---
sourceDocument: Brazil Platform security
sourceDocumentLink: https://www.servicenow.com/docs/r/platform-security

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Visibility domains and Contains domains

# Visibility domains and Contains domains {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Visibility domains and Contains domains

Visibility domains and Contains domains are mechanisms in ServiceNow that control access to domain-specific data.
They determine what records users or groups can see across different domains, supporting data separation and security in multi-domain environments.
Show full answer Show less  

## Visibility domains

Visibility domains define explicit user-to-domain relationships that grant access rights to records within a specific domain and its child domains, based on ACL rules. These domains are associated with individual users or groups, and group membership grants users the group's visibility domains. When users leave a group, they lose those visibility rights. Visibility domains are not influenced by the domain picker and are not hierarchical child domains themselves.

**Key points:**

* Explicitly granted user or group to domain relationship.
* Grants access to data in the domain and its child domains.
* Not controlled by the domain picker selection.
* Best used sparingly; more robust control is achieved with contains domains.

## Contains domains

Contains domains establish many-to-many relationships between domains independently of the parent-child domain hierarchy. They control what an entire domain of users can see, allowing visibility into data from related domains and their children. The domain picker controls visibility for contains domains, enabling users to switch domain views dynamically.

**Key points:**

* Many-to-many domain-to-domain relationships.
* Visibility includes the selected domain and its children.
* Controlled by the domain picker, allowing users to change their visible domain scope.
* Contains domains affect data visibility only, not processes.

## Practical examples

* **Contains domain example:** A user with home domain A can see data from domains A, B, and C if A contains B and C. Switching the domain picker to B limits visibility to domain B data only.
* **Visibility domain example:** Users in separate domains (e.g., Database vs. Network) cannot see each other's records unless visibility domains are explicitly granted.

## Additional considerations

Users inherit visibility domains through group memberships if visibility is configured on the Group table, facilitating scalable access management. Excessive use of visibility domains is discouraged; contains domains provide more flexible and robust domain visibility control.  
Visibility domains control what a specific user or group of users can see. "Contains"
domains control what an entire domain of users can see.

## Visibility domains {#c_DomainVisibility__section_sb3_hk4_2cb}

The "Visibility domains" element determines whether users from one domain can access records
from another domain. Associate this element with User \[sys_user\] and Group \[sys_user_group\]
records in related lists on those records. Groups grant their members the visibility domains of
the group. When a user leaves a group, they lose the group's visibility domains. Granting users
a visibility domain grants all the rights to the records in that domain based on ACL (access
control list) rules.

A visibility domain:  
* Is a user-to-domain relationship and is explicitly granted.
* Is not a child domain.
* Is not controlled by the selection in the domain picker. Users with access to a visibility domain always see data in that domain and its child domains.
{#c_DomainVisibility__ul_ppq_c44_4s}  
Note:  
Using visibility domains excessively is not recommended. Although visibility is one method to allow users to access records, it's best to use contains domains for more robust control.

## Contains domains {#c_DomainVisibility__section_lxd_pk4_2cb}

Normally parent-child relationships define the domain hierarchy. A contains domain lets you
relate domains on an as-needed basis, independent of parent-child relationships. However,
contains domains grant visibility only to domain data. Processes remain unaffected by contains
relationships.

A contains domain:  
* Is a many-to-many, domain-to-domain relationship.
* May have child domains. When a domain is selected, you can see the data from that domain and its children.
* Is controlled by the selection in the domain picker.
{#c_DomainVisibility__ul_pr5_yj4_2cb}  
Note:  
When you open the domain record, the scope is set to that record's domain, so you can see only child domains. Choose Toggle Domain Scope from the menu to populate the related list.

## Contains domain example {#c_DomainVisibility__section_nqz_jt2_ybb}

When a user's home domain is A, and the A domain contains domains B and C, they all become
peer domains. That means the user sees data from domains A, B, and C while in their home domain
A. If users change domains with the domain picker to Domain B, they see only data in Domain B.
When users interact with a record from Domain B or Domain C directly, they see only data for
that domain.

## Visibility domain example {#c_DomainVisibility__section_xnr_kj2_ybb}

Using domain visibility, if Don Goodliffe is in the Database domain, and Bow Ruggeri is in the
Network domain, and no incidents are in the global domain, then Don cannot access Bow's
incidents because of data separation.

## Inheriting visibility domains based on group membership {#c_DomainVisibility__section_mbt_vl2_ybb}

If you set the domain table to the Group \[sys_user_group\] table, users can inherit visibility
domains based on their group membership.
**Related concepts**   

* [Configuration that can be delegated to internal or external customers](https://www.servicenow.com/docs/Mp8o~IR9AtSIl~_kTGUiBA "Domain separation is designed to give ServiceNow service providers (SPs) the ability to configure the services they offer to their customers. It is not designed to enable their customers to administer those services themselves, except in a few areas that this topic details.")
* [Domain assignment](https://www.servicenow.com/docs/J66J2mxUsC2s95mCkolidQ "By default, domain separation adds a domain field to tables and their extensions.")
* [Domain scope](https://www.servicenow.com/docs/Kuj5zJfU1CDvkRARgusZtw "Domain scope defines what users can and cannot access.")
* [Concepts for service providers](https://www.servicenow.com/docs/IYy0bbVZtzPNgbE9vncLxA "These concepts work with the existing ServiceNow platform capabilities to help you solve for common use cases.")
* [Contains queries and domain access](https://www.servicenow.com/docs/OYZHXyzGPq2iZHHECtgC~A "Use a \"contains\" query only in special cases, such as when users or groups need to see data from a domain that they don't have access to, but you don't want to move those users to a domain. Creating domain \"contains\" and user or group access for a domain should be an exception, only when absolutely needed.")  
**Related reference**   

* [Installed with domain separation](https://www.servicenow.com/docs/pxc3Zy8HzF0PHGAfucU3hA "Several platform components are added or modified with domain separation.")
* [Domain separation recommended practices for service providers](https://www.servicenow.com/docs/EUZvVtuMANy7DLwscS5fsg "You can create, implement, and maintain domain separation for your applications and services.")

