Domain separation and Knowledge Management
Summarize
Summary of Domain separation and Knowledge Management
Domain separation in ServiceNow Knowledge Management allows you to logically partition data, processes, and administrative tasks into distinct domains. This ensures data visibility, user access, and administrative functions are isolated per domain, supporting multi-tenant environments such as service providers managing multiple customers within a single instance.
Show less
This separation applies to knowledge bases, articles, categories, templates, and user feedback, controlling access at data, requester, and fulfiller levels. It helps enforce data privacy and operational boundaries between tenants.
How Domain Separation Works in Knowledge Management
- Data level: Knowledge data such as articles, templates, and feedback are domain separated, meaning data in one domain is not visible in others. For example, an article created in Domain A is only visible in Domain A if its template is also in Domain A.
- Requester access: Users can search, view, comment, and rate articles within their domain, any child domains, and global domains if they have read access granted through knowledge base settings and user criteria.
- Fulfiller access: Users can author and update articles within their domain, child domains, and global domains if contribute access is granted. Articles are saved in the user’s current domain by default.
- Editing global articles: Editing global domain articles is restricted unless a specific system property is enabled. Users can also switch domains to edit global articles.
- Versioning: Article versioning maintains domain consistency across related tables, ensuring the latest version's domain is reflected in associated data.
- Domain containment: Users with access to a parent domain can author articles in its child domains by toggling domain scope.
Access Control Use Cases
Requester and fulfiller user access depends on their domain relative to the knowledge base and article domains:
- Requesters can interact with articles in their domain, relevant child domains, and global domains if allowed.
- Fulfillers can author, update, view, comment, and rate articles in similar domain scopes, depending on configured contribute permissions.
Key Considerations and Known Issues
- Some AQI tables related to article quality checklists are not domain separated, which might affect their use in multi-domain contexts.
- User comments on articles are stored in the article’s domain rather than the commenter’s domain.
Practical Impact for ServiceNow Customers
By using domain separation in Knowledge Management, you can securely manage multiple tenants or organizational units within a single ServiceNow instance. You gain precise control over who can see, contribute to, and manage knowledge articles, ensuring data isolation and compliance with internal or external data governance policies. Proper configuration of domains and access criteria is essential to achieve the desired separation and user experience.
Domain separation is supported in Knowledge Management. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.
Support level: Standard
- Includes all aspects of Basic level support.
- Application properties are domain-aware as needed.
- Business logic: The service provider (SP) creates or modifies processes per customer. The use cases reflect proper use of the application by multiple SP customers in a single instance.
- The instance owner must configure the minimum viable product (MVP) business logic and data parameters per tenant as expected for the specific application.
Sample use case: An Admin must be able to make comments required when a record closes for one tenant, but not for another.
For more information on support levels, see Application support for domain separation.
Overview of domain separation
Domain separation works differently at different access levels of an application. In Knowledge Management, data, requester, and fulfiller access to knowledge bases are domain separated.
How domain separation works in Knowledge Management
In Knowledge Management, the following rules apply:
Requester: Requester activities are supported within tenant domains. Users can search; view; comment; and rate articles of their domain, any child domain, and global domains, if feedback is enabled and the knowledge base settings grant them read access to articles.
- Users in the global domain can access articles in all the domains if read access is granted at knowledge base and/or article level.
- Users in the parent domain can access articles in that domain, global, and all its child domains if read access is granted at knowledge base and/or article level.
- Users in the child domain can access articles in that domain and the global domain if read access is granted at knowledge base and/or article level.
Fulfiller: The application can be used by the Fulfiller within the tenant domains as a tenant domain-owned application. Users are allowed to author articles in knowledge bases of their domain, any child domain, and the global domain if the knowledge base has user criteria set up to grant contribute access.
Articles are automatically saved to the user's current domain when the article is created.
- If the
glide.knowman.allow_edit_global_articlessystem property is enabled, users from a domain other than the global domain can check out and edit global articles. Otherwise, system administrators and users from a domain other than the global domain cannot check out global articles and are shown a warning message to that effect. Depending on their access, users can change their domain to the global domain to check out and edit the global articles. - Domains of versioned articles will be maintained as per the latest article version's domain. This includes updating the domain for kb_version, kb_knowledge, kb_feedback, and sys_attachment tables.
- If domains contain another domain: If Domain A contains Domain B, users with access to Domain A can author articles in Domain B by toggling the domain scope. To learn more about toggling domain scope, see Visibility domains and Contains domains.
See Managing access to knowledge bases and knowledge articles to learn how to control contribute and read access to knowledge bases and knowledge articles.
Requester use cases
| User domain | Knowledge base domain | Read user criteria domain | Article domain | Result |
|---|---|---|---|---|
| Global | Global | Global | Global | Can view, comment, rate articles. |
| Parent domain (TOP) | Parent domain (TOP) | Parent domain (TOP) | ||
| Child domain (TOP/ACME) | Child domain (TOP/ACME) | Child domain (TOP/ACME) | ||
| MSP domain (TOP/MSP) | MSP domain (TOP/MSP) | MSP domain (TOP/MSP) | ||
| Parent domain (TOP) | Global | Global | Global | |
| Parent domain (TOP) | Parent domain (TOP) | Parent domain (TOP) | ||
| Child domain (TOP/ACME) | Child domain (TOP/ACME) | Child domain (TOP/ACME) | ||
| MSP domain (TOP/MSP) | MSP domain (TOP/MSP) | MSP domain (TOP/MSP) | ||
| Child domain (TOP/ACME) | Global | Global | Global | Can view, comment, rate articles. |
| Parent domain (TOP) | Parent domain (TOP) | Parent domain (TOP) | ||
| Child domain (TOP/ACME) | Child domain (TOP/ACME) | Child domain (TOP/ACME) | ||
| MSP domain (TOP/MSP) | MSP domain (TOP/MSP) | MSP domain (TOP/MSP) |
Fulfiller use cases
| User domain | Knowledge base domain | Contribute user criteria domain | Article domain | Result |
|---|---|---|---|---|
| Global | Global | Global | Global | Can author, update, view, comment, rate articles. |
| Parent domain (TOP) | Parent domain (TOP) | Parent domain (TOP) | ||
| Child domain (TOP/ACME) | Child domain (TOP/ACME) | Child domain (TOP/ACME) | ||
| MSP domain (TOP/MSP) | MSP domain (TOP/MSP) | MSP domain (TOP/MSP) | ||
| Parent domain (TOP) | Global | Global | Global | |
| Parent domain (TOP) | Parent domain (TOP) | Parent domain (TOP) | ||
| Child domain (TOP/ACME) | Child domain (TOP/ACME) | Child domain (TOP/ACME) | ||
| MSP domain (TOP/MSP) | MSP domain (TOP/MSP) | MSP domain (TOP/MSP) | ||
| Child domain (TOP/ACME) | Global | Global | Global | Can author, update, view, comment, rate articles. |
| Parent domain (TOP) | Parent domain (TOP) | Parent domain (TOP) | ||
| Child domain (TOP/ACME) | Child domain (TOP/ACME) | Child domain (TOP/ACME) | ||
| MSP domain (TOP/MSP) | MSP domain (TOP/MSP) | MSP domain (TOP/MSP) |
Known Issues
- The following AQI tables are not domain separated:
- AQI Checklist [kb_quality_checklist]
- Checklist Question [kb_checklist_question]
- Article Checklist Answer [kb_article_checklist_answer]Note:The Article Checklist Answer table does not contain the Order field. The application shows the list in a random order.
- Comment provided by a user on an article is stored in article's domain instead of user domain.