What is Moveworks?
Moveworks is an enterprise AI assistant and agent platform designed for large organizations; it enables employees to search for internal knowledge using natural language, obtain personalized answers, and carry out tasks across various systems such as IT, HR, finance, and sales.
The platform consists of various functionalities such as AI Assistant, Enterprise Search, Agent Studio, Reasoning Engine, AI Agent Marketplace, Service Management, Knowledge Studio, and operational analytics.
ServiceNow completed the acquisition of Moveworks in December 2025. The Moveworks brand, platform, documentation, and sales channels remain in operation; its conversational AI and enterprise search capabilities are also used within ServiceNow EmployeeWorks.
Main functions
AI Assistant: A unified entry point for corporate tasks
- Natural language Q&A: Employees ask questions related to IT, HR, policies, benefits, procurement, or accounts, and the assistant retrieves and generates answers from trusted sources that are available.
- End-to-end operations: It not only provides explanations but also allows the use of plugins and workflows to create tickets, check status, request permissions, fill out forms, approve requests, or update business records.
- Personalized context: The Reasoning Engine determines the scope of searches and subsequent actions by taking into account the user’s identity, the conversation history, permissions, and available tools.
- Multiple rounds of processing: Complex requests can be broken down, planned, and executed; if necessary, the user can be asked for missing parameters or the task can be forwarded to a human team.
- Omni-channel experience: It can be deployed on web pages, messaging tools, browsers, intranets, service portals, and mobile devices, and it supports over 100 languages.
Enterprise Search: Enterprise search with permission controls
- Cross-system search: It is possible to index a wide range of enterprise data sources such as Slack, OneDrive, Google Drive, SharePoint, Confluence, Outlook, and more.
- Permission inheritance: Connectors that support permission retrieval mirror the access controls of the source system, ensuring that employees can only see the content to which they have access in the original system.
- Citation and location: The responses can be linked to the relevant knowledge materials that support the conclusions, enabling employees to go back to the original texts in order to verify policies, procedures, and dates of updates.
- Incremental updates: The connector synchronizes changes in content through polling, Webhooks, or an indexing mechanism; the actual freshness level is influenced by the data source, configurations, and synchronization interval.
- Custom content: Content Gateway allows customers to implement standard interfaces on their own servers, thereby providing the search system with content that is not natively supported as well as permissions for each file.
Agent Studio: Low-code and professional code development
- Agent design: Developers define tasks, inputs, data objects, steps, conditions, and outputs within a unified environment, while also taking advantage of the platform’s reasoning and security control mechanisms.
- Connectors: The system connectors are maintained by Moveworks; custom network connectors enable the configuration of the base address for business APIs, as well as authentication and credential reuse settings.
- Web actions: Use GET, POST, PUT, PATCH, and DELETE to read from or update external systems; they are suitable for querying orders, submitting requests, and triggering approvals.
- Authentication methods: Custom network connectors support Basic, API Key, Bearer, JWKS, and various OAuth 2.0 flows; it is also possible to connect to internal systems via a local agent.
- Testing and troubleshooting: API Playground allows testing of requests, parameters, responses, and errors on authorized connectors; however, it is still necessary to verify permissions, idempotency, and fallback mechanisms before going into production.
- MCP integration: The MCP service can be integrated as an agent tool; administrators should control the server identity, the available operations, and the scope of credentials.
AI Agent Marketplace
- Marketplace offers over 100 pre-built plugins for areas such as IT, HR, sales, and finance; they can be installed quickly using templates and customized to fit an organization’s needs.
- The plugin directory provides connections to ServiceNow, Workday, Salesforce, SAP, Jira, Okta, Slack, Microsoft 365, and numerous other systems.
- Pre-built solutions do not mean no configuration is required; the organization still needs to set up service accounts, define permissions, handle field mapping, carry out approval processes, and conduct security tests.
- The availability scope of plugins, the products they depend on, their versions, and licensing terms may vary; it is necessary to read the integration instructions for each template before installing it.
Service management, knowledge, and analysis
- Service Management: It allows for the routing of tasks and the creation of tickets, accelerates the approval process, helps locate forms, provides status updates, and forwards issues that cannot be resolved automatically to the service desk.
- Provision Management: Handles processes related to software access, distribution lists, as well as application submission, eligibility verification, approval, and configuration.
- Knowledge Studio: It assists support teams in identifying knowledge gaps, creating or maintaining knowledge articles, which must be verified by the content owner before being published.
- Employee Experience Insights: Analyzes employee needs, failed conversations, and high-friction processes to help project leaders determine automation priorities.
- Data API: It exports raw analysis data such as conversations, interactions, plugin calls, resources, and users, which can be used to create custom metrics, data lakes, and BI dashboards.
Typical inputs, outputs, and actions
| Task | Enter | Platform processing | Output or action |
|---|---|---|---|
| Corporate knowledge Q&A | Employee issues, identities, and accessible data sources | Permission-aware retrieval and generation | Answers, summary, and original content link |
| IT services | Fault description, device, and account context | Diagnosis, knowledge matching, and process routing | Resolution steps, tickets, or manual escalation |
| HR services | Benefits, leave, compensation, and policy issues | Retrieve the policy and invoke the HR system. | Personalized responses, applications, and status |
| Permission configuration | Software, roles, managers, and business reasons | Qualification assessment, approval, and connector actions | Records of access approvals, denials, or pending reviews |
| Financial processes | Costs, purchase orders, invoices, or contract requests | Cross-system queries and workflow execution | Data, approval tasks, or status updates |
| Operational analysis | Dialogue, interaction, click, and plugin data | Data API export and external ETL | Data warehouses, metrics, and BI reports |
Implementation and launch process
- Identify the initial departments, user groups, and common issues, and establish baselines for the automatic resolution rate, answer quality, task completion rate, escalation rate to human agents, and satisfaction level.
- Confirm the product portfolio, regions, contracts, implementation services, data processing agreements, and target systems with the Moveworks or ServiceNow teams.
- Synchronize user and group identities, configure single sign-on, administrator roles, PII viewing permissions, and service accounts, adhering to the principle of least privilege.
- Start by integrating a small number of high-quality knowledge sources, and verify one by one the file scope, permission inheritance, content freshness, as well as the policies regarding duplicates and outdated content.
- Install built-in plugins or create custom network connectors, configure authentication, fields, and actions, and test successful, failed, timed-out, and cancellation scenarios in the API Playground.
- Build agents in Agent Studio, and define input parameters, confirmation processes, approval procedures, safeguards for sensitive operations, manual intervention options, and audit requirements.
- Pilot testing is carried out using representative employees and multilingual scenarios to test situations such as incorrect permissions, prompt injection, lack of answers, conflicting policies, and unavailable external systems.
- Release in phases to the target channels, continuously analyze conversations and plugin calls, and expand the scope after fixing issues related to knowledge, connectors, and processes.
Prices and Purchases
| Package or version | Price | Billing cycle | Core benefits or quota | Suitable for users |
|---|---|---|---|---|
| Moveworks enterprise platform | Custom quote | Contractual agreement | AI Assistant, search functions, intelligent agents, connectors, and related corporate capabilities; the actual modules are determined based on the order. | Medium to large organizations |
| Implementation and professional services | Custom quote | As stipulated in the project or contract agreement | Architecture, connectors, migration, governance, training, and deployment support – the scope is as specified in the service details. | Complex or large-scale deployments |
| ServiceNow EmployeeWorks | Contact ServiceNow | Contractual agreement | Combining Moveworks’ conversational AI, enterprise search with ServiceNow’s portal and workflows | Companies that use the ServiceNow AI platform |
Moveworks does not disclose fixed pricing for specific packages, the minimum number of users required, or information regarding a free version or trial period. Quotations are provided based on factors such as the size of the organization, the modules used, integration needs, location, as well as service and contract requirements.
Public pages do not provide unified refund terms; business contracts typically cover issues such as go-live, renewal, SLAs, excess usage, professional services, and early termination. The purchaser should refer to the order, customer agreement, and data and security appendices.
Channels and Integration
| Category | Capabilities have been verified. | Key implementation points |
|---|---|---|
| Employee entrance | Websites, chats, browsers, intranets, portals, and mobile devices | Identity mapping, channel permissions, and consistent experience |
| Knowledge systems | SharePoint, OneDrive, Google Drive, Confluence, Slack, and others | Index range, ACL, freshness, and file format |
| Business system | ServiceNow, Workday, Salesforce, SAP, Jira, Okta, and others | Service accounts, action permissions, and approvals |
| Custom system | Custom network connectors, Content Gateway, other customer-hosted Gateways | Stable interfaces, authentication, pagination, rate limiting, and permission mapping |
| Agent tools | MCP and Marketplace plugins | Recipient server, tool description, write operations, and key isolation |
| Data and analysis | Events, Conversations, Data API, and Webhook Listeners | Regional endpoints, Bearer Tokens, rate limits, and data governance |
APIs and developer capabilities
- Moveworks offers REST APIs; the main categories include Events, Conversations, Data API, and Webhook Listeners. It also provides customer-hosted content, identity, knowledge, and form Gateways.
- APIs use Bearer Tokens, and each data center has its own distinct base endpoints; sending requests to the wrong location can result in authentication or routing errors.
- The Data API allows for the export of conversations, interactions, plugin calls, resources, and users. According to some documentation, the query window is 30 days, and the analysis data is updated on a basis of a 24-hour SLA.
- For the raw data provided by the Data API, customers need to set up their own ETL, storage, and BI systems; it cannot be used as a database for real-time business transactions.
- APIs have rate limits, though the specific values are not publicly disclosed; for large-scale usage, historical data processing, and higher limits, it is necessary to consult the support team.
- API Keys, connector credentials, and MCP keys should be stored in a server-side key management system, rotated regularly, and separated by product, environment, and write permissions.
GitHub and the open-source status
- The official GitHub organization makes available examples of Gateway, Data API, MCP Proxy Client, connector plugins, as well as projects for installing the local Agent.
- The licenses for different repositories vary; for example, Gateway and some clients use the MIT license, while the Data API example uses the Apache-2.0 license. It is necessary to follow the license file specific to each repository.
- Public repositories mainly contain examples, agents, connectors, or integration tools; they do not include the source code for Moveworks AI Assistant, the Reasoning Engine, or the full SaaS platform.
- Therefore, the Moveworks product itself is not open-source software; to use the available examples, enterprise tenants still need API credentials as well as an appropriate license for that product.
Security, permissions, and privacy
- The platform encrypts transmitted and static data, employs access controls, data minimization, and masking of sensitive PII; it is the customer who decides which data sources to connect to.
- Whether enterprise search can inherit the permissions of the source depends on the connector; content for which permission retrieval is not supported may be visible to all employees, and administrators must verify the connector settings before going live.
- Moveworks states that customer data is not used to train global generation models, and it employs various safeguards such as content moderation, fact-checking, prompt protection, risk assessment, and knowledge validation.
- The security page lists standards such as ISO 42001, ISO 27001, ISO 27017, ISO 27018, ISO 27701, SOC 2 Type 2, CSA STAR Level 2, FedRAMP, GDPR, and CCPA.
- The scope of certification and authorization varies depending on the region, cloud environment, and procurement module; it is necessary to obtain the current certificates, SOC reports, FedRAMP packages, as well as information regarding the applicable systems and data centers.
- RBAC distinguishes between roles such as administrators, users, super administrators, and PII Authorized Viewers; sensitive viewing permissions require separate approval and regular review.
- The Data API makes available employee statements, clicks, forms, plugins, and user data; once these data are exported, the customer is responsible for ensuring the security of the data lake, ETL processes, BI tools, and any downstream access to that data.
- The Privacy Policy was updated in December 2025; details regarding the retention and deletion of customer data, sub-processors, cross-border data transfers, and access rights are specified in the customer agreement and the data processing appendix.
Suitable for users and typical use cases
- Global large enterprises: Provide employees with a unified interface for communication across IT, HR, finance, and business systems.
- IT service team: Automatically resolves common issues, creates and routes tickets, and handles software and account configurations.
- HR and Employee Experience Team: Answers questions regarding policies and benefits, and handles matters related to leave, certifications, and onboarding processes.
- Platform engineering and automation team: Expand internal systems using Agent Studio, custom network connectors, MCP, and REST APIs.
- Knowledge Management Team: Integrates multiple content repositories, identifies knowledge gaps, and maintains trackable corporate answers.
- Organizations using ServiceNow: Assess the combination of the Moveworks standalone platform and EmployeeWorks, as well as the aspects related to migration and licensing.
Advantages and limitations
- Searching and executing are done within the same assistant, so employees do not need to remember multiple portals and entry points.
- A large number of ready-made plugins can reduce the time required for basic integration, but custom systems still require APIs, permissions, and operational capabilities.
- Permission-aware retrieval and enterprise security frameworks are suitable for regulated organizations, but an incorrect range of data sources or service accounts can still lead to unauthorized access.
- The Reasoning Engine continuously updates and optimizes the underlying models; companies cannot assume that a fixed version of a model will always yield reproducible results, nor can they choose any LLM at will.
- Public quotes are not sufficient for directly estimating the total cost; implementation, connectors, professional services, ServiceNow products, and internal governance efforts all need to be taken into account.
- AI responses and automated actions may be incorrect; operations related to accounts, finance, human resources, compliance, and deletion must include confirmation, approval, and the ability to revert changes.
- The acquisition of ServiceNow has been completed, but the specific integration of Moveworks and EmployeeWorks’ products, as well as the details regarding contracts and migration, shall be determined in accordance with the current sales plan.
Summary
Moveworks is suitable for large organizations that wish to integrate corporate search, employee support, and cross-system workflows into a governed AI assistant.
The key to a successful launch lies not only in the capabilities of the model, but also in identity and permissions, the quality of knowledge, the rights to develop connectors, the possibility of manual intervention, operational metrics, contract modules, and the boundaries of the ServiceNow product.
Guigong Network Security Registration No. 45132202000164