---
sourceDocument: Zurich Enable AI
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/intelligent-experiences

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich Enable AI

ft:clusterId :

    - platai

bundleId :

    - platai

workflow :

    - Platform


---

# Domain separation

# Domain separation in AI Agent Studio {#ariaid-title1}

Release version: Zurich  
Updated July 31, 2025  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Domain separation in AI Agent Studio

Domain separation in AI Agent Studio, available from the Zurich release, allows ServiceNow customers to logically segregate data, processes, and administrative tasks into distinct domains.
This segregation ensures that users only see and access data relevant to their assigned domain, enhancing data security and operational clarity within AI agents and workflows.
Show full answer Show less  
Domain separation applies at two levels:

* **Design-time:** Controls domain-specific configurations such as agentic workflows, agents, tools, and triggers. Administrators assign domains to these AI agent records, restricting access based on user domain hierarchy.
* **Run-time:** Governs conversations initiated by AI agents on various interfaces like the ServiceNow Otto panel or web client. The domain visibility during conversations is determined by the user that the agent impersonates and the Run as attribute in the agentic workflow trigger.

## How It Works

Domain separation is implemented by adding the **sysdomain** field to all AI agent tables and enabling **sysdomainpath** on the instance. Process separation is supported through the **sysoverrides** column on domain-aware configuration tables, allowing different domains to override configurations independently.

The key configuration tables supporting process separation include:

* **snaiaagentconfig**
* **snaiausecaseconfigoverride**

## Key Capabilities

* Enable or disable AI agents and their tools per domain, allowing active configurations in one domain and inactive in another.
* Control memory categories per domain.
* Override properties (**snaiaproperty**) and triggers in different domains for tailored behavior.
* Note that AI agent core details and agentic workflows themselves cannot be overridden across domains.

## Practical Benefits for ServiceNow Customers

This domain separation enables customers to:

* Maintain strict data and configuration isolation between different business units or clients.
* Apply fine-grained access control to AI agent data and workflows, aligning with organizational security policies.
* Customize AI agent behavior and triggers per domain without impacting other domains.
* Ensure that AI agent conversations respect domain visibility rules dynamically during runtime, reinforcing secure and compliant interactions.  
Domain separation is supported for Now AssistAI Agent Studio. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.

## Domain Separation Overview {#aia-studio-domain-separation__section_ity_lyh_cfc}

AI agents use basic domain separation capabilities to help protect your users' data. Domain separation support for AI agents is applied at design time and run time.  

Design-time support
:   Refers to creating or updating agentic workflows, agents, tools, trigger configurations, and so on. AI agent configurations can be made domain-specific for individual agents and the actual agentic workflows. Administrators
    can apply specific domains to those records. Similar to other basic domain separations, records in the AI agents tables are accessible if the user belongs to the same or a higher domain than those records.

Run-time support
:   Refers to the agentic conversation on the ServiceNow Otto panel, web client, or any conversational channel. In the agentic conversations, the user that the agent impersonates functions as an agent with any AI agents who initiate the conversation on
    demand. For example, if the conversation is happening via a trigger mentioned on the Run as field on the Trigger form of an agentic workflow. If the user that the agent impersonates belongs to the same or
    a higher domain, that agent can access and use configurations that are associated with that domain.

    The domain visibility for an agentic workflow is resolved during run time based on the Run as
    attribute in the agentic workflow trigger condition. For more information, see [defining a trigger for an agentic workflow](https://www.servicenow.com/docs/KERnILnT9UhCfhg_3K6QBw "Create an agentic workflow in AI Agent Studio so that AI agents can coordinate to solve complex problems.").

When an agentic conversation is triggered on demand, the domain visibility is applied to the particular agent in action. When an agentic conversation is initiated through a trigger, the domain visibility is applied to the user who
resolves the caller (in an incident record where the Run as attribute is set to Caller), when the conversation runs against the incident record.  
Note:  
The sys_domain field is added to all AI agent tables to achieve domain separation in AI Agent Studio. The sys_domain_path, which is available for domain separation, is enabled on your instance.

To understand more about the ServiceNow domain separation, see [Exploring domain separation](https://www.servicenow.com/docs/access?context=c_DomainSeparation&version=zurich&pubname=zurich-platform-security&ft:locale=en-US).

## How domain separation works in AI Agent Studio {#aia-studio-domain-separation__section_jty_lyh_cfc}

Process separation is enabled through the use of the sys_overrides column in domain-aware tables. Any table that contains both the sys_domain and the sys_overrides fields can be configured to have different processes from the
parent domain.  
AI Agents support only configuration tables to be process separated. Below are the list of tables that are process separated:

* sn_aia_agent_config
* sn_aia_usecase_config_override
{#aia-studio-domain-separation__ul_bf2_dhp_cfc}  
Domain separation in AI agents supports:

* Agentic workflow discovery.
* AI agent and its tools can be active in the X domain and inactive in the Y domain.
* Memory category can be active in the X domain and inactive in the Y domain.
* sn_aia_property can be overridden in a different domain.
* Triggers can be overridden in different domain.

{#aia-studio-domain-separation__ul_dxn_nhp_cfc}  
Note:  
AI agent and agentic workflow details can't be overridden in the different domains.
**Related topics**   

* [Domain separation for service providers](https://www.servicenow.com/docs/access?context=domain-sep-landing-page&version=zurich&pubname=zurich-platform-security&ft:locale=en-US)

