You would want to create new groups, users and roles to act as "admins" for particular domains based on those roles/rights. Then restrict usage/access to the cloud admin user/role to only those who are truly cloud-wide admins. Perhaps start here: link text