In short
One workspace per client, one identity per account, one carrier IP per identity, and never share an operator seat across clients without device-group scoping. Export the audit trail monthly and attach it to the client report.
The failure mode
An agency runs 8 clients on 40 devices. Client C does something aggressive, gets a client-level enforcement action, and because devices were reused across clients, Clients A, B and F lose accounts too. You now have three angry contracts and no evidence of what happened.
The structure
- One workspace per client. Hard boundary. Devices, identities, proxies and RPA flows do not cross it.
- One identity per account. Never run two client accounts on one identity even for the same platform.
- One carrier IP per identity. Shared IPs are the second most common contagion vector after shared hardware IDs.
- Scoped seats. An operator working across three clients gets three device-group scopes, not global access.
- Monthly audit export. CSV or JSON, attached to the client report. This is what turns an argument into a document.
What to tell a client who asks
Clients increasingly ask how their accounts are isolated. The honest answer, if you are structured as above: each of your accounts runs on a dedicated device identity with its own hardware identifiers, its own carrier IP and its own storage sandbox, in a workspace that no other client's operators can access. Nothing is shared, so nothing propagates. Here is the audit trail.