---
sourceDocument: Brazil Platform security
sourceDocumentLink: https://www.servicenow.com/docs/r/platform-security

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Exploring domain separation

# Exploring domain separation {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Exploring domain separation

Domain separation in ServiceNow allows customers to logically separate data, processes, and administrative tasks into distinct domains within a single instance.
It is ideal for organizations that require strict data segregation between business entities, need to customize processes and user interfaces per domain, maintain some global processes and reporting, or separate data between service providers, customers, partners, or sub-organizations.
Show full answer Show less  
Domain separation supports multi-tenancy within one instance, sharing some global properties and processes, unlike completely separate instances which offer total separation without shared global reporting or processes.

## Key Features

* **Data separation:** Users can only see data within their domain or child domains, ensuring strict access control. By default, all users and records belong to the global domain until assigned otherwise.
* **Incremental support levels:** Including data separation, UI separation (tenant-specific UI elements), business logic separation (tenant-specific policies and scripts), hierarchical modeling (nested multi-tenancy with parent-child domain access), and cross-tenant intelligence (handling data and processing for tenants with additional access).
* **Domain assignment:** Domains are assigned via a domain field added to tables and their extensions, controlling visibility and access.
* **Delegated configuration:** Enables service providers to configure services for their customers, though full administration by customers is limited to specific areas.
* **Domain scope:** Defines what users in each domain can access, supporting fine-grained control over data and functionality.

## Key Outcomes

By using domain separation, ServiceNow customers can:

* Enforce absolute data segregation while still benefiting from shared global processes and reporting.
* Customize business processes, policies, and user interfaces per domain to meet diverse organizational needs.
* Support hierarchical domain models allowing parent domains to access child domain data and override business logic as needed.
* Maintain a single instance environment while logically isolating tenants or business units for security and compliance.

However, customers should be aware that domain separation introduces additional administration overhead and cannot be fully removed once activated. Consultation with a ServiceNow representative is recommended to ensure domain separation fits the environment and requirements.  
With domain separation you can separate data, processes, and administrative tasks into logically defined domains.{#c_DomainSeparation__domain-sep-desc}

Domain separation is best for those customers who:  
* Need to enforce absolute data segregation between business entities (data separation).
* Customize business process definitions and user interfaces for each domain (delegated administration).
* Maintain some global processes and global reporting in a single instance.
* Separate data between service providers, customers, partners, or sub-organizations.
* Have minor or moderate process differences among customers.
{#c_DomainSeparation__ul_jx2_qdh_1r}

## Domain separation compared to separate instances {#c_DomainSeparation__section_xsc_tlb_mz}

While domain separation provides multi-tenancy support, multi-tenancy is still contained
within a single instance. Some global properties, data, and processes are shared across all
domains. For example, having the system Remember me on the login page of the
system is global and cannot be specified per domain.

If you need complete and total separation of all system properties and do not require global
reporting or global processes, then separate instances are the best option.

## Data separation

Members of a domain see only the data contained within their domain or the child domains that
are lower in the domain hierarchy. By default, all users and all records are members of the
global domain unless an administrator assigns them to a particular domain. Once you assign a
user or a record to a domain, the instance compares the user's domain to the record's domain to
determine whether the user can view the record.

ServiceNow applications are defined with the following incremental support levels. These
levels are based on the perspective of actual use cases and personas.

Data Separation: Tenants see only data that they have permissions to
see. Tenants can be granted access to other tenant data, but cannot query tenant data if they
don't have access.

UI Separation: Supports a tenant-specific experience for UI elements
such as views, lists, labels, and so on.

Business Logic Separation: You can create tenant-specific system
policies such as email notifications, business rules, client scripts, UI policy, and UI
actions.

Hierarchical Modeling: Nested-multi-tenancy so parent tenants can
access child tenant resources. Business logic for parent tenants runs automatically for child
tenants, and can be overridden at any level.

Cross-Tenant Intelligence (Domain Scope): Handles automatically the
data, metadata, business logic, and processing context for tenants that have access to
additional tenant data.

In general, data defined at a higher level in the domain hierarchy is not visible at lower
levels in the hierarchy.

## Domain path migration

Domain paths are used for all customers. Domain numbering is not used. Customer Service and Support can assist in the upgrade.

## Alternatives to domain separation {#c_DomainSeparation__section_rjy_nqf_l1b}

Separate
instances are a common alternative to domain separation. This provides a great degree of
flexibility in meeting the requirements for customers and stakeholders with little to no impact
on others.  
Warning:  
Before activating domain separation, consult your representative to verify that it is suitable for your environment. Domain separation adds a level of administration overhead. Although it can be disabled, it cannot be removed from an instance.
* **[Configuration that can be delegated to internal or external customers](https://www.servicenow.com/docs/Mp8o~IR9AtSIl~_kTGUiBA)**   
  Domain separation is designed to give ServiceNow® service providers (SPs) the ability to configure the services they offer to their customers. It is not designed to enable their customers to administer those services themselves, except in a few areas that this topic details.
* **[Domain assignment](https://www.servicenow.com/docs/J66J2mxUsC2s95mCkolidQ)**   
  By default, domain separation adds a domain field to tables and their extensions.
* **[Visibility domains and Contains domains](https://www.servicenow.com/docs/UnR3ZJZLsyXqWaCTa4g4sQ)**   
  Visibility domains control what a specific user or group of users can see. "Contains" domains control what an entire domain of users can see.
* **[Domain scope](https://www.servicenow.com/docs/Kuj5zJfU1CDvkRARgusZtw)**   
  Domain scope defines what users can and cannot access.
* **[Concepts for service providers](https://www.servicenow.com/docs/IYy0bbVZtzPNgbE9vncLxA)**   
  These concepts work with the existing ServiceNow platform capabilities to help you solve for common use cases.
* **[Installed with domain separation](https://www.servicenow.com/docs/pxc3Zy8HzF0PHGAfucU3hA)**   
  Several platform components are added or modified with domain separation.

**Related concepts**   

* [Domain separation plugin](https://www.servicenow.com/docs/kEbEgMZ06OhRXIuyvPRkcQ "The Domain Support - Domain Extensions Installer plugin activates several domain separation features and properties at once. This plugin is typically referred to as the Domain Separation plugin.")  
**Related reference**   

* [Domain separation recommended practices for service providers](https://www.servicenow.com/docs/EUZvVtuMANy7DLwscS5fsg "You can create, implement, and maintain domain separation for your applications and services.")

