---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Domain scope

# Domain scope {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 Minuten Lesedauer

Domain scope defines what users can and cannot access.

Every user has two domain scopes when establishing a session in a domain-separated
instance.  
* Session scope is set upon session establishment to the domain listed in the user's user record. Users can manually change their session domain scope from the domain picker.
* Record scope uses the domain of the record and is active when viewing the form of any record.
{#c_DomainScope__ul_oj3_f3h_1r}

By default, the record scope takes precedence over the session scope so that users in higher
level domains adhere to each record's data and process constraints. However, these users can
choose to expand or collapse the domain scope to show or hide data from other domains. For
example, a user in the Service Provider (SP) domain also has visibility into child domains
such as the ACME domain. When looking at an incident record from the ACME domain, the user can
choose to expand the domain scope to show values from the SP domain or collapse the domain
scope to show only record values that match the record's ACME domain.  
Hinweis:  
Users always have access to data from domains that have been explicitly granted to them by domain visibility.

Users with the domain_expand_scope user role can select the domain scope from the
Toggle Domain Scope UI action on the form. When record scope is in
effect, click the UI action to expand to session scope and display all data available based to
the user's domain and child domains. When session scope is in effect, click the UI action to
collapse to record scope and display only data that matches the current record's domain.  
Hinweis:  
A record does not display the UI action to toggle the domain scope if the record is in the global domain or if the user's domain matches the record's domain.

## Record value selection from other domains {#c_DomainScope__section_hjn_gg4_2cb}

Users who can see multiple domains have the option to select record values from a domain that
is different than the record's domain.

For example, service desk agents working for a service provider might want to assign certain
incidents to themselves to resolve issues on behalf of their customers. When they do this,
the incident Assigned to field might contain a user from the SP
domain, even though the incident record itself is associated with a child domain such as
ACME.

Selecting a record value from another domain does not change the record's domain. The record
retains its original domain. When a user views a record with values from multiple domains, the
user's domain visibility determines what they see.  
{#c_DomainScope__table_lnm_z3h_1r__entry__2}

| When these conditions are met | The user has access to these UI elements |
|-|-|
| The user has access to the domain of the current record referenced in a field. | The user can: * See reference field display value. For example, sees the user name in the Assigned to field. * See the related record from reference icon. For example, sees the user record for the user in the Assigned to field. * Select values from any visible domain. For example, can select users from either the SP and ACME domains. {#c_DomainScope__ul_t45_cjh_1r} |
| The user does not have access to the domain of the current record referenced in a field. | The user can: * Not see reference field display values. (This is the case if domain separation was activated in Madrid or later releases and the user doesn't have access to the domain of that record.) * Only select values from the record's domain. For example, can only select users from the ACME domain. {#c_DomainScope__ul_ljf_djh_1r} |
[Tabelle : 1. Record value selection]

{#c_DomainScope__table_lnm_z3h_1r}

## Domains and associated companies {#c_DomainScope__section_kms_pg4_2cb}

With domain separation you can cascade changes you make to a company record to the domain
and other records associated to the company.

By default, the system automatically assigns users to the same domain as their company. For
example, all users of the ACME company automatically become members of the TOP/ACME
domain.  
Hinweis:  
Users with the admin role can change their own user records and therefore change domains. Service Providers may want to either disable delegated administration or set up an approval process to verify that the user needs the admin role.

When you change a company's domain, the instance automatically changes the domain of the
following associated records to match the company's new domain.  
* Locations
* Departments
* Groups
* Users
{#c_DomainScope__ul_vxh_kd4_1r}  
Hinweis:  
The instance does not automatically change the domain of any record where you have selected the Managed domain checkbox.

## Domain deactivation and associated companies {#c_DomainScope__section_erv_4h4_2cb}

When you deactivate a domain, the instance also automatically completes the following
actions.  
* Deactivates all companies in the domain.
* Prevents all users assigned to the inactive company from logging in.
{#c_DomainScope__ul_i3b_53c_mz}  
Hinweis:  
When a user from an inactive company attempts to log in, the user sees an error message similar to Company inactive - your access to this instance is not authorized.

For example, if you deactivate the ACME domain from the sample data, the instance also
deactivates the ACME company, and the three sample users are locked out.
**Zugehörige Konzepte**   

* [Configuration that can be delegated to internal or external customers](https://servicenow-prod.fluidtopics.net/pOd6TVzcEYSOtU6NbkzLxw "Domain separation is designed to give ServiceNow service providers (SPs) the ability to configure the services they offer to their customers. It is not designed to enable their customers to administer those services themselves, except in a few areas that this topic details.")
* [Domain assignment](https://servicenow-prod.fluidtopics.net/p8nHbzEnZXZJ~XFrPVR_Mg "By default, domain separation adds a domain field to tables and their extensions.")
* [Visibility domains and Contains domains](https://servicenow-prod.fluidtopics.net/5abdd86~QaxlGJI_IFH7TA "Visibility domains control what a specific user or group of users can see. \"Contains\" domains control what an entire domain of users can see.")
* [Concepts for service providers](https://servicenow-prod.fluidtopics.net/_QM8GOzYXmovbRj65yC7hQ "These concepts work with the existing ServiceNow platform capabilities to help you solve for common use cases.")  
**Zugehörige Verweise**   

* [Installed with domain separation](https://servicenow-prod.fluidtopics.net/36~JdKE54_AB1YemUw0W_w "Several platform components are added or modified with domain separation.")

