Table inspector
Everything attached to a table, in one drawer, read through the ancestry and exportable as XML.
A rail pinned to the right edge of any page that has a table. Parked, it is a teal tab on the edge of the page, in a colour that stands out on a light page and on a dark one. Point at it and it slides out to show the table and how many artefacts are attached; clicking it opens the drawer. Where there is no table, the rail removes itself rather than sitting there empty.
The rail lives in the top window only. Inside an iframe it would be clipped, and so would the drawer.
The seven categories
| Category | Read from | Filtered on | What each row also carries |
|---|---|---|---|
| Business Rules | sys_script | collection | When it runs, which operations, the condition, and a flag when a before rule writes a record |
| ACLs | sys_security_acl | name | The operation, resolved to its name, plus type, admin override, and whether it has a script |
| Client Scripts | sys_script_client | table | Type, field, and whether it extends to child tables |
| UI Policies | sys_ui_policy | table | Conditions, on load, reverse, global |
| Data Policies | sys_data_policy | model_table | Whether it applies to the UI, to import sets, and whether it reverses |
| UI Actions | sys_ui_action | table | Form button, list button, context menu, client |
| Notifications | sysevent_email_action | collection | The event, and which operations trigger it |
It reads the whole ancestry
Every category asks about the table and every table it inherits from, walking super_class up to
thirty hops. Each row is tagged with the table it actually came from, so you can tell a rule on
task from a rule on incident.
The walk is done by hand rather than with the platform's own hierarchy API, which is available only inside a scoped application.
Two checks before every query
Each category checks that the table is valid, and that the field it is about to filter on exists on that table.
That is not caution for its own sake. ServiceNow silently drops a condition on a field it does not recognise and runs the query anyway, so a renamed field would quietly return every ACL on the instance instead of the ones for your table. A category that cannot be queried says why instead.
The list of ancestors is never allowed to collapse into an empty condition, for the same reason.
One script, seven queries, in order
The drawer runs one background script per open, and the seven queries run in sequence inside it. They are not parallel on purpose: a per-table fan-out saturates a node's semaphores, and the first thing that queues behind it is your own next page load.
Each category stops at three hundred records. Past that the drawer says so, and both the filter and the export work on what was actually read.
Search and own table only
Inside a category, a search box filters the rows. Every word you type has to land somewhere in the
row: its name, its second line, the table it came from, its tags, operations or phase. So
task write finds an inherited write ACL without knowing which field held which word.
Own table only, under the drawer's header, drops everything inherited from a parent table. It answers a different question from the search, what was put on this table as opposed to what runs on it, so it changes the counts on the category list too. Switching it on inside a category that has nothing of its own steps back to the list, where the zero is legible.
Inheritance narrows first, then the words. Select all ticks what is left, an Export with nothing ticked sends what is left, and a row ticked before a filter hid it is neither counted nor exported.
Export
Export uses the platform's own XML endpoint, fetched from the same origin so your session rides along, fifty records per request, sequentially.
A list answers with an <xml> document and a single record with <unload>. Anything else is a
login page or a refusal, and it is not saved as a file: a downloaded file that is secretly a login
page is worse than an error.
What is not there
Flows. A flow's table is buried in its trigger's inputs and cannot be resolved reliably, so the inspector leaves flows out rather than showing some of them. Flows and catalog items reads them properly.
