No, a person who holds the SharePoint admin role can see all SharePoint sites and grant themselves full control of any site. In addition, a single M365 tenant only has a single domain (tenantName.sharepoint.com).
If you're referring to sites, each site is a permissions boundary, so for example, you can grant HR personnel only access to /sites/HR and Finance personnel to only the site /sites/Finance, etc.