Cross-Domain Policies
Setup Guide — Letting One Data Domain Use Another's Data
Module: AI Module › Configuration | Last updated: July 2026
Contents
- Overview
- Key Concept: Domains Are Separate by Default
- Finding Your Way Around
- Creating a Cross-Domain Policy
- How It Works with Data Domain Policies
- Quick Reference
1. Overview
Normally, the AI in each data domain only ever looks at that domain's own data. A cross-domain policy is a deliberate exception: it lets one domain — the source — draw on data from another domain — the target — when the AI answers a request.
Nothing is shared unless you create a policy for that exact pair of domains and switch it on. This keeps your data separated by default, and puts you in control of every exception.
What you can do here
- Allow a specific domain to use another domain's data for AI requests.
- Limit the sharing to certain kinds of records (object types), or allow all of them.
- Turn any sharing arrangement on or off without deleting it.
WHERE TO FIND IT — Cross-domain policies live under Admin → AI → Configuration → Cross-Domain Policies. Adding one opens the Configure Cross-Domain AI Policy screen.
2. Key Concept: Domains Are Separate by Default
Every cross-domain policy is about one direction between two domains:
- The source domain is the one making the AI request.
- The target domain is the one whose data the source is allowed to use.
A policy applies to that pair in that direction only. Letting Domain A use Domain B's data does not automatically let Domain B use Domain A's — that would be a separate policy. Each pair can have only one policy, and the source and target must be different domains.
Rule of thumb: think of a policy as a one-way permission slip — "the source domain may look at the target domain's data."
3. Finding Your Way Around
Go to Admin → AI → Configuration → Cross-Domain Policies. This lists the sharing arrangements you've set up, showing each source/target pair and whether it's currently allowed. From here you can add a new policy or switch an existing one on or off.
4. Creating a Cross-Domain Policy
Click to add a policy and fill in the Configure Cross-Domain AI Policy screen. It's organised into three parts:
| Field | What it means |
|---|---|
| Source Domain | The domain that will be making AI requests — the one that wants to use another domain's data. |
| Target Domain | The domain whose data the source may use. Must be different from the source. |
| Object Types | The kinds of records the source is allowed to use from the target. Pick one or more, or leave it empty to allow all types. The available types come from Reference Data → Object Types. |
| Allowed | Whether the sharing is switched on. Yes lets the source use the target's data; No blocks it while keeping the policy on file. New policies default to Yes, since you're deliberately allowing the pair. |
Steps
- Choose the Source Domain — the domain that needs the data.
- Choose the Target Domain — the domain it may draw from. (It can't be the same as the source.)
- Pick the Object Types to share, or leave empty to allow all.
- Set Allowed to Yes, then Save.
START NARROW — If you only need to share one kind of record, choose just that object type rather than leaving the list empty. It's easier to widen a policy later than to discover you shared more than you meant to.
5. How It Works with Data Domain Policies
Cross-domain sharing takes two settings working together:
- In the source domain's Data Domain Policy, the Allow Cross-Domain Search switch must be Yes. This is the general permission — "this domain is allowed to look beyond itself."
- A cross-domain policy here then says exactly which target domains (and which object types) it may use.
Think of the domain policy switch as unlocking the door, and the cross-domain policy as the specific guest list. If either one says no, the sharing doesn't happen.
BOTH MUST AGREE — If cross-domain search is off in the source domain's own policy, adding a cross-domain policy here won't take effect until you turn it on there too.
6. Quick Reference
A fast lookup for the most common actions.
| I want to… | Do this |
|---|---|
| Let one domain use another's data | Cross-Domain Policies → add → pick Source and Target → Allowed = Yes → Save |
| Limit sharing to certain record types | Choose specific Object Types instead of leaving the list empty |
| Share every kind of record | Leave Object Types empty |
| Pause a sharing arrangement | Edit the policy → set Allowed = No |
| Understand why sharing isn't working | Check that Allow Cross-Domain Search is Yes in the source domain's Data Domain Policy |
Source: OnCoor AI Module product documentation, written for end users. For the latest screens and options, always refer to the in-app interface.