Product documentation Docs
    • English
    • Deutsch
    • 日本語
    • 한국어
    • Français
  • More Sites
    • Now Community
    • Developer Site
    • Knowledge Base
    • Product Information
    • ServiceNow.com
    • Training
    • Customer Success Center
    • ServiceNow Support Videos
  • Log in

Product documentation

  • Home
How search works:
  • Punctuation and capital letters are ignored
  • Special characters like underscores (_) are removed
  • Known synonyms are applied
  • The most relevant topics (based on weighting and matching to search terms) are listed first in search results
Topics are ranked in search results by how closely they match your search terms
  • A match on the entire phrase you typed
  • A match on part of the phrase you typed
  • A match on ALL of the terms in the phrase you typed
  • A match on ANY of the terms in the phrase you typed

Note: Matches in titles are always highly ranked.

  • Release version
    Table of Contents
    • Security Operations
Table of Contents
Choose your release version
    Home Paris Security Incident Management Security Operations Trusted Security Circles Domain separation and Trusted Security Circle

    Domain separation and Trusted Security Circle

    • Save as PDF Selected topic Topic & subtopics All topics in contents
    • Unsubscribe Log in to subscribe to topics and get notified when content changes.
    • Share this page

    Domain separation and Trusted Security Circle

    This is an overview of domain separation in Trusted Security Circle. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can then control several aspects of this separation, including which users can see and access data.

    Support level: Standard

    • Includes Basic level support.
    • Business logic: Processes can be created or modified per customer by the service provider (SP). The use cases reflect proper use of the application by multiple SP customers in a single instance.
    • The owner of the instance needs to be able to configure the minimum viable product (MVP) business logic and data parameters per tenant as expected for the specific application.
    Use case: An admin needs to be able to make comments mandatory when a record closes for one tenant, but not for another.

    How domain separation works in Trusted Security Circle

    Domain separation enables service providers (SPs to standardize Trusted Security Circle procedures across the customer base they serve with lowered operational costs and a higher quality of service.

    Separate customer work spaces for workflows, dashboards, reports, and so forth ensures that customer data is separated and never exposed to other clients.

    Domain separation support in Trusted Security Circle by version releases

    Release Support level Notes
    Jakarta Level 2 (Data, Requestor, Fulfiller)
    Kingston Level 2 (Data, Requestor, Fulfiller)
    London All integrations reside across multiple domains.
    Madrid Level 2 (Data, Requestor, Fulfiller) All integrations reside across multiple domains.
    New York Level 2 (Data, Requestor, Fulfiller) All integrations reside across multiple domains.
    Orlando Standard All integrations reside across multiple domains.
    Paris Standard All integrations reside across multiple domains.

    Domain separation setup

    Setting up domain separation for Trusted Security Circle requires that you request domain separation, register the central instance for each domain, and configure the job queue.
    Important: If you are using domain separation, you must activate the Domain Support - Domain Extensions plugin before activating Trusted Security Circle. Several of the setup steps are also different for domain separation setup.
    Related topics
    • Domain separation for service providers

    Request domain separation

    All domain support features are activated with a plugin called Domain Support - Domain Extensions Installer. Administrators can request activation of this plugin.

    Before you begin

    To purchase a subscription, contact your ServiceNow account manager. The account manager can arrange to have the plugin activated on your organization's production and sub-production instances, generally within a few days.

    If you do not have an account manager, decide to delay activation after purchase, or want to evaluate the product on a sub-production instance without charge, follow these steps.

    Role required: admin

    About this task

    If the Domain Support - Domain Extensions Installer plugin is already active, content in the Domain Support - Domain Extensions Installer plugin will not be installed to avoid potential conflict with an existing implementation.

    Domain separation replaces Company Separation. Starting with the Helsinki release, the Company Separation plugin can no longer be activated. However, if company separation is already active when you activate domain separation, both plugins are active at the same time. You can control the company separation activation status with the glide.db.separation.field property.

    Note: Domain paths are used for all customers on Helsinki and later. Domain numbering is no longer used. ServiceNow Technical Support can assist in the upgrade.

    Procedure

    1. Navigate to System Applications > All Available Applications > All.
    2. On the All Applications page, click Request Plugin to open the request form on HI.
      Select to request a plugin from the All Applications page.
    3. On HI, select to be redirected to the HI Service Portal Service Catalog.
      HI redirect to Service Catalog
    4. On the Activate Plugin request form, fill in the fields.
      Field Description
      Target Instance Instance on which to activate the plugin.
      Plugin Name Name of the plugin to activate.
      Specify the date and time you would like this plugin to be enabled

      The date and time must be at least two business days from the current time.

      Note: Plugins are activated in two batches each business day in the Pacific time zone, once in the morning and once in the evening. If the plugin must be activated at a specific time, enter the request in the Reason/Comments field.
      Reason/Comments Information that would be helpful for the ServiceNow personnel who are activating the plugin. For example, if you need the plugin activated at a specific time instead of during one of the default activation windows, specify it in the comments.
    5. Click Submit.

    Result

    Activating the Domain Extension Installer plugin enables these features:
    • Domain separation is based on the Domain [sys_domain] table.
    • Delegated administration lets each domain have separate policy.
    • All records are part of the global domain.
    • The current user's domain determines the domain to use when viewing or operating on a record in a different domain.
    Related concepts
    • Domain separation plugin

    Register the Trusted Security Circles central instance for each domain

    If domain separation is not installed, registration to the global domain occurs automatically. If you have installed domain separation, manually register the Trusted Security Circle central instance for each of your domains.

    Before you begin

    If you are using the basic level of Trusted Security Circle, it is activated automatically when you activate Security Incident Response. Trusted Security Circles Client (Advanced) is available as a separate subscription.
    When domain separation is activated, two additional modules appear in the Trusted Security Circles navigation bar:
    • Job Queue Entries
    • Registration

    Role required: sn_tis_admin

    Procedure

    1. If it is not already activated, active the appropriate level of Trusted Security Circles.
    2. Navigate to Trusted Security Circles > Registration.
    3. From the Domain (Domain) drop-down list, select the domain you want to register to the Trusted Security Circles central instance.
    4. Click Register.
    5. You can verify that the domain registration completed successfully by navigating to Trusted Security Circles > Circles.

    Configure the job queue

    The job queue is used to execute scheduled jobs for getting messages from the central instance, processing records in the central instance, and refreshing records from central for your domain or for each of your domains (if you are using domain separation).

    Before you begin

    Role required: admin

    Procedure

    1. Navigate to Trusted Security Circles > Job Queue Entries.
    2. In the Job Queue Entries screen, click New.
    3. From the Domain (Domain) drop-down list, select the domain for which you want to configure the job queue.
    4. Fill in the fields as appropriate.
      Field Description
      Job Click the lookup icon and select the scheduled job executer you want to use for the selected domain.
      Last Run Displays the date and time when the job was last run. The oldest job will be the next one to run.
      Domain User Select the user in this domain who is identified as the person running this job.
    5. Click Submit.
    6. Repeat these steps as needed to select other jobs for this domain and for other domains (if you are using domain separation).
    Related concepts
    • Domain separation and Trusted Security Circle

    Tags:

    Feedback
    On this page

    Previous topic

    Next topic

    • Contact Us
    • Careers
    • Terms of Use
    • Privacy Statement
    • Sitemap
    • © ServiceNow. All rights reserved.

    Release version
    Choose your release version

      Domain separation and Trusted Security Circle

      • Save as PDF Selected topic Topic & subtopics All topics in contents
      • Unsubscribe Log in to subscribe to topics and get notified when content changes.
      • Share this page

      Domain separation and Trusted Security Circle

      This is an overview of domain separation in Trusted Security Circle. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can then control several aspects of this separation, including which users can see and access data.

      Support level: Standard

      • Includes Basic level support.
      • Business logic: Processes can be created or modified per customer by the service provider (SP). The use cases reflect proper use of the application by multiple SP customers in a single instance.
      • The owner of the instance needs to be able to configure the minimum viable product (MVP) business logic and data parameters per tenant as expected for the specific application.
      Use case: An admin needs to be able to make comments mandatory when a record closes for one tenant, but not for another.

      How domain separation works in Trusted Security Circle

      Domain separation enables service providers (SPs to standardize Trusted Security Circle procedures across the customer base they serve with lowered operational costs and a higher quality of service.

      Separate customer work spaces for workflows, dashboards, reports, and so forth ensures that customer data is separated and never exposed to other clients.

      Domain separation support in Trusted Security Circle by version releases

      Release Support level Notes
      Jakarta Level 2 (Data, Requestor, Fulfiller)
      Kingston Level 2 (Data, Requestor, Fulfiller)
      London All integrations reside across multiple domains.
      Madrid Level 2 (Data, Requestor, Fulfiller) All integrations reside across multiple domains.
      New York Level 2 (Data, Requestor, Fulfiller) All integrations reside across multiple domains.
      Orlando Standard All integrations reside across multiple domains.
      Paris Standard All integrations reside across multiple domains.

      Domain separation setup

      Setting up domain separation for Trusted Security Circle requires that you request domain separation, register the central instance for each domain, and configure the job queue.
      Important: If you are using domain separation, you must activate the Domain Support - Domain Extensions plugin before activating Trusted Security Circle. Several of the setup steps are also different for domain separation setup.
      Related topics
      • Domain separation for service providers

      Request domain separation

      All domain support features are activated with a plugin called Domain Support - Domain Extensions Installer. Administrators can request activation of this plugin.

      Before you begin

      To purchase a subscription, contact your ServiceNow account manager. The account manager can arrange to have the plugin activated on your organization's production and sub-production instances, generally within a few days.

      If you do not have an account manager, decide to delay activation after purchase, or want to evaluate the product on a sub-production instance without charge, follow these steps.

      Role required: admin

      About this task

      If the Domain Support - Domain Extensions Installer plugin is already active, content in the Domain Support - Domain Extensions Installer plugin will not be installed to avoid potential conflict with an existing implementation.

      Domain separation replaces Company Separation. Starting with the Helsinki release, the Company Separation plugin can no longer be activated. However, if company separation is already active when you activate domain separation, both plugins are active at the same time. You can control the company separation activation status with the glide.db.separation.field property.

      Note: Domain paths are used for all customers on Helsinki and later. Domain numbering is no longer used. ServiceNow Technical Support can assist in the upgrade.

      Procedure

      1. Navigate to System Applications > All Available Applications > All.
      2. On the All Applications page, click Request Plugin to open the request form on HI.
        Select to request a plugin from the All Applications page.
      3. On HI, select to be redirected to the HI Service Portal Service Catalog.
        HI redirect to Service Catalog
      4. On the Activate Plugin request form, fill in the fields.
        Field Description
        Target Instance Instance on which to activate the plugin.
        Plugin Name Name of the plugin to activate.
        Specify the date and time you would like this plugin to be enabled

        The date and time must be at least two business days from the current time.

        Note: Plugins are activated in two batches each business day in the Pacific time zone, once in the morning and once in the evening. If the plugin must be activated at a specific time, enter the request in the Reason/Comments field.
        Reason/Comments Information that would be helpful for the ServiceNow personnel who are activating the plugin. For example, if you need the plugin activated at a specific time instead of during one of the default activation windows, specify it in the comments.
      5. Click Submit.

      Result

      Activating the Domain Extension Installer plugin enables these features:
      • Domain separation is based on the Domain [sys_domain] table.
      • Delegated administration lets each domain have separate policy.
      • All records are part of the global domain.
      • The current user's domain determines the domain to use when viewing or operating on a record in a different domain.
      Related concepts
      • Domain separation plugin

      Register the Trusted Security Circles central instance for each domain

      If domain separation is not installed, registration to the global domain occurs automatically. If you have installed domain separation, manually register the Trusted Security Circle central instance for each of your domains.

      Before you begin

      If you are using the basic level of Trusted Security Circle, it is activated automatically when you activate Security Incident Response. Trusted Security Circles Client (Advanced) is available as a separate subscription.
      When domain separation is activated, two additional modules appear in the Trusted Security Circles navigation bar:
      • Job Queue Entries
      • Registration

      Role required: sn_tis_admin

      Procedure

      1. If it is not already activated, active the appropriate level of Trusted Security Circles.
      2. Navigate to Trusted Security Circles > Registration.
      3. From the Domain (Domain) drop-down list, select the domain you want to register to the Trusted Security Circles central instance.
      4. Click Register.
      5. You can verify that the domain registration completed successfully by navigating to Trusted Security Circles > Circles.

      Configure the job queue

      The job queue is used to execute scheduled jobs for getting messages from the central instance, processing records in the central instance, and refreshing records from central for your domain or for each of your domains (if you are using domain separation).

      Before you begin

      Role required: admin

      Procedure

      1. Navigate to Trusted Security Circles > Job Queue Entries.
      2. In the Job Queue Entries screen, click New.
      3. From the Domain (Domain) drop-down list, select the domain for which you want to configure the job queue.
      4. Fill in the fields as appropriate.
        Field Description
        Job Click the lookup icon and select the scheduled job executer you want to use for the selected domain.
        Last Run Displays the date and time when the job was last run. The oldest job will be the next one to run.
        Domain User Select the user in this domain who is identified as the person running this job.
      5. Click Submit.
      6. Repeat these steps as needed to select other jobs for this domain and for other domains (if you are using domain separation).
      Related concepts
      • Domain separation and Trusted Security Circle

      Tags:

      Feedback

          Share this page

          Got it! Feel free to add a comment
          To share your product suggestions, visit the Idea Portal.
          Please let us know how to improve this content

          Check any that apply

          To share your product suggestions, visit the Idea Portal.
          Confirm

          We were unable to find "Coaching" in Jakarta. Would you like to search instead?

          No Yes
          • Contact Us
          • Careers
          • Terms of Use
          • Privacy Statement
          • Sitemap
          • © ServiceNow. All rights reserved.

          Subscribe Subscribed Unsubscribe Last updated: Tags: January February March April May June July August September October November December No Results Found Versions Search preferences successfully updated My release version successfully updated My release version successfully deleted An error has occurred. Please try again later. You have been unsubscribed from all topics. You are now subscribed to and will receive notifications if any changes are made to this page. You have been unsubscribed from this content Thank you for your feedback. Form temporarily unavailable. Please try again or contact  docfeedback@servicenow.com  to submit your comments. The topic you requested does not exist in the release. You were redirected to a related topic instead. The available release versions for this topic are listed There is no specific version for this documentation. Explore products Click to go to the page. Release notes and upgrades Click to open the dropdown menu. Delete Remove No selected version Reset This field is required You are already subscribed to this topic Attach screenshot The file you uploaded exceeds the allowed file size of 20MB. Please try again with a smaller file. Please complete the reCAPTCHA step to attach a screenshot
          Log in to personalize your search results and subscribe to topics
          No, thanks Login