---
sourceDocument: Brazil Enable AI
sourceDocumentLink: https://www.servicenow.com/docs/r/intelligent-experiences

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil Enable AI

ft:clusterId :

    - platai

bundleId :

    - platai

workflow :

    - Platform


---

# Domain separation

# Domain separation in AI Agent Studio {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Domain separation in AI Agent Studio

Domain separation in AI Agent Studio allows ServiceNow customers to logically segment data, processes, and administrative tasks into distinct domains.
This separation controls access and visibility, ensuring that users only interact with data and configurations relevant to their assigned domain.
It enhances data protection by applying domain separation at both design time and run time for AI agents.
Show full answer Show less  

## Design-time Support

At design time, domain separation applies when creating or updating AI agents, workflows, tools, and triggers. Administrators can assign specific domains to these configuration records. Access to AI agent table records is granted only if the user belongs to the same or a higher domain than the record, preserving domain boundaries.

## Run-time Support

During run time, domain separation governs agentic conversations initiated via the ServiceNow Otto panel, web client, or other conversational channels. The AI agent impersonates a user whose domain determines which configurations are accessible. The domain visibility is resolved based on the "Run as" attribute in the agentic workflow trigger, ensuring conversations adhere to domain restrictions dynamically.

## Technical Details

* The **sysdomain** field is added to all AI agent tables to enforce domain separation.
* The **sysdomainpath** feature must be enabled on the instance for domain separation functionality.
* Process separation is enabled via the **sysoverrides** column in domain-aware tables, allowing different processes per domain.
* Only configuration tables support process separation, specifically **snaiaagentconfig** and **snaiausecaseconfigoverride**.

## Key Capabilities

* Agentic workflows and AI agents can be active in one domain while inactive in another, enabling domain-specific activation.
* Memory categories and triggers can be overridden or disabled per domain.
* Some properties (snaiaproperty) can be domain-specific and overridden accordingly.
* AI agent and agentic workflow details themselves cannot be overridden across domains.

## Practical Implications for ServiceNow Customers

Implementing domain separation in AI Agent Studio helps organizations maintain strict data and process isolation across departments, regions, or business units. Customers can confidently deploy AI agents knowing that domain boundaries prevent unauthorized data access and ensure compliance with organizational policies. Administrators have granular control over AI agent configurations and runtime behavior within their domains, resulting in secure and tailored AI agent deployments.  
Domain separation is supported for AI agents in the AI Agent Studio. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.

## Domain Separation Overview {#aia-studio-domain-separation__section_ity_lyh_cfc}

AI agents use basic domain separation capabilities to help protect your users' data. Domain separation support for AI agents is applied at design time and run time.  

Design-time support
:   Refers to creating or updating agentic workflows, agents, tools, trigger configurations, and so on. AI agent configurations can be made domain-specific for individual agents and the actual agentic workflows. Administrators
    can apply specific domains to those records. Similar to other basic domain separations, records in the AI agents tables are accessible if the user belongs to the same or a higher domain than those records.

Run-time support
:   Refers to the agentic conversation on the ServiceNow Otto panel, web client, or any conversational channel. In the agentic conversations, the user that the agent impersonates functions as an agent with any AI agents who initiate the conversation on
    demand. For example, if the conversation is happening via a trigger mentioned on the Run as field on the Trigger form of an agentic workflow. If the user that the agent impersonates belongs to the same or
    a higher domain, that agent can access and use configurations that are associated with that domain.

    The domain visibility for an agentic workflow is resolved during run time based on the Run as
    attribute in the agentic workflow trigger condition. For more information, see [defining a trigger for an agentic workflow](https://www.servicenow.com/docs/fUhvQODnzcgoSYwnGQFX0Q "Create an agentic workflow in AI Agent Studio so that AI agents can coordinate to solve complex problems.").

When an agentic conversation is triggered on demand, the domain visibility is applied to the particular agent in action. When an agentic conversation is initiated through a trigger, the domain visibility is applied to the user who
resolves the caller (in an incident record where the Run as attribute is set to Caller), when the conversation runs against the incident record.  
Note:  
The sys_domain field is added to all AI agent tables to achieve domain separation in AI Agent Studio. The sys_domain_path, which is available for domain separation, is enabled on your instance.

To understand more about the ServiceNow domain separation, see [Exploring domain separation](https://www.servicenow.com/docs/access?context=c_DomainSeparation&version=brazil&pubname=brazil-platform-security&ft:locale=en-US).

## How domain separation works in AI Agent Studio {#aia-studio-domain-separation__section_jty_lyh_cfc}

Process separation is enabled through the use of the sys_overrides column in domain-aware tables. Any table that contains both the sys_domain and the sys_overrides fields can be configured to have different processes from the
parent domain.  
AI Agents support only configuration tables to be process separated. Below are the list of tables that are process separated:

* sn_aia_agent_config
* sn_aia_usecase_config_override
{#aia-studio-domain-separation__ul_bf2_dhp_cfc}  
Domain separation in AI agents supports:

* Agentic workflow discovery.
* AI agent and its tools can be active in the X domain and inactive in the Y domain.
* Memory category can be active in the X domain and inactive in the Y domain.
* sn_aia_property can be overridden in a different domain.
* Triggers can be overridden in different domain.

{#aia-studio-domain-separation__ul_dxn_nhp_cfc}  
Note:  
AI agent and agentic workflow details can't be overridden in the different domains.
**Related topics**   

* [Domain separation for service providers](https://www.servicenow.com/docs/access?context=domain-sep-landing-page&version=brazil&pubname=brazil-platform-security&ft:locale=en-US)

