{"templateId":"markdown","versions":[{"version":"v1.39","label":"v1.39 STS","link":"/products/custody/governance/genesis/design-your-domains","default":true,"active":false,"folderId":"c15a2701"},{"version":"v1.38","label":"v1.38 STS","link":"/products/custody/v1.38/governance/genesis/design-your-domains","default":false,"active":true,"folderId":"c15a2701"},{"version":"v1.34","label":"v1.34 LTS","link":"/products/custody/v1.34/governance/genesis/design-your-domains","default":false,"active":false,"folderId":"c15a2701"},{"version":"v1.26","label":"v1.26 LTS","link":"/products/custody/v1.26/governance/genesis/design-your-domains","default":false,"active":false,"folderId":"c15a2701"},{"version":"v1.19","label":"v1.19 LTS","link":"/products/custody/v1.19/governance/genesis/design-your-domains","default":false,"active":false,"folderId":"c15a2701"},{"version":"v1.15","label":"v1.15 LTS","link":"/products/custody/v1.15/governance/genesis/design-your-domains","default":false,"active":false,"folderId":"c15a2701"}],"sharedDataIds":{"sidebar":"sidebar-products/custody/@v1.15/sidebars.yaml"},"props":{"metadata":{"markdoc":{"tagList":[]},"type":"markdown"},"seo":{"title":"Design your domains","description":"User guides, API reference, and support resources.","siteUrl":"https://docs.ripple.com","lang":"en-US","llmstxt":{"hide":false,"sections":[{"title":"Table of contents","includeFiles":["**/*"],"excludeFiles":[]}],"excludeFiles":[]}},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"design-your-domains","__idx":0},"children":["Design your domains"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Design the domains that must exist when your environment first starts. The goal is the smallest domain hierarchy that expresses the governance boundaries you need on day one."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"inputs","__idx":1},"children":["Inputs"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Before you define the domain tree, identify:"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Input"},"children":["Input"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Questions"},"children":["Questions"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Operating model"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Are you separating clients, regions, business units, treasury desks, compliance teams, or environments?"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Ownership"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Which team owns root-domain governance?"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Oversight"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Which parent-domain controls must apply to child domains?"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Visibility"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Which roles must be able to view domains, users, accounts, transactions, policies, requests, endpoints, and events?"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Launch dependency"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Which domain boundaries must exist before users and policies can work?"]}]}]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"design-decisions","__idx":2},"children":["Design decisions"]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"root-domain","__idx":3},"children":["Root domain"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Use the root domain for platform-level governance, policy administration, emergency control, and the initial root of trust. Avoid using it as the default place for routine operations if your operating model needs separation."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"launch-subdomains","__idx":4},"children":["Launch subdomains"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Create a subdomain at genesis when it is required for:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Client or tenant isolation."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Regional or legal-entity separation."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Treasury isolation."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Compliance review or quarantine workflows."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Parent-domain oversight or override."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["If a subdomain can be created safely through a governed intent after launch, defer it."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"governing-strategy","__idx":5},"children":["Governing strategy"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Choose the governing strategy for each parent domain:"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Strategy"},"children":["Strategy"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Choose when"},"children":["Choose when"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["ConsiderDescendants"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Parent and child policies should both be considered."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["CoerceDescendants"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Parent policies should override matching child policies."]}]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Use ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["CoerceDescendants"]}," only when override is intentional, such as breakglass or compliance enforcement."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"read-access","__idx":6},"children":["Read access"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Read access should let each role see the records it needs to approve, investigate, or audit. Review read access for domains, users, accounts, transactions, policies, endpoints, requests, and events."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"genesis-domain-example","__idx":7},"children":["Genesis domain example"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The following example shows the domain portion of a genesis request body. It creates a root domain, one operations subdomain, and one compliance subdomain. The users and policies arrays are intentionally empty here because they are designed in the next two steps."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For the complete genesis request body, see ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/v1.38/governance/genesis/payload-reference"},"children":["Genesis payload reference"]},". For the post-genesis domain intent shape, see ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/v1.38/governance/domains/manage-domains#create-a-domain-with-the-api"},"children":["Manage domains"]},"."]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"json","header":{"controls":{"copy":{}}},"source":"{\n  \"rootDomainSetup\": {\n    \"id\": \"9067d363-6411-498b-a32b-15d230a86706\",\n    \"alias\": \"Root domain\",\n    \"lock\": \"Unlocked\",\n    \"governingStrategy\": \"ConsiderDescendants\",\n    \"permissions\": {\n      \"readAccess\": {\n        \"domains\": [\"platform-admin\", \"auditor\"],\n        \"users\": [\"platform-admin\", \"auditor\"],\n        \"accounts\": [\"platform-admin\", \"auditor\"],\n        \"transactions\": [\"platform-admin\", \"auditor\"],\n        \"policies\": [\"platform-admin\", \"policy-operator\", \"auditor\"],\n        \"endpoints\": [\"platform-admin\"],\n        \"requests\": [\"platform-admin\", \"policy-operator\", \"auditor\"],\n        \"events\": [\"platform-admin\", \"auditor\"]\n      }\n    },\n    \"description\": \"Root governance domain\",\n    \"customProperties\": {},\n    \"users\": [],\n    \"policies\": [],\n    \"descendants\": [\n      {\n        \"id\": \"1f1e3d9c-f2bf-4a92-a0fa-4a825e70ecb4\",\n        \"alias\": \"Operations\",\n        \"lock\": \"Unlocked\",\n        \"governingStrategy\": \"ConsiderDescendants\",\n        \"permissions\": {\n          \"readAccess\": {\n            \"domains\": [\"platform-admin\", \"transaction-operator\", \"compliance\", \"auditor\"],\n            \"users\": [\"platform-admin\", \"compliance\", \"auditor\"],\n            \"accounts\": [\"platform-admin\", \"transaction-operator\", \"compliance\", \"auditor\"],\n            \"transactions\": [\"platform-admin\", \"transaction-operator\", \"compliance\", \"auditor\"],\n            \"policies\": [\"platform-admin\", \"policy-operator\", \"auditor\"],\n            \"endpoints\": [\"platform-admin\", \"transaction-operator\", \"compliance\"],\n            \"requests\": [\"platform-admin\", \"transaction-operator\", \"compliance\", \"auditor\"],\n            \"events\": [\"platform-admin\", \"compliance\", \"auditor\"]\n          }\n        },\n        \"description\": \"Day-to-day transaction operations\",\n        \"customProperties\": {},\n        \"users\": [],\n        \"policies\": [],\n        \"descendants\": []\n      },\n      {\n        \"id\": \"2d37d78f-6f75-4667-93f7-1c6c07d77491\",\n        \"alias\": \"Compliance\",\n        \"lock\": \"Unlocked\",\n        \"governingStrategy\": \"CoerceDescendants\",\n        \"permissions\": {\n          \"readAccess\": {\n            \"domains\": [\"platform-admin\", \"compliance\", \"auditor\"],\n            \"users\": [\"platform-admin\", \"compliance\", \"auditor\"],\n            \"accounts\": [\"platform-admin\", \"compliance\", \"auditor\"],\n            \"transactions\": [\"platform-admin\", \"compliance\", \"auditor\"],\n            \"policies\": [\"platform-admin\", \"policy-operator\", \"compliance\", \"auditor\"],\n            \"endpoints\": [\"platform-admin\", \"compliance\"],\n            \"requests\": [\"platform-admin\", \"compliance\", \"auditor\"],\n            \"events\": [\"platform-admin\", \"compliance\", \"auditor\"]\n          }\n        },\n        \"description\": \"Compliance oversight and exception handling\",\n        \"customProperties\": {},\n        \"users\": [],\n        \"policies\": [],\n        \"descendants\": []\n      }\n    ]\n  }\n}\n","lang":"json"},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"output","__idx":8},"children":["Output"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["By the end of this step, you should have:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Root domain owner."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Launch domain tree."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Governing strategy for each parent domain."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Read access by role."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["List of deferred domains."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Use the output as input for ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/v1.38/governance/genesis/plan-your-first-users"},"children":["Plan your first users"]}," and ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/v1.38/governance/genesis/design-your-policies"},"children":["Design your policies"]},"."]}]},"headings":[{"value":"Design your domains","id":"design-your-domains","depth":1},{"value":"Inputs","id":"inputs","depth":2},{"value":"Design decisions","id":"design-decisions","depth":2},{"value":"Root domain","id":"root-domain","depth":3},{"value":"Launch subdomains","id":"launch-subdomains","depth":3},{"value":"Governing strategy","id":"governing-strategy","depth":3},{"value":"Read access","id":"read-access","depth":3},{"value":"Genesis domain example","id":"genesis-domain-example","depth":2},{"value":"Output","id":"output","depth":2}],"frontmatter":{"seo":{"title":"Design your domains"}},"lastModified":"2026-07-27T10:10:43.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/products/custody/v1.38/governance/genesis/design-your-domains","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}