Integration Is a 2C Fact",
          "detail": "ServiceNow schedules its own NVIDIA fleet behind the Now LLM Service. The AI Control Tower integration with the NVIDIA Enterprise AI Factory validated design (GA May 5, 2026) governs model workloads at the infrastructure layer; the GPU scheduling plane there is NVIDIA's (Run:ai) and isn't surfaced by ServiceNow as an orchestration product."
        }
      ],
      "gap": "There's nothing to operate, and that's the offer. ServiceNow provisions, scales, patches, and upgrades instances on a published family-release cadence (Zurich, Australia), with the customer choosing a release window and little else. Compute for Now Assist and the Now LLM Service is metered in assists and credits, not sized. Private Stack inverts the operating model, the customer runs hardware, database, load balancers, networking, and operating system, but ServiceNow's contribution there is application software, deployment guidance, upgrade packages, and workshops, not an orchestrator.\n\nThe layer's job is GPU scheduling, quotas, fair-share, and utilization for the enterprise's AI compute, and ServiceNow surfaces no orchestration product at all: no customer-administered control plane, cluster orchestration, or compute pool. The exposure test governs, and the Salesforce precedent is explicit that Hyperforce's invisible provisioning carries no capability weight; Salesforce's moderate rests on CloudHub 2.0 and Runtime Fabric, surfaces the customer deploys to and operates. ServiceNow has no equivalent. Qlik has lakehouse cluster orchestration, Palantir has Rubix, Elastic has ECE and ECK, Snowflake has compute pools; ServiceNow has instance lifecycle management the customer never touches. That's the vendor absorbing the layer beneath its service.\n\nCalibration: Salesforce, Snowflake, Qlik, and Palantir read moderate on a customer-consumed, platform-scoped orchestration surface; Kamiwaza reads gap with authority Absent because it offers nothing and inherits nothing. ServiceNow offers nothing the customer administers and absorbs the layer invisibly: gap, Ceded.",
      "borrowedJudgment": "Total and invisible. The release cadence, instance sizing, and compute allocation are ServiceNow's and the customer never sees them; on Private Stack the customer operates the infrastructure and ServiceNow's orchestration opinions still aren't on offer. Vendor absorbs the layer: vendor decides, not visible, not overridable, Ceded.",
      "notes": "Private Stack is named in prose, not scored: it's application software on customer-operated infrastructure with no orchestration product. The NVIDIA Enterprise AI Factory governance integration is scored at 2C. Public evidence that moves the cell: a customer-administered compute, cluster, or GPU surface in either deployment model.",
      "components": []
    },
    {
      "id": "layer2b",
      "label": "Layer 2B",
      "shortName": "Runtime",
      "title": "Application Runtime & Execution",
      "purpose": "Model serving, agent execution, inference APIs, distributed inference",
      "status": "strong",
      "statusLabel": "Constructible Governed Agent Runtime; Multi-Model; Flow-Executed",
      "authority": {
        "decides": "model",
        "visible": true,
        "overridable": false,
        "boundary": "model",
        "direction": "Ceded"
      },
      "nvidia": [
        {
          "component": "Now LLM Service GPUs (ServiceNow-Operated) and Apriel",
          "detail": "ServiceNow's models run on NVIDIA GPUs in ServiceNow compute hubs with Azure bursting; Apriel 2.0 is co-developed with NVIDIA. On Private Stack the model runs on the customer's GPUs. No customer-administered NVIDIA dependency on the SaaS path."
        }
      ],
      "gap": "This is what the buyer came for in 2026, and it's a first-party runtime. AI Agent Studio builds agents from instructions and tools, where the documented tool types are Flow actions, subflows and spokes, record operations, knowledge search, scripts, and, since Zurich Patch 4, external MCP server tools, each with an execution mode: supervised, where inputs from a human agent are required during the tool's execution, or autonomous. The AI Agent Orchestrator (GA, enhanced in Australia) plans and sequences agents with three configurable planners, and Agentic Playbooks hand whole jobs to them; Agentic Evaluations scores agents with an evaluation model before deployment. Every agent runs as an identity: a dynamic user inheriting the invoker's roles under mandatory role masking, or an AI user with fixed roles. Model access for agents is ServiceNow-managed Azure OpenAI, Google Gemini, and Amazon Bedrock Claude (Gemini 3.5 Flash and GPT 5.1 and 5.4 Mini added July 2026), or bring-your-own-key to the customer's own Azure, Google, or AWS accounts; skills additionally take spokes to OpenAI, IBM watsonx, and Vertex, and a generic bring-your-own-LLM connector, neither supported for agents. Now LLM Service stopped being the default in July 2026, its long-term-support SKU ended, and it remains selectable; Apriel 2.0, the open model co-developed with NVIDIA under the MIT license, targets regulated industries. The Build Agent (Zurich, now in Studio) writes applications from prompts on Claude Opus 4.6 by default. Private Stack runs the whole thing, model included, on the customer's hardware.\n\nThe deciding precedent is Salesforce and Palantir: strong at 2B on a governed, constructible, swappable-model agent runtime without general model serving, because agents are constructed, the model is swappable, and execution lands in deterministic business logic. ServiceNow has the shape: constructible in Studio, swappable across three frontier providers and the customer's own keys, execution through Flow actions and subflows with a per-tool supervised mode, orchestration and evaluation on top. What it lacks is what Salesforce lacks, and one thing more: no product for serving or fine-tuning the customer's own model on the SaaS path, no distributed inference, and no arbitrary-endpoint model connector for agents, so the label reads multi-model rather than any-model. The runtime is platform-bound, agents ground in the Now Platform and can't be lifted, and that's the authority finding scored below, not a capability dock.\n\nCalibration: Salesforce strong (Atlas), Palantir strong, Snowflake strong with serving on top. Qlik moderate on configurable agents with a fixed model; Elastic moderate on a first-release runtime. ServiceNow is on the Salesforce side of the constructible-and-swappable line, with two years of shipping agents, an orchestrator, and an evaluation surface behind it. Strong, with the model breadth named honestly.",
      "borrowedJudgment": "Low for the runtime, governance, and execution machinery, all ServiceNow IP and Ceded, and the capture is designed: agents, Flow actions, subflows, and skills ground in the Now Platform and run nowhere else, the Salesforce Flow-and-Apex reading. Model access is Delegated: managed frontier models the enterprise can swap and bring-your-own-key through the providers' own accounts, the Elastic Managed-LLM reading. The model decides which tool to call. The supervised execution mode requires a human's input during the tool's execution, but no documented control lets the enterprise approve or refuse the specific model-selected effect before it lands, and the override rule needs that gate: model decides, visible, not overridable, Ceded (Keith's ruling, September 5, 2026).",
      "notes": "Customer-authored tools chip ruled Ceded (Keith, September 5, 2026, on the SAP row, applied here to the identical shape): Flow actions, subflows, scripts, and skills run only on the Now Platform; customer-authored tool logic reads Retained only where it runs outside the vendor. The Snowflake and Elastic customer-tools chips are logged for re-reading under this ruling. Second, the authority reading was ruled Ceded on September 5, 2026: supervised mode requires human input during tool execution but isn't documented as approval of the specific effect before commit, so it isn't the gate the override rule needs; Elastic's Workflows approval step and Salesforce's Flow commit boundary remain the Delegated precedents. Grade question also escalated: whether three managed providers plus bring-your-own-key (BYOK) is 'swappable model' at the Salesforce standard; recommendation strong. Watch-list, notes only: Otto (live inside EmployeeWorks and AI Control Tower, rolling through Australia); whether Apriel 2.0 is selectable inside the platform (the provider docs list Now LLM Service, Azure OpenAI, Google Gemini, and AWS Claude); some out-of-box skills and agents don't support Now LLM Service or third-party providers (KB2222333).",
      "components": [
        {
          "component": "AI Agent Studio + AI Agent Orchestrator + Agentic Playbooks + Agentic Evaluations",
          "detail": "Agents built from instructions and tools, sequenced by the Orchestrator's planners across departments, assigned whole jobs through playbooks, and scored by Agentic Evaluations before deployment; the Build Agent generates applications from prompts. ServiceNow objects that run nowhere else.",
          "dapm": "Ceded"
        },
        {
          "component": "Customer-Authored Tools + Execution Modes (Flow Actions, Subflows, Scripts, Skills; Supervised or Autonomous)",
          "detail": "The Flow actions, subflows, scripts, and skills the enterprise writes as tools, each with a supervised or autonomous execution mode, executed under the agent's identity. The customer authors the logic; it runs only on the Now Platform, the Salesforce Flow-and-Apex reading. Ceded: the logic runs only on the vendor's platform (ruled September 5, 2026).",
          "dapm": "Ceded"
        },
        {
          "component": "Managed Third-Party Models (Azure OpenAI, Google Gemini, Amazon Bedrock Claude via the Now LLM Service)",
          "detail": "ServiceNow-managed connections to Azure OpenAI GPT 4.1 and 5.x, Google Gemini 2.5 and 3.5 Flash, and Amazon Bedrock Claude, the default since Now LLM stopped being the default in July 2026 (Now LLM remains selectable; its LTS SKU is retired). A managed broker the enterprise can replace with its own keys: Delegated on the Elastic Managed-LLM precedent.",
          "dapm": "Delegated"
        },
        {
          "component": "Bring-Your-Own-Key (Agents) and Spokes / Generic Connector (Skills Only)",
          "detail": "Route agents through the customer's own Azure OpenAI, Google Gemini, or Amazon Bedrock accounts (BYOK, supported for agents); route skills through spokes to OpenAI, IBM watsonx, or Vertex, or a generic connector with transformation scripts (not supported for agents). The inference-interface ruling: Delegated.",
          "dapm": "Delegated"
        },
        {
          "component": "Now Assist Skills + Skill Kit",
          "detail": "Out-of-the-box generative skills across IT Service Management (ITSM), Customer Service Management (CSM), HR, and more, plus the Skill Kit for custom skills over any connected model. ServiceNow IP.",
          "dapm": "Ceded"
        },
        {
          "component": "Private Stack Model Hosting (ServiceNow Model on Customer GPUs)",
          "detail": "The production LLM on customer-owned GPU infrastructure, or BYOK, inside a customer-operated deployment. The model and its serving are ServiceNow's; running them on your own GPUs is operational control, not authority.",
          "dapm": "Ceded"
        }
      ]
    },
    {
      "id": "layer2c",
      "label": "Layer 2C",
      "shortName": "Reasoning",
      "title": "Agentic Infrastructure — The Reasoning Plane",
      "purpose": "Policy-driven placement and resource coordination — the Autonomy Layer",
      "status": "moderate",
      "statusLabel": "Cross-Enterprise Agent Registry, Containment, Orchestration, Observability; Identity and Gateway Legs Contested",
      "authority": {
        "decides": "code",
        "visible": true,
        "overridable": true,
        "boundary": "vendor",
        "direction": "Retained"
      },
      "nvidia": [
        {
          "component": "NVIDIA Enterprise AI Factory Governance Integration (GA May 5, 2026)",
          "detail": "AI Control Tower's integration with the NVIDIA Enterprise AI Factory validated design extends discovery, inventory, observability, compliance monitoring, and remediation to model workloads running in AI factories. Governance reach, not a runtime dependency."
        }
      ],
      "gap": "AI Control Tower is the broadest agent-governance surface on the map, and it governs other vendors' agents as readily as ServiceNow's. Registry: every agent, model, prompt, dataset, and MCP server is an inventoried asset with provider, lifecycle phase, state, and risk classification; assets are Managed or Unmanaged, promotion rules run on a schedule, MCP servers need formal approval before activation, and discovery runs through AI Service Graph Connectors, with Databricks, Snowflake, and Hugging Face generally available in June 2026 alongside Salesforce, AWS, and Azure. Containment and enforcement: the Australia release ships AI agent containment with kill-switch protocols across AWS, Google Cloud Platform (GCP), and ServiceNow, hides unapproved MCP servers from AI Agent Studio, and can disable a model and its tool access in real time; MCP governance, formerly the standalone AI Gateway application (deprecated in Australia), is consolidated into AI Control Tower with approval workflows, sensitive-data protection, and audit on MCP tool invocations, and the Universal MCP Client runs with that enforcement always on. Orchestration: the AI Agent Orchestrator sequences agents across departments, and Action Fabric's MCP Server Console (GA June 2026) and agent-to-agent (A2A) let external agents run governed ServiceNow workflows. Observability: automated scoring, configurable metrics, and trend analysis for AI quality and safety, an Activity Center for governance tasks, agent reasoning traces, and cost tracking. Identity: an agent runs as a dynamic user under mandatory role masking or as an AI user, a dedicated sys_user identity with fixed roles; the Machine Identity Console governs inbound machine identities; Veza (closed March 2, 2026) maps every human and non-human identity's effective access, agents included. Compliance packs ship for the EU AI Act and the California and Colorado acts, and the NVIDIA Enterprise AI Factory integration (GA May 5, 2026) extends governance to model workloads in the data center.\n\nApplying the strong criterion, three legs are clean: registry, orchestration, observability. Two are contested in the documentation. The gateway: the AI Gateway application is deprecated and unsupported in Australia, its MCP governance consolidated into AI Control Tower, and the product docs describe approval, containment, and audit rather than per-request policy (rate limits, cost caps) at the Salesforce Omni and Flex Gateway standard; A2A runs outside it on its own authentication. The identity: the AI user is a per-agent principal, but it's an option rather than the default, the ACLs set in AI Agent Studio govern invocation while runtime data access follows the agent identity's roles under the platform's table ACLs, and agent-typed audit at the effect boundary isn't documented at the Snowflake standard. No reasoning mechanism exists; live placement and the deterministic outcome validator are absent as everywhere.\n\nCalibration: GCP reads strong on a complete plane; Azure strong with its policy engine as the orchestration leg. Salesforce reads moderate on MuleSoft Agent Fabric, a registry, broker, gateway, and observability, with the identity leg thin. Snowflake reads moderate on identity, registry, and observability with no gateway. ServiceNow has more reach than either, cross-vendor discovery and containment that neither offers, and the same two legs in question. Moderate at the Salesforce standard, with the two legs named as what completes the plane.",
      "borrowedJudgment": "Low upstream borrowed judgment, and the term means dependence on third parties: everything here is ServiceNow IP (Control Tower, Orchestrator, Action Fabric, Veza, Armis) and Ceded to ServiceNow. Which agent may act on what is decided by policy the enterprise writes, agent identities and role masking, approval workflows, promotion rules, containment rules, execution modes, evaluated deterministically by the platform: code decides, visible, overridable, Retained, the Salesforce and Azure reading. The model decides inside the agent loop and that reading lives at 2B.",
      "notes": "ESCALATED: the grade sits on the strong boundary. Recommendation moderate; the alternative reads strong on the complete plane, treating the AI-user principal plus Veza as first-class identity and the consolidated MCP governance plus containment as the request-time gateway. What settles it: product documentation that the consolidated MCP governance in AI Control Tower enforces policy per tool invocation (not only approval and containment), and that AI-user executions carry agent-typed audit at the effect boundary. Watch-list, notes only: the Knowledge 2026 enhancements across Discover, Observe, Govern, Secure, and Measure (Innovation Lab May 2026, GA expected August 2026; the Australia release notes confirm containment, discovery, scoring, and compliance as GA); the 30-system discovery claim including SAP, Oracle, and Workday (rolling from April 2026; GA-confirmed connectors are the ones named in the June release notes); ServiceNow MCP Registry (Innovation Lab) and A2A Agent Card support (expected by year end); A2A governance outside the consolidated gateway; ISO 42001 content in legal review.",
      "components": [
        {
          "component": "AI Control Tower: Registry and Discovery (Managed and Unmanaged Assets, AI Service Graph Connectors)",
          "detail": "Agents, models, prompts, datasets, and MCP servers as governed assets with lifecycle, state, and risk classification; discovery through AI Service Graph Connectors (Databricks, Snowflake, Hugging Face GA June 2026; Salesforce, AWS, Azure earlier); Managed versus Unmanaged designation; scheduled promotion rules; MCP-server approval gates; publishing to Microsoft Agent 365. ServiceNow IP.",
          "dapm": "Ceded"
        },
        {
          "component": "MCP Governance and Agent Containment in AI Control Tower (Formerly the AI Gateway Application)",
          "detail": "Approval workflows, sensitive-data protection, and audit on MCP tool invocations; unapproved servers hidden from AI Agent Studio; kill-switch containment across AWS, GCP, and ServiceNow that disables a model and its tool access in real time; always-on enforcement for the Universal MCP Client. The standalone AI Gateway application is deprecated in Australia and its function consolidated here. A2A runs outside it. Read as containment and approval, not per-request policy; the contested gateway leg.",
          "dapm": "Ceded"
        },
        {
          "component": "AI Agent Orchestrator + Action Fabric (MCP Server Console, MCP Client, A2A)",
          "detail": "Cross-department sequencing of specialized agents; the MCP Server Console (GA June 2026) publishes skills, Knowledge Graph traversal, subflows, actions, and scripted REST APIs to external clients under OAuth 2.0 with three-vector access control and audit; A2A delegates tasks to external agents under OAuth or API keys. The protocols are standard; the orchestration and the exposed catalog are ServiceNow objects.",
          "dapm": "Ceded"
        },
        {
          "component": "Observe: Automated Scoring, Metrics and Trends, Activity Center, Reasoning Traces, Cost",
          "detail": "Automated scoring, configurable metrics, and trend analysis for AI quality and safety; the Activity Center for governance tasks; agent reasoning traces and execution logs; assist-based cost tracking; NVIDIA Enterprise AI Factory workloads in scope. ServiceNow dashboards and data model.",
          "dapm": "Ceded"
        },
        {
          "component": "Agent Identity: Dynamic Users under Role Masking, AI Users, Machine Identity Console, Veza Access Graph",
          "detail": "Agents run as a dynamic user inheriting the invoker's roles under mandatory role masking, or as an AI user, a dedicated sys_user identity with fixed roles; the Machine Identity Console governs inbound machine identities; Veza maps every human and non-human identity's effective access, agent sprawl, dormant identities, and access drift. A per-agent principal is available, not default; the contested identity leg.",
          "dapm": "Ceded"
        }
      ]
    },
    {
      "id": "layer3",
      "label": "Layer 3 (+1)",
      "shortName": "Applications",
      "title": "AI Application Layer — The Value Plane",
      "purpose": "AI-powered business capabilities — business logic, workflow automation",
      "status": "strong",
      "statusLabel": "First-Party Workflow Applications with an Autonomous Workforce Arriving",
      "authority": {
        "decides": "vendor",
        "visible": false,
        "overridable": false,
        "boundary": "vendor",
        "direction": "Ceded"
      },
      "nvidia": [
        {
          "component": "No NVIDIA Layer 3 Dependency",
          "detail": "The applications are platform software; the models behind them are brokered at 2B."
        }
      ],
      "gap": "This is ServiceNow's native layer and where the AI annual contract value passed one billion dollars in the second quarter of 2026. IT Service Management (ITSM), Customer Service Management (CSM), Human Resources Service Delivery (HRSD), Field Service Management (FSM), Security Operations (SecOps), Strategic Portfolio Management (SPM), and the rest ship with Now Assist skills across every workflow. The Autonomous Workforce is arriving inside them: the Level 1 (L1) Service Desk AI Specialist is generally available (AI Prime or Pro Plus and Enterprise Plus entitlement; Zurich Patch 13, Australia Patch 6, or later; English only), the first delivered out-of-box specialist; customer relationship management (CRM), employee-service, IT, and security and risk specialists were announced at Knowledge 2026 with availability language and are watch-listed until product documentation confirms them. Autonomous Security and Risk integrates Armis asset intelligence and Veza identity governance into one operating framework. Otto, the assistant experience announced at Knowledge 2026, is live inside EmployeeWorks and AI Control Tower and rolling through the Australia release. Platform Analytics, App Engine, and the Build Agent round out the layer, and the ServiceNow Store carries hundreds of certified partner applications and integrations beside ServiceNow's own.\n\nEverything ServiceNow-built is ServiceNow's: the applications, the specialist, the playbooks, and the data model they act on rebuild nowhere. The AI-driven pieces put a model in the workflow, and the human's override is the execution mode and the approval; the application's opinions about what to surface, route, and automate are ServiceNow's, and the buyer doesn't see them.\n\nCalibration: Salesforce reads strong on first-party business applications with AppExchange Delegated beside them; Palantir on first-party applications; Qlik on the analytics value plane; Snowflake on first-party agents with a Delegated marketplace. ServiceNow is the Salesforce case in the workflow department, with the autonomous layer arriving one specialist at a time. Strong.",
      "borrowedJudgment": "Low. The applications and the specialist are ServiceNow IP and Ceded; the models behind them are brokered and swappable at 2B; the partner ecosystem on the Store is Delegated on the AppExchange and Snowflake Marketplace precedent. Vendor decides, not visible, not overridable, Ceded, the reading every first-party value plane on the map carries.",
      "notes": "Watch-list, notes only: CRM, employee-service, and IT AI Specialists (announced available or expected June 2026 at Knowledge 2026; product documentation confirms only the L1 Service Desk specialist as GA); security and risk AI Specialists (preview June 2026, GA expected September 2026); Otto's full rollout through the Australia release; Autonomous Security's six solution areas (August 4, 2026). Public evidence that moves the cell: nothing upward from strong; product-doc GA for the remaining specialists widens the scored component.",
      "components": [
        {
          "component": "Workflow Applications with Now Assist (ITSM, CSM, HRSD, FSM, SecOps, SPM)",
          "detail": "The first-party applications and their generative skills across every workflow. ServiceNow IP.",
          "dapm": "Ceded"
        },
        {
          "component": "Autonomous Workforce: L1 Service Desk AI Specialist (GA)",
          "detail": "The first delivered out-of-box AI Specialist, generally available on AI Prime or Pro Plus and Enterprise Plus, Zurich Patch 13 or Australia Patch 6 and later, English only; further specialists watch-listed pending product documentation. ServiceNow IP.",
          "dapm": "Ceded"
        },
        {
          "component": "Autonomous Security and Risk (Armis + Veza)",
          "detail": "Asset intelligence across code, IT, operational technology (OT), and Internet of Things (IoT) (Armis) and identity governance for human and non-human identities (Veza) in one operating framework; security and risk crossed one billion dollars in ACV. ServiceNow-owned since 2026.",
          "dapm": "Ceded"
        },
        {
          "component": "Platform Analytics + App Engine + Build Agent",
          "detail": "Analytics, low-code application building, and the Build Agent that generates applications from prompts (Zurich; in Studio in Australia on Claude Opus 4.6 by default). ServiceNow IP.",
          "dapm": "Ceded"
        },
        {
          "component": "ServiceNow Store (Certified Partner Applications and Integrations)",
          "detail": "The public marketplace where ServiceNow and certified partners publish applications, integrations, and products, with hundreds of certified partner apps listing a non-ServiceNow provider. Substitutable independent software vendor (ISV) ecosystem at menu altitude: Delegated on the AppExchange and Snowflake Marketplace precedent.",
          "dapm": "Delegated"
        }
      ]
    }
  ]
}
