You have not mentioned the nos of users in each domains, that could be one reason to push for a separate domain from the point of view of maitenance. One can go for separate domain of Resources only when this deptt has huge nos. of users and the proposed DC might not cater its demand as it should do. BUT SECURITY REASON CAN BE EASILY NEGATED BY ASKING YOU TO HAVE SEPARATE VLAN, SO THAT NOTHING UNTOWARD IS FORWARDED TO THE PROPOSED FOREST TO BREAK A HELL. The reasons may be…
1- Production server should not be linked to any other, for you may need to upgrade/update (hardware/software).
2 – Ideally production department is kept separte, industry standard. You never mix production (development) deptt with real world systems that are in use.
And what else.
Thanks and Regards