Domain access

Which catalog a user gets is decided by Salesforce record sharing on the domain. Share a domain with someone and their agents can discover what it serves. Share nothing and they get the default.

Three rules

Sharing is the ceiling. A user reads the domains shared to them, and no others. Share to a user, a public group, a role, or a role and its subordinates — whatever your org already uses.

The default domain is a fallback. Installing the sample configuration creates General and shares it with every internal user. Hold no other domain and you read General. Hold one and General drops away automatically, so scoping someone is one grant with nothing to revoke.

The Domains page badges it Default. The name describes what the domain covers — rename it freely — and the badge describes what it does.

Membership decides what a domain serves. An entity reaches a user because a domain they hold has it on its roster. An entity on no roster reaches nobody — deterministic, and the Access page names any that are stranded.

Setting someone up

To…Do this
Give a user the default catalogAssign ContextWorks User. Nothing else
Limit a user to one domainDomains → the domain’s Users button → add them
Let someone maintain a domainThe domain’s Managers button. They also need ContextWorks Domain Manager

Both buttons accept a user, a public group, a role, or a role and its subordinates.

Two things worth knowing

Rosters need to be complete. A user scoped to Finance sees only what Finance rosters. If they still need Accounts, add the Account entity to Finance’s roster too — entities can sit in several domains at once.

An entity that has never been activated reaches nobody, whichever domains carry it. → Versions

Prerequisite

Domain scoping requires the Entity Domain object’s org-wide default to be Private. → Sharing setup

What’s next

  • Domains — what a domain is and when to add one.
  • Security — how payloads stay permission-correct.