Product documentation Docs
    • English
    • Deutsch
    • 日本語
    • 한국어
    • Français
  • More Sites
    • Now Community
    • Developer Site
    • Knowledge Base
    • Product Information
    • ServiceNow.com
    • Training
    • Customer Success Center
    • ServiceNow Support Videos
  • Log in

Product documentation

  • Home
How search works:
  • Punctuation and capital letters are ignored
  • Special characters like underscores (_) are removed
  • Known synonyms are applied
  • The most relevant topics (based on weighting and matching to search terms) are listed first in search results
Topics are ranked in search results by how closely they match your search terms
  • A match on the entire phrase you typed
  • A match on part of the phrase you typed
  • A match on ALL of the terms in the phrase you typed
  • A match on ANY of the terms in the phrase you typed

Note: Matches in titles are always highly ranked.

  • Release version
    Table of Contents
    • IT Operations Management
Table of Contents
Choose your release version
    Home Orlando IT Operations Management IT Operations Management ITOM Optimization Cloud Management Cloud Management administration guide Domain separation in Cloud Management

    Domain separation in Cloud Management

    • Save as PDF Selected topic Topic & subtopics All topics in contents
    • Unsubscribe Log in to subscribe to topics and get notified when content changes.
    • Share this page

    Domain separation in Cloud Management

    An overview of domain separation in Cloud Management. With domain separation you can separate data, processes, and administrative tasks into logical groupings called domains. You can then control several aspects of this separation, including which users can see and access data.

    Support level: Basic

    • There is business logic to ensure data goes into the proper domain for the application’s service provider use cases.
    • In the application, the user interface, cache keys, reporting, rollups, aggregations, and so on, all consider domain at run time.
    • The owner of the instance needs to be able to set up the application to function normally across multiple tenants.
    Use case: As a service provider when I use chat to respond to a tenant-customer’s message, the client must be able to see my response.

    Overview

    Basic support targets tenant domain requester use cases in an application. The application has been designed to support requester activities within tenant domains. Logic is in place to route data to tenant domains, based on applicable use cases. The owner of the instance must be able to set up the application to function normally across multiple tenants. The application handles data routing to domains.

    Every table Cloud Management is not domain separated and delegated domain separation is not supported.

    Domain separation for Cloud Management is designed for:
    • Service Providers (SPs) using the application to provide data separation. In this scenario, SPs can provide data separation to multiple customers, where domains are necessary to contain all relevant customer data and processes. For example, an SP providing support to customers who typically use Cloud Management to manage their IT infrastructure on the cloud. SPs can use a single instance to manage cloud resources for multiple customers using a dedicated MID Server per customer. SPs can provide catalogs, template profiles, Resource Pools & filter, Resource profiles, Quotas, Permissions, IP Address Management (IPAM), Lease and Business hours scheduling, and a view to Billing, as domain separated offerings to their customers.

    How domain separation works in Cloud Management

    Domain separation for Cloud Management aligns one or more companies to a domain. To use domain separation with the application, assign all user accounts to a specific company associated with that domain.

    All entities that are related to the company, such as cloud accounts and service accounts, are created in the same domain as the company. When a new company is created, create a domain with a unique name and assign it to the company. All related entities for an account, such as contacts and cases, must reside in the same domain. When you create a related entity for a domain-separated account, the entity is assigned to the company domain.

    Members of a domain can only view the data that is contained within their domain or child domains that are lower in the domain hierarchy. By default, all users and all records are members of the global domain unless you assign them to a particular domain. Once you assign a user or a record to a domain, the instance compares the user's domain to the record's domain to determine whether the user can view the record.

    Service Providers (SPs) use domain separation to segregate data for each customer. Users in a given domain can only view the data in their own domains or in child domains. SPs typically control the top-level domain, which allows them to view data that is associated with all domains. Don't delegate administration to cloud admin users of the child domains in Cloud Management.

    Set up domain separation for Cloud Management

    Ensure that you activate the following plugins:
    Domain Support - Domain Extensions Installer plugin (com.glide.domain.msp_extensions.installer) to enable domain separation in Cloud Management
    Service Catalog - Domain Separation plugin (glideapp.servicecatalog.domain_separation) to enable separation of catalog items in different domains in Cloud Management

    Changes to Cloud Management tables

    Domain separation for Cloud Management adds the Domain and Domain Path fields to the list views. These fields are not exposed by default. As a domain admin you can customize lists and forms to view these fields. Not all tables in Cloud Management are domain separated. While some top-level tables are domain separated, several child tables are not domain separated. However, this does not impact how the Cloud Management application works in a domain-separated context.

    Account domains and related entities

    When you create related entities for an account, the domain for the related entities is set to the account domain.

    Domain visibility for cloud administrators and users

    Manually assign users with the Cloud User Portal (sn_cmp.cloud_service_user) roles and Cloud Admin Portal (sn_cmp.cmp_root_admin) roles for each domain to the TOP/MSP/Default/Company or leaf domain. Domain administrators and users in Cloud Management can only view data in the domain that they are created in, until they are assigned to the TOP domain. The Top domain represents a single common parent domain, which acts as a single parent node, for the Service Provider domains.

    Next Steps

    For more information on creating, implementing, and maintaining domain separation for Cloud Management services in the instance you are setting up for your customers, see Domain separation in Cloud Management - considerations for service providers.

    Related topics
    • Domain separation

    Tags:

    Feedback
    On this page

    Previous topic

    Next topic

    • Contact Us
    • Careers
    • Terms of Use
    • Privacy Statement
    • Sitemap
    • © ServiceNow. All rights reserved.

    Release version
    Choose your release version

      Domain separation in Cloud Management

      • Save as PDF Selected topic Topic & subtopics All topics in contents
      • Unsubscribe Log in to subscribe to topics and get notified when content changes.
      • Share this page

      Domain separation in Cloud Management

      An overview of domain separation in Cloud Management. With domain separation you can separate data, processes, and administrative tasks into logical groupings called domains. You can then control several aspects of this separation, including which users can see and access data.

      Support level: Basic

      • There is business logic to ensure data goes into the proper domain for the application’s service provider use cases.
      • In the application, the user interface, cache keys, reporting, rollups, aggregations, and so on, all consider domain at run time.
      • The owner of the instance needs to be able to set up the application to function normally across multiple tenants.
      Use case: As a service provider when I use chat to respond to a tenant-customer’s message, the client must be able to see my response.

      Overview

      Basic support targets tenant domain requester use cases in an application. The application has been designed to support requester activities within tenant domains. Logic is in place to route data to tenant domains, based on applicable use cases. The owner of the instance must be able to set up the application to function normally across multiple tenants. The application handles data routing to domains.

      Every table Cloud Management is not domain separated and delegated domain separation is not supported.

      Domain separation for Cloud Management is designed for:
      • Service Providers (SPs) using the application to provide data separation. In this scenario, SPs can provide data separation to multiple customers, where domains are necessary to contain all relevant customer data and processes. For example, an SP providing support to customers who typically use Cloud Management to manage their IT infrastructure on the cloud. SPs can use a single instance to manage cloud resources for multiple customers using a dedicated MID Server per customer. SPs can provide catalogs, template profiles, Resource Pools & filter, Resource profiles, Quotas, Permissions, IP Address Management (IPAM), Lease and Business hours scheduling, and a view to Billing, as domain separated offerings to their customers.

      How domain separation works in Cloud Management

      Domain separation for Cloud Management aligns one or more companies to a domain. To use domain separation with the application, assign all user accounts to a specific company associated with that domain.

      All entities that are related to the company, such as cloud accounts and service accounts, are created in the same domain as the company. When a new company is created, create a domain with a unique name and assign it to the company. All related entities for an account, such as contacts and cases, must reside in the same domain. When you create a related entity for a domain-separated account, the entity is assigned to the company domain.

      Members of a domain can only view the data that is contained within their domain or child domains that are lower in the domain hierarchy. By default, all users and all records are members of the global domain unless you assign them to a particular domain. Once you assign a user or a record to a domain, the instance compares the user's domain to the record's domain to determine whether the user can view the record.

      Service Providers (SPs) use domain separation to segregate data for each customer. Users in a given domain can only view the data in their own domains or in child domains. SPs typically control the top-level domain, which allows them to view data that is associated with all domains. Don't delegate administration to cloud admin users of the child domains in Cloud Management.

      Set up domain separation for Cloud Management

      Ensure that you activate the following plugins:
      Domain Support - Domain Extensions Installer plugin (com.glide.domain.msp_extensions.installer) to enable domain separation in Cloud Management
      Service Catalog - Domain Separation plugin (glideapp.servicecatalog.domain_separation) to enable separation of catalog items in different domains in Cloud Management

      Changes to Cloud Management tables

      Domain separation for Cloud Management adds the Domain and Domain Path fields to the list views. These fields are not exposed by default. As a domain admin you can customize lists and forms to view these fields. Not all tables in Cloud Management are domain separated. While some top-level tables are domain separated, several child tables are not domain separated. However, this does not impact how the Cloud Management application works in a domain-separated context.

      Account domains and related entities

      When you create related entities for an account, the domain for the related entities is set to the account domain.

      Domain visibility for cloud administrators and users

      Manually assign users with the Cloud User Portal (sn_cmp.cloud_service_user) roles and Cloud Admin Portal (sn_cmp.cmp_root_admin) roles for each domain to the TOP/MSP/Default/Company or leaf domain. Domain administrators and users in Cloud Management can only view data in the domain that they are created in, until they are assigned to the TOP domain. The Top domain represents a single common parent domain, which acts as a single parent node, for the Service Provider domains.

      Next Steps

      For more information on creating, implementing, and maintaining domain separation for Cloud Management services in the instance you are setting up for your customers, see Domain separation in Cloud Management - considerations for service providers.

      Related topics
      • Domain separation

      Tags:

      Feedback

          Share this page

          Got it! Feel free to add a comment
          To share your product suggestions, visit the Idea Portal.
          Please let us know how to improve this content

          Check any that apply

          To share your product suggestions, visit the Idea Portal.
          Confirm

          We were unable to find "Coaching" in Jakarta. Would you like to search instead?

          No Yes
          • Contact Us
          • Careers
          • Terms of Use
          • Privacy Statement
          • Sitemap
          • © ServiceNow. All rights reserved.

          Subscribe Subscribed Unsubscribe Last updated: Tags: January February March April May June July August September October November December No Results Found Versions Search preferences successfully updated My release version successfully updated My release version successfully deleted An error has occurred. Please try again later. You have been unsubscribed from all topics. You are now subscribed to and will receive notifications if any changes are made to this page. You have been unsubscribed from this content Thank you for your feedback. Form temporarily unavailable. Please try again or contact  docfeedback@servicenow.com  to submit your comments. The topic you requested does not exist in the release. You were redirected to a related topic instead. The available release versions for this topic are listed There is no specific version for this documentation. Explore products Click to go to the page. Release notes and upgrades Click to open the dropdown menu. Delete Remove No selected version Reset This field is required You are already subscribed to this topic Attach screenshot The file you uploaded exceeds the allowed file size of 20MB. Please try again with a smaller file. Please complete the reCAPTCHA step to attach a screenshot
          Log in to personalize your search results and subscribe to topics
          No, thanks Login