Now Assist Secrets Revealed: What ServiceNow Consulting Experts Don't Want You to Know
I have spent years implementing ServiceNow solutions across enterprises, and I can tell you with absolute certainty: Now Assist represents both the most transformative opportunity and the most misunderstood technology in the ServiceNow ecosystem. What concerns me deeply is how many consulting partners gloss over critical details that every organization needs to understand before investing in AI-driven automation.
Today, I am pulling back the curtain on what you truly need to know about Now Assist: the insights that will empower you to make informed decisions and protect your organization from costly mistakes.
The Security Reality Nobody Discusses
Let me start with the most critical revelation: Now Assist experienced a severe security vulnerability that exposed fundamental weaknesses in how AI agents interact with enterprise systems. The vulnerability, tracked as CVE-2025-12420 and nicknamed "BodySnatcher," allowed unauthenticated attackers to impersonate any ServiceNow user using nothing more than an email address.
I need you to understand the gravity of this: attackers could bypass multi-factor authentication, single sign-on, and all other access controls. They could impersonate administrators, execute AI agents to override security controls, create backdoor accounts, and access sensitive data including Social Security numbers, healthcare information, and confidential intellectual property.

The vulnerability stemmed from two critical design flaws. First, ServiceNow deployed identical hardcoded shared secrets across all customer instances. Anyone obtaining this token could interact with the Virtual Agent API of any customer environment. Second, the account-linking logic required only an email address to link an external entity to a ServiceNow account.
While ServiceNow has patched these vulnerabilities, this incident reveals something most consultants won't tell you: AI agent security demands far more scrutiny than traditional application security. The stakes are higher, the attack surface is broader, and the potential for exploitation is unprecedented.
AI Agents Execute Without Channel Deployment
Here is a secret that fundamentally changes how you should approach Now Assist security: AI agents can be executed directly through the system without being deployed to a channel with explicitly enabled Now Assist features. This contradicts the general understanding many organizations operate under.
As long as an agent exists in an active state and the calling user possesses necessary permissions, it can be invoked directly. This means your security perimeter must extend far beyond what traditional consulting partners typically recommend. You cannot rely on channel-level controls alone: you need comprehensive role-based access controls, continuous monitoring, and strict agent lifecycle management.
I have witnessed organizations deploy Now Assist with inadequate security frameworks because their consulting partner failed to communicate this critical operational reality. The result? Unnecessary exposure and compliance risks that could have been entirely avoided.
The Licensing Trap Most Partners Won't Explain
Now Assist operates on consumption-based licensing using "assists" as units of measurement. ServiceNow grants customers fixed annual allotments, and once you exceed that threshold, additional fees apply. Here is what most consulting partners conveniently omit: ServiceNow maintains deliberate opacity around the pricing for these additional assists.

This creates an unpredictable cost structure that can dramatically impact your ROI calculations. I have reviewed countless implementations where organizations significantly underestimated their actual Now Assist costs because their consulting partner provided overly optimistic usage projections without accounting for organizational growth, seasonal fluctuations, or expanded use cases.
The reality is that consumption patterns are difficult to predict accurately, especially in the first 12-18 months of deployment. Your consulting partner should provide conservative estimates, implement robust usage monitoring, and establish clear governance frameworks to prevent runaway costs. If they are not having these conversations upfront, you are not receiving strategic guidance: you are receiving sales pitches.
Prompt Injection Vulnerabilities
Research has identified that default settings in Now Assist could enable second-order prompt injection attacks: a sophisticated exploit method that manipulates AI agents through data they process rather than direct user input. This represents a fundamentally different threat model than traditional application vulnerabilities.
Consider this scenario: an attacker embeds malicious instructions in a knowledge article, incident description, or configuration item. When an AI agent processes this data, it could be manipulated to execute unintended actions. Traditional security controls often fail to detect these attacks because they occur within the normal operational flow of the system.
Most consulting partners lack the specialized expertise to identify and mitigate these AI-specific vulnerabilities. They apply conventional security frameworks to AI agents and assume the work is complete. I can tell you from direct experience: this approach leaves critical gaps in your security posture.
The Implementation Complexity Partners Minimize
Here is the uncomfortable truth about Now Assist: successful implementation demands far more than technical configuration. It requires comprehensive change management, extensive training, continuous optimization, and ongoing governance. Many consulting partners minimize this complexity to close deals faster.

I have inherited countless Now Assist implementations that technically functioned but delivered minimal business value because the consulting partner focused exclusively on configuration while neglecting adoption strategies. Users didn't trust the AI recommendations. Business processes weren't optimized for AI-assisted workflows. Knowledge bases contained outdated or contradictory information that confused the AI agents.
The transformative potential of Now Assist only materializes when implementation extends beyond technical deployment into organizational transformation. Your consulting partner should be conducting stakeholder workshops, developing adoption roadmaps, establishing feedback mechanisms, and creating continuous improvement processes. If they view Now Assist as a configuration project rather than a transformation initiative, you will not achieve the outcomes you expect.
Version Dependencies and Upgrade Complexity
Now Assist AI Agents versions 5.0.24 through 5.1.17 and Virtual Agent API versions ≤3.15.1 and 4.0.0–4.0.3 were affected by the critical security vulnerabilities I discussed earlier. This highlights another reality partners often downplay: Now Assist creates complex version dependencies that impact your entire ServiceNow roadmap.
Upgrading Now Assist requires careful coordination with your broader ServiceNow instance upgrades. You cannot simply apply patches in isolation: you must consider compatibility with your ITSM, ITOM, HRSD, and other modules. This demands strategic foresight and meticulous planning that many consulting partners fail to provide.
What You Should Demand From Your ServiceNow Partner
Based on everything I have shared, here is what you should expect from a truly strategic ServiceNow consulting partner:
Transparent security assessments: Your partner should conduct comprehensive security reviews that address AI-specific vulnerabilities, including prompt injection risks, agent permission structures, and data access patterns.
Realistic cost projections: Demand consumption modeling based on conservative estimates, with clear governance frameworks to monitor and control usage.
Comprehensive change management: Implementation plans must address organizational adoption, not just technical configuration.
Ongoing optimization: Now Assist is not a set-it-and-forget-it solution. Your partner should provide continuous refinement based on usage analytics and user feedback.

Honest communication: Your partner should discuss limitations, risks, and complexities upfront rather than promising unrealistic outcomes to close deals.
The Path Forward
Now Assist represents unprecedented potential to elevate operational excellence through AI-driven automation. But realizing that potential requires far more than technical implementation: it demands strategic foresight, comprehensive security frameworks, realistic planning, and ongoing optimization.
I have guided organizations through transformative Now Assist implementations that delivered measurable ROI, enhanced user experiences, and strengthened security postures. The difference between success and disappointment comes down to one factor: working with a consulting partner who prioritizes your long-term success over short-term sales targets.
The secrets I have revealed today should not be secrets at all. They should be the foundation of every Now Assist conversation. If your current consulting partner has not discussed these realities with you, ask yourself: are they truly acting as your strategic advisor, or are they simply selling you a product?
At SnowGeek Solutions, we built our reputation on transparency, expertise, and unwavering commitment to client success. We do not hide complexities: we help you navigate them. We do not minimize challenges: we help you overcome them. And we do not promise unrealistic outcomes: we deliver measurable results through strategic implementation.
The ServiceNow ecosystem continues evolving at unprecedented velocity. Organizations that succeed are those that partner with consultants who provide honest guidance, comprehensive expertise, and strategic foresight. Everything else is just noise.

Comments