{"templateId":"markdown","versions":[{"version":"v1.39","label":"v1.39 STS","link":"/products/custody/governance/domains/manage-domains","default":true,"active":true,"folderId":"c15a2701"},{"version":"v1.38","label":"v1.38 STS","link":"/products/custody/v1.38/governance/domains/manage-domains","default":false,"active":false,"folderId":"c15a2701"},{"version":"v1.34","label":"v1.34 LTS","link":"/products/custody/v1.34/governance/domains/manage-domains","default":false,"active":false,"folderId":"c15a2701"},{"version":"v1.26","label":"v1.26 LTS","link":"/products/custody/v1.26/governance/domains/manage-domains","default":false,"active":false,"folderId":"c15a2701"},{"version":"v1.19","label":"v1.19 LTS","link":"/products/custody/v1.19/governance/domains/manage-domains","default":false,"active":false,"folderId":"c15a2701"},{"version":"v1.15","label":"v1.15 LTS","link":"/products/custody/v1.15/governance/domains/manage-domains","default":false,"active":false,"folderId":"c15a2701"}],"sharedDataIds":{"sidebar":"sidebar-products/custody/@v1.15/sidebars.yaml"},"props":{"metadata":{"markdoc":{"tagList":[]},"type":"markdown"},"seo":{"title":"Manage domains","description":"User guides, API reference, and support resources.","siteUrl":"https://docs.ripple.com","lang":"en-US","llmstxt":{"hide":false,"sections":[{"title":"Table of contents","includeFiles":["**/*"],"excludeFiles":[]}],"excludeFiles":[]}},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"manage-domains","__idx":0},"children":["Manage domains"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Use this page for post-genesis domain operations. For the domain model, see ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/governance/domains"},"children":["Domains"]},". For launch design, see ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/governance/genesis/design-your-domains"},"children":["Design your domains"]},"."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"domain-actions","__idx":1},"children":["Domain actions"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Action"},"children":["Action"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"UI procedure"},"children":["UI procedure"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"API procedure"},"children":["API procedure"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Create a domain"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"#create-a-domain-in-the-ui"},"children":["Create a domain in the UI"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"#create-a-domain-with-the-api"},"children":["Create a domain with the API"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["View domain details"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"#view-domain-details-in-the-ui"},"children":["View domain details in the UI"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"#view-domain-details-with-the-api"},"children":["View domain details with the API"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Update domain details"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"#update-domain-details-in-the-ui"},"children":["Update domain details in the UI"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"#update-domain-details-with-the-api"},"children":["Update domain details with the API"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Update domain read access"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"#update-domain-read-access-in-the-ui"},"children":["Update domain read access in the UI"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"#update-domain-read-access-with-the-api"},"children":["Update domain read access with the API"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Lock and unlock a domain"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"#lock-or-unlock-a-domain-in-the-ui"},"children":["Lock or unlock a domain in the UI"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"#lock-or-unlock-a-domain-with-the-api"},"children":["Lock or unlock a domain with the API"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Inject a domain"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Use the API procedure."]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/governance/domains/inject-a-domain"},"children":["Inject a domain"]}]}]}]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"api-reference-and-shared-process","__idx":2},"children":["API reference and shared process"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Task"},"children":["Task"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"API reference"},"children":["API reference"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Propose a domain intent"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/reference/api/openapi/intents/createintent"},"children":["Propose an intent"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Dry run a domain intent"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/reference/api/openapi/intents/intentdryrun"},"children":["Perform a dry run"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["View a domain"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/reference/api/openapi/domains/getdomain"},"children":["Get domain details"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["List domains"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/reference/api/openapi/domains/getdomains"},"children":["List domains"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Check known roles"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/reference/api/openapi/users/getknownuserroles"},"children":["Get known user roles"]}]}]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Domain changes use the standard intent flow. For signing, approval, and status checks, see ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/governance/intents/manage-intents-and-approvals"},"children":["Manage intents and approvals"]},", ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/identity-and-access/authentication/authenticate-api-requests#signing-intents-state-mutation-operations"},"children":["Sign intents"]},", and ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/governance/intents/manage-intents-and-approvals#check-state"},"children":["Check updates"]},"."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"common-operations","__idx":3},"children":["Common operations"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Operation"},"children":["Operation"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Intent type"},"children":["Intent type"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Use when"},"children":["Use when"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Create domain"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["v0_CreateDomain"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Add a new governance boundary after launch."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Update domain details"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["v0_UpdateDomain"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Change mutable details such as alias, description, or custom properties."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Update domain permissions"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["v0_UpdateDomainPermissions"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Change read access by role."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Lock domain"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["v0_LockDomain"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Temporarily suspend activity in a domain."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Unlock domain"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["v0_UnlockDomain"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Re-enable a locked domain."]}]}]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"create-a-domain-in-the-ui","__idx":4},"children":["Create a domain in the UI"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["All environments include at least a root domain. After setup, you create new domains as subdomains of the root domain or of an existing subdomain."]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["From the domain selector, select the parent domain."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Go to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Domains"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Create a domain"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Enter the domain details."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Review the summary."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Submit for approval"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Sign the operation with the mobile app."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The domain is created after the intent is approved and executed."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Use these UI pages to enter the domain details:"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Page"},"children":["Page"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Details"},"children":["Details"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["General information"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Domain name, optional description, custom properties, and governing strategy. Choose ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Coerce descendants"]}," to ignore policies in subdomains, or ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Consider descendants"]}," to consider policies in subdomains. If you do not choose a governing strategy, ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["ConsiderDescendants"]}," applies."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["User information"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["One or more users associated with the domain, including email address for an existing or new user and user role within the domain."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Access management"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Read-only access by role for each entity type, and the roles that can administer the default policy created with the domain."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Summary"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Details entered for review and submission."]}]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["When you create a domain in the UI, the domain is created with a default catch-all policy. Update that policy and add more specific policies so the domain matches your governance model."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"view-domain-details","__idx":5},"children":["View domain details"]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"view-domain-details-in-the-ui","__idx":6},"children":["View domain details in the UI"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In the UI, you can view the current domain and its subdomains:"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["From the domain selector, select the top-level domain to view."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Go to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Domains"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["To view the subdomains of a domain, click the arrow next to the domain."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["To view domain details, click the domain."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"view-domain-details-with-the-api","__idx":7},"children":["View domain details with the API"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The UI displays the first 100 subdomains of any domain. Use ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/reference/api/openapi/domains/getdomains"},"children":["List domains"]}," or ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/reference/api/openapi/domains/getdomain"},"children":["Get domain details"]}," when you need API access to domain details."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"create-a-domain-with-the-api","__idx":8},"children":["Create a domain with the API"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Create a domain by submitting a ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["v0_CreateDomain"]}," intent. The payload can include initial users and policies for the new domain."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Before you create a domain, prepare:"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Prerequisite"},"children":["Prerequisite"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Additional information"},"children":["Additional information"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Available roles"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Call ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/reference/api/openapi/users/getknownuserroles"},"children":["Get known user roles"]},". You can also use new roles if required."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["New IDs"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Prepare a domain ID, any user IDs, any policy IDs, and an intent ID in standard UUID format."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Governing strategy"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Choose ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["ConsiderDescendants"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["CoerceDescendants"]},", or omit the field to use the default ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["ConsiderDescendants"]}," behavior."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Read access"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Decide which roles can view domains, users, endpoints, policies, accounts, transactions, requests, and events."]}]}]}]}]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"json","header":{"controls":{"copy":{}}},"source":"{\n  \"payload\": {\n    \"id\": \"1f1e3d9c-f2bf-4a92-a0fa-4a825e70ecb4\",\n    \"alias\": \"Operations\",\n    \"lock\": \"Unlocked\",\n    \"governingStrategy\": \"ConsiderDescendants\",\n    \"permissions\": {\n      \"readAccess\": {\n        \"domains\": [\"admin\", \"manager\"],\n        \"users\": [\"admin\", \"manager\"],\n        \"accounts\": [\"admin\", \"manager\", \"trader\"],\n        \"transactions\": [\"admin\", \"manager\", \"trader\"],\n        \"policies\": [\"admin\"],\n        \"endpoints\": [\"admin\", \"manager\"],\n        \"requests\": [\"admin\", \"manager\", \"trader\"],\n        \"events\": [\"admin\", \"manager\"]\n      }\n    },\n    \"description\": \"Operations domain\",\n    \"customProperties\": {},\n    \"users\": [],\n    \"policies\": [],\n    \"type\": \"v0_CreateDomain\"\n  }\n}\n","lang":"json"},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Field notes:"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Field"},"children":["Field"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Notes"},"children":["Notes"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["id"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["New domain ID in UUID format."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["lock"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Use ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Locked"]}," to create an inactive domain and unlock it later."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["governingStrategy"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["ConsiderDescendants"]}," considers subdomain policies. ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["CoerceDescendants"]}," ignores matching subdomain policies."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["permissions"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Role-based read access for each entity type in the domain."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["users"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Users to create with the domain."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["policies"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Policies to create with the domain. Use the field shape in ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/governance/policies/reference"},"children":["Policy reference"]},"."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["type"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["v0_CreateDomain"]},"."]}]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Dry run before submitting:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"sh","header":{"controls":{"copy":{}}},"source":"curl -X POST \"${CUSTODY_API_URL}/v1/intents/dry-run\" \\\n  -H \"Authorization: Bearer ${JWT_TOKEN}\" \\\n  -H \"Content-Type: application/json\" \\\n  -d @create-domain-intent.json\n","lang":"sh"},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Submit the signed intent:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"sh","header":{"controls":{"copy":{}}},"source":"curl -X POST \"${CUSTODY_API_URL}/v1/intents\" \\\n  -H \"Authorization: Bearer ${JWT_TOKEN}\" \\\n  -H \"Content-Type: application/json\" \\\n  -d @signed-create-domain-intent.json\n","lang":"sh"},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"update-domain-details","__idx":9},"children":["Update domain details"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Use ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["v0_UpdateDomain"]}," to update mutable domain details such as alias, description, and custom properties."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"update-domain-details-in-the-ui","__idx":10},"children":["Update domain details in the UI"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["You can update the alias and description of a subdomain from the root domain:"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Select the root domain from the domain selector."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Go to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Domains"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["In the domain hierarchy, click the domain to update."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Edit information"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Update ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Name"]}," or ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Description"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Submit for approval"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Sign the operation with the mobile app."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"update-domain-details-with-the-api","__idx":11},"children":["Update domain details with the API"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Submit an update intent with the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["targetDomainId"]}," set to the domain to update. The update payload uses the current domain reference:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"json","header":{"controls":{"copy":{}}},"source":"{\n  \"payload\": {\n    \"reference\": {\n      \"id\": \"1f1e3d9c-f2bf-4a92-a0fa-4a825e70ecb4\",\n      \"revision\": 2\n    },\n    \"alias\": \"Operations\",\n    \"description\": \"Updated operations domain description\",\n    \"customProperties\": {},\n    \"type\": \"v0_UpdateDomain\"\n  }\n}\n","lang":"json"},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"update-domain-read-access","__idx":12},"children":["Update domain read access"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Use ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["v0_UpdateDomainPermissions"]}," to update read access. Use ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["v0_UpdateDomain"]}," for mutable domain details such as alias, description, and custom properties."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"update-domain-read-access-in-the-ui","__idx":13},"children":["Update domain read access in the UI"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Select the domain, or another domain above it in the same hierarchy, from the domain selector."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Go to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Domains"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["In the domain hierarchy, click the domain to update."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Edit read permissions"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["In ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Read permissions"]},", add or remove user roles."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Select the entities each role can view."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Submit for approval"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Sign the operation with the mobile app."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"update-domain-read-access-with-the-api","__idx":14},"children":["Update domain read access with the API"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Domain permission updates can be submitted:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["By a user in a parent domain, through an intent submitted to the parent domain."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["By a user in a parent domain, through an intent submitted to a subdomain."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["By a user in a subdomain, through an intent submitted to the subdomain."]}]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"json","header":{"controls":{"copy":{}}},"source":"{\n  \"payload\": {\n    \"reference\": {\n      \"id\": \"1f1e3d9c-f2bf-4a92-a0fa-4a825e70ecb4\",\n      \"revision\": 2\n    },\n    \"permissions\": {\n      \"readAccess\": {\n        \"domains\": [\"admin\", \"auditor\"],\n        \"users\": [\"admin\", \"auditor\"],\n        \"accounts\": [\"admin\", \"auditor\", \"compliance\"],\n        \"transactions\": [\"admin\", \"auditor\", \"compliance\"],\n        \"policies\": [\"admin\", \"auditor\"],\n        \"endpoints\": [\"admin\"],\n        \"requests\": [\"admin\", \"auditor\", \"compliance\"],\n        \"events\": [\"admin\", \"auditor\", \"compliance\"]\n      }\n    },\n    \"type\": \"v0_UpdateDomainPermissions\"\n  }\n}\n","lang":"json"},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Before updating read access, confirm that approvers and auditors can still see the records they need."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"lock-and-unlock-a-domain","__idx":15},"children":["Lock and unlock a domain"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Use lock operations for incident response, investigations, temporary suspension, or decommissioning."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"lock-or-unlock-a-domain-in-the-ui","__idx":16},"children":["Lock or unlock a domain in the UI"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Select the domain, or another domain above it in the same hierarchy, from the domain selector."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Go to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Domains"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["In the domain hierarchy, click the domain to lock or unlock."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["If the domain is unlocked, click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Lock"]},". If it is locked, click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Unlock"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Sign the operation with the mobile app."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"lock-or-unlock-a-domain-with-the-api","__idx":17},"children":["Lock or unlock a domain with the API"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"json","header":{"controls":{"copy":{}}},"source":"{\n  \"payload\": {\n    \"reference\": {\n      \"id\": \"1f1e3d9c-f2bf-4a92-a0fa-4a825e70ecb4\",\n      \"revision\": 2\n    },\n    \"type\": \"v0_LockDomain\"\n  }\n}\n","lang":"json"},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Use ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["v0_UnlockDomain"]}," to re-enable the domain. When a domain is locked, users cannot submit intents in that domain or any of its subdomains."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"add-or-update-entities-in-a-domain","__idx":18},"children":["Add or update entities in a domain"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["To add or update entities in a domain, select the target domain from the domain selector and follow the relevant governance procedure, such as ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/governance/users/manage-users-and-roles"},"children":["Manage users and roles"]}," or ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/governance/policies/reference"},"children":["Manage policies"]},"."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"operational-checklist","__idx":19},"children":["Operational checklist"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Before submitting a domain intent:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Confirm the parent domain and governing strategy."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Confirm read access for operators, approvers, compliance, and auditors."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Confirm the policy that will govern the domain intent."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Confirm approvers can satisfy quorum without relying on users being created by the same intent."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Dry run the payload."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Verify the executed change by viewing the domain."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For domain fields, see ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/governance/domains/reference"},"children":["Domain reference"]},"."]}]},"headings":[{"value":"Manage domains","id":"manage-domains","depth":1},{"value":"Domain actions","id":"domain-actions","depth":2},{"value":"API reference and shared process","id":"api-reference-and-shared-process","depth":2},{"value":"Common operations","id":"common-operations","depth":2},{"value":"Create a domain in the UI","id":"create-a-domain-in-the-ui","depth":2},{"value":"View domain details","id":"view-domain-details","depth":2},{"value":"View domain details in the UI","id":"view-domain-details-in-the-ui","depth":3},{"value":"View domain details with the API","id":"view-domain-details-with-the-api","depth":3},{"value":"Create a domain with the API","id":"create-a-domain-with-the-api","depth":2},{"value":"Update domain details","id":"update-domain-details","depth":2},{"value":"Update domain details in the UI","id":"update-domain-details-in-the-ui","depth":3},{"value":"Update domain details with the API","id":"update-domain-details-with-the-api","depth":3},{"value":"Update domain read access","id":"update-domain-read-access","depth":2},{"value":"Update domain read access in the UI","id":"update-domain-read-access-in-the-ui","depth":3},{"value":"Update domain read access with the API","id":"update-domain-read-access-with-the-api","depth":3},{"value":"Lock and unlock a domain","id":"lock-and-unlock-a-domain","depth":2},{"value":"Lock or unlock a domain in the UI","id":"lock-or-unlock-a-domain-in-the-ui","depth":3},{"value":"Lock or unlock a domain with the API","id":"lock-or-unlock-a-domain-with-the-api","depth":3},{"value":"Add or update entities in a domain","id":"add-or-update-entities-in-a-domain","depth":2},{"value":"Operational checklist","id":"operational-checklist","depth":2}],"frontmatter":{"seo":{"title":"Manage domains"}},"lastModified":"2026-08-04T20:25:11.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/products/custody/governance/domains/manage-domains","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}