Domain Seperation | Managing the users on Global domain

vrnath
Tera Contributor

Hello All,

Appreciate your help on this.

Currently we are working on Domain separated instance. Where we are facing an issue with the users. Right now, we have a domain structure like this:

Global

|

Global/Company   (where Company we built all the blueprint and have access to all the data in global and all customer domains)

|

Global/Company/CustA && Global/Company/CustB

We are having the different support groups and users (Support people) are in Company. From there we already given access for users the visibility to see all the data in CustA & CustB (Eg: Reporting the incidents by the CustA & CustB can bee seen by the support group people based in Company). As we declared all the users in Company we dont want to create the users (support people) in Cust A and Cust B. We want to create some different groups for Cust A & Cus B and want to add these users (Support people) to that groups.

As we are using the AD and making the userID as email. So while to recreate the users also will be an issue with duplication.

The other thing we tried to make these users( support people) as global, but they are getting access to all the domains from the settings menu and as well as the data. (thought to write an access control on Domain table and only allow Admins with domain = global to be able to create/write and delete items on domain table. - is this one will work to not show the drop down of the domain menu in settings)

Thought to make the group as global but once the incident is created - change the domain to company and still the users is not populating.

How to make the users (support people) to be created under one domain and is there any way to utilize that users on other domains. As its a domain specific environment the records created in one domain cant be visible in other domain.

Please suggest me if you have any other alternative which i missed.

Thanks in advance!!

Raghu

17 REPLIES 17

simonw
Tera Expert

Hi Raghu,



I think you're asking is it possible to allow people in a child domain to see a sister domain?   If so, you can add the Visible Domains related list on a user or group field and grant users visibility of any other domains.   They won't see the domain picklist as they default to the domain they were created in but can access records in other domains you want to grant them access to



Kind regards,



Simon


Hi, you have an issue I run into often.


What I do is one of the following, depending on the scenario:


  1. Visibility domains: you can add certain users to have visibility into the "Company" domain, but this has its disadvantages, obviously, as they would see everything as if they were part of the Company domain.
  2. Create another "escalation" process: this can be achieved with a UI Action (button) for example, where the CustA user would just click on a UI Action form button that reads something like "Escalate".   This UI Action would then set the Assignment Group to the Company group.   After this you would need to have a process for your "Company" service desk to review and assign these, or you could also set a Round Robin auto-assignment feature.


Hope that helps.


Hi William,



Thanks for your reply,



for the first point, we tried sending the users to company domain, but the user is getting the access to other Customers also. So hope this one will not work.


for the second point, As the users (support people ) is not present under the Cust A & Cust B, So we created a group in global and assigned these users (support people) under the Company domain. We created an incident under cust A and assigned to the global group and again came back to the Company domain and tried to select the users - but the users are not getting populate when we are in the company domain also. We thought to make the group global instead of making the users global.



currently the issue is - As we are creating different groups under CustA and CustB (eg: Cust A Windows & Cust B Windows) for that groups i want to populate the users (support people) under the company (eg: company windows). So all the support people under windows groups will be same but the users (support people) will be there in different groups in different domains. So currently the users are located under Company. So how to bring that users to CustA & CustB (with out making the users global). we cant recreate the users under custA and CustB.



So we want to create the seperate groups for CustA & CustB and want to use the same users in all.



Appreciate your help



Thanks


Raghu


vrnath
Tera Contributor

Hi Simon,



Thanks for your valuable response,



We already given the visibility domain access to Custa & CustB to the users( support people) under the Company. So the users (Support people) under the company can view all the records under the CustA & CustB.



what we are facing is, As we are creating different groups under CustA and CustB (eg: Cust A Windows & Cust B Windows) for that groups i want to populate the users (support people) under the company (eg: company windows). So all the support people under windows groups will be same but the users (support people) will be there in different groups in different domains. So currently the users are located under Company. So how to bring that users to CustA & CustB (with out making the users global). we cant recreate the users under custA and CustB.



please let me know if you need any further information.



Thanks


Raghu