---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Exploring domain separation

# Exploring domain separation {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 Minuten Lesedauer

With domain separation you can separate data, processes, and administrative tasks into logically defined domains.{#c_DomainSeparation__domain-sep-desc}

Domain separation is best for those customers who:  
* Need to enforce absolute data segregation between business entities (data separation).
* Customize business process definitions and user interfaces for each domain (delegated administration).
* Maintain some global processes and global reporting in a single instance.
* Separate data between service providers, customers, partners, or sub-organizations.
* Have minor or moderate process differences among customers.
{#c_DomainSeparation__ul_jx2_qdh_1r}

## Domain separation compared to separate instances {#c_DomainSeparation__section_xsc_tlb_mz}

While domain separation provides multi-tenancy support, multi-tenancy is still contained
within a single instance. Some global properties, data, and processes are shared across all
domains. For example, having the system Remember me on the login page of the
system is global and cannot be specified per domain.

If you need complete and total separation of all system properties and do not require global
reporting or global processes, then separate instances are the best option.

## Data separation

Members of a domain see only the data contained within their domain or the child domains that
are lower in the domain hierarchy. By default, all users and all records are members of the
global domain unless an administrator assigns them to a particular domain. Once you assign a
user or a record to a domain, the instance compares the user's domain to the record's domain to
determine whether the user can view the record.

ServiceNow applications are defined with the following incremental support levels. These
levels are based on the perspective of actual use cases and personas.

Data Separation: Tenants see only data that they have permissions to
see. Tenants can be granted access to other tenant data, but cannot query tenant data if they
don't have access.

UI Separation: Supports a tenant-specific experience for UI elements
such as views, lists, labels, and so on.

Business Logic Separation: You can create tenant-specific system
policies such as email notifications, business rules, client scripts, UI policy, and UI
actions.

Hierarchical Modeling: Nested-multi-tenancy so parent tenants can
access child tenant resources. Business logic for parent tenants runs automatically for child
tenants, and can be overridden at any level.

Cross-Tenant Intelligence (Domain Scope): Handles automatically the
data, metadata, business logic, and processing context for tenants that have access to
additional tenant data.

In general, data defined at a higher level in the domain hierarchy is not visible at lower
levels in the hierarchy.

## Domain path migration

Domain paths are used for all customers. Domain numbering is not used. Customer Service and Support can assist in the upgrade.

## Alternatives to domain separation {#c_DomainSeparation__section_rjy_nqf_l1b}

Separate
instances are a common alternative to domain separation. This provides a great degree of
flexibility in meeting the requirements for customers and stakeholders with little to no impact
on others.  
Warnung:  
Before activating domain separation, consult your representative to verify that it is suitable for your environment. Domain separation adds a level of administration overhead. Although it can be disabled, it cannot be removed from an instance.
* **[Configuration that can be delegated to internal or external customers](https://servicenow-prod.fluidtopics.net/pOd6TVzcEYSOtU6NbkzLxw)**   
  Domain separation is designed to give ServiceNow® service providers (SPs) the ability to configure the services they offer to their customers. It is not designed to enable their customers to administer those services themselves, except in a few areas that this topic details.
* **[Domain assignment](https://servicenow-prod.fluidtopics.net/p8nHbzEnZXZJ~XFrPVR_Mg)**   
  By default, domain separation adds a domain field to tables and their extensions.
* **[Visibility domains and Contains domains](https://servicenow-prod.fluidtopics.net/5abdd86~QaxlGJI_IFH7TA)**   
  Visibility domains control what a specific user or group of users can see. "Contains" domains control what an entire domain of users can see.
* **[Domain scope](https://servicenow-prod.fluidtopics.net/K6SrKpNf2jlk8mqnnYF8Ag)**   
  Domain scope defines what users can and cannot access.
* **[Concepts for service providers](https://servicenow-prod.fluidtopics.net/_QM8GOzYXmovbRj65yC7hQ)**   
  These concepts work with the existing ServiceNow platform capabilities to help you solve for common use cases.
* **[Installed with domain separation](https://servicenow-prod.fluidtopics.net/36~JdKE54_AB1YemUw0W_w)**   
  Several platform components are added or modified with domain separation.

**Zugehörige Konzepte**   

* [Domain separation plugin](https://servicenow-prod.fluidtopics.net/~4fOBVP~xRs5Y2IWrcJzug "The Domain Support - Domain Extensions Installer plugin activates several domain separation features and properties at once. This plugin is typically referred to as the Domain Separation plugin.")  
**Zugehörige Verweise**   

* [Domain separation recommended practices for service providers](https://servicenow-prod.fluidtopics.net/PFPBfqQYeA_4Q9vVvFyyvw "You can create, implement, and maintain domain separation for your applications and services.")

