In short

One workspace per client, one identity per account, one carrier IP per identity, and never share an operator seat across clients without device-group scoping. Export the audit trail monthly and attach it to the client report.

The failure mode

An agency runs 8 clients on 40 devices. Client C does something aggressive, gets a client-level enforcement action, and because devices were reused across clients, Clients A, B and F lose accounts too. You now have three angry contracts and no evidence of what happened.

The structure

  1. One workspace per client. Hard boundary. Devices, identities, proxies and RPA flows do not cross it.
  2. One identity per account. Never run two client accounts on one identity even for the same platform.
  3. One carrier IP per identity. Shared IPs are the second most common contagion vector after shared hardware IDs.
  4. Scoped seats. An operator working across three clients gets three device-group scopes, not global access.
  5. Monthly audit export. CSV or JSON, attached to the client report. This is what turns an argument into a document.

What to tell a client who asks

Clients increasingly ask how their accounts are isolated. The honest answer, if you are structured as above: each of your accounts runs on a dedicated device identity with its own hardware identifiers, its own carrier IP and its own storage sandbox, in a workspace that no other client's operators can access. Nothing is shared, so nothing propagates. Here is the audit trail.