---
sourceDocument: Brazil Platform security
sourceDocumentLink: https://www.servicenow.com/docs/r/platform-security

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Domain assignment

# Domain assignment {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Domain assignment

Domain assignment in ServiceNow enables the separation and management of records by domain, improving data segregation in multi-tenant or multi-company environments.
By default, domain separation adds asysdomainfield to platform and baseline application tables, assigning each record to a specific domain.
This assignment can happen automatically based on user company, business rules, modules, or form templates.
Show full answer Show less  

## Key Features

* **Default domain separation:** Platform and baseline tables include the `sysdomain` field to identify record domains.
* **Domain assignment methods:**
  * Assign users to companies to automatically assign their domain.
  * Use business rules to set the `sysdomain` field on record creation.
  * Use modules with the `sysparmdomain` URL parameter to assign domains.
  * Use form templates with a preset `sysdomain` field value.
* **Domain inheritance:** Child records inherit the domain of their parent record (e.g., change tasks inherit from change requests).
* **Limitation on domain separation:** ServiceNow does not recommend domain separation for platform tables with the `sys` prefix (such as Dictionary Entry tables) due to potential unexpected results. Also, some tables like Access Control, Script Include, and System Property cannot be domain separated.

## Key Outcomes

* Records are properly segregated by domain, ensuring data isolation and compliance with organizational policies.
* Administrators can automate domain assignment, reducing manual effort and errors.
* Domain inheritance simplifies domain management for related records.
* Proper domain assignment supports multi-company and multi-tenant use cases effectively.

## Practical Considerations for ServiceNow Customers

* Ensure the `sysdomain` field is present on custom tables to enable domain separation.
* Avoid domain separating core platform tables to prevent unexpected behavior.
* Use user company assignments and business rules to automate domain assignment for new records.
* Leverage modules and form templates for consistent domain assignment in specific workflows.
* Understand domain inheritance to maintain consistent domain context across related records.  
By default, domain separation adds a domain field to tables and their
extensions.

You can also extend domain separation to any new tables you create by adding a
sys_domain field to the table's dictionary definition. By default, the
system only domain-separates platform and baseline application tables where appropriate.  
Warning:  
ServiceNow does not recommend domain-separating platform tables (any table with the sys_ prefix such as the Dictionary Entry \[sys_dictionary\] and Dictionary Entry Override \[sys_dictionary_override\] tables) because it can produce unexpected results.

Each record is assigned a single domain. That domain is stored in the sys_domain field. Several tables, by default, have the sys_domain column
and are already domain separated.  
The value of the sys_domain field contains the domain assigned to the record by any of the following:

* Company to which the user belongs
* Business rule when creating record
* Module used when creating record
* Form template used when creating record
* Domain of the parent record
* Domain assigned to User record
* Domain of the user who creates it
{#c_DomainAssignment__ul_yhy_r2h_1r}

The system prevents the following tables from being domain separated:

* Access Control `[sys_security_acl]`
* Script Include `[sys_script_include]`
* System Property `[sys_properties]`
* Security Exclusion/Inclusion List Entities `[sys_security_restricted_list]`
* Dictionary Entry `[sys_dictionary]`
* Dictionary Entry Override `[sys_dictionary_override]`

{#c_DomainAssignment__ul_srr_v2h_1r}

## Assigning users to companies

Administrators can quickly assign users to a domain by assigning them to a company. After
users are assigned to a domain, records automatically inherit the user's domain.

For example, assigning Bow Ruggeri to the ACME company automatically assigns him to the ACME
domain. Assigning Don Goodliffe to the Initech company automatically assigns him to the Initech
domain. Any records they create are automatically added to the appropriate domain.

## Using business rules to assign domains

Administrators can use a business rule to automatically set a domain value when creating a
record. The business rule must set a value in the sys_domain field.
Administrators must ensure there is a sys_domain column available for the
record's table. To learn more see [Domain separation recommended practices for service providers](https://www.servicenow.com/docs/EUZvVtuMANy7DLwscS5fsg "You can create, implement, and maintain domain separation for your applications and services.").

## Using modules to assign domains

Administrators can use the sysparm_domain URL parameter to
automatically assign new records to a particular domain from a module. Administrators must
create a module with an Argument value of: `sysparm_domain=sys_ID
of domain`.

## Using form templates to assign domains

Administrators can use a form template to automatically assign new records to a particular
domain. Administrators must add the sys_domain field to the form and
select a domain value. For example, setting the sys_domain field to
TOP/ACME domain automatically assigns all records from this template to
the TOP/ACME domain.

## Domain inheritance on tables

By default, related records inherit the domain of the parent record. For example:

* A change task record inherits the domain of the parent change request record.
* A problem record inherits the domain of the parent incident record.
{#c_DomainAssignment__ul_s52_jfh_1r}

## Automatic domain assignment based on user domains

If no other domain conditions apply, a record automatically inherits the domain of the user
who creates it.
**Related concepts**   

* [Configuration that can be delegated to internal or external customers](https://www.servicenow.com/docs/Mp8o~IR9AtSIl~_kTGUiBA "Domain separation is designed to give ServiceNow service providers (SPs) the ability to configure the services they offer to their customers. It is not designed to enable their customers to administer those services themselves, except in a few areas that this topic details.")
* [Visibility domains and Contains domains](https://www.servicenow.com/docs/UnR3ZJZLsyXqWaCTa4g4sQ "Visibility domains control what a specific user or group of users can see. \"Contains\" domains control what an entire domain of users can see.")
* [Domain scope](https://www.servicenow.com/docs/Kuj5zJfU1CDvkRARgusZtw "Domain scope defines what users can and cannot access.")
* [Concepts for service providers](https://www.servicenow.com/docs/IYy0bbVZtzPNgbE9vncLxA "These concepts work with the existing ServiceNow platform capabilities to help you solve for common use cases.")  
**Related reference**   

* [Installed with domain separation](https://www.servicenow.com/docs/pxc3Zy8HzF0PHGAfucU3hA "Several platform components are added or modified with domain separation.")

