# Keeping client data separate

How a consultant runs many clients in one account without mixing them: one isolated workspace per client, data segregation, role-based access with a dedicated Client role, and Client View.

Published: 2026-09-17

## The consultant's first rule

A consultant who serves several clients in the same market lives with one non-negotiable: nothing from one client may reach another. Not a document, not a number, not a hint in a chat. Tools built for a single company rarely respect that rule, because they were never asked to. A Haycion workspace was built for the consultant, so the rule is the architecture, not a setting.

## One workspace per client

Each client is its own workspace. The company baseline, competitors, segments, opportunities, reports, uploads, conversations and agent all belong to that workspace and to no other. Workspace records and files are stored and served per workspace, so isolation does not depend on a filter being applied correctly on every screen. You switch between clients from the sidebar, and what you see is only ever one client at a time.

## Role-based access

Access to a workspace is by membership and role. There are three workspace roles: Administrator, who manages the workspace and its members; User, who works in it; and a dedicated Client role for the client's own people. Membership and role are checked when a request is served, not just when a page is drawn. Someone invited to one workspace has nothing in any other until they are invited there too.

At the account level, an administrator manages the team and the plan across every workspace, and a team access overview shows who has which role where, so an offboarding is one screen rather than a hunt.

## Client View

Giving the client access is how a project becomes a retainer, and it only works if you control what they see. Client View does that with about two dozen switches, one per part of the workspace: the profile, the products, the personas, the competitors, the Strength Matrix, the opportunities, the reports, the brief and so on, plus whether the client can edit at all. Everything is off until you switch it on.

Six presets match the usual stages of an engagement, from an initial analysis through detailed competitive work, positioning and messaging, competitor and media tracking, a fully trained agent, and finished collateral. Pick the preset for where the engagement is, adjust a switch or two, and use the preview mode to see the workspace exactly as the client will. Then invite them.

## Invitations and the team

Colleagues and clients join a workspace by invitation, with the role set at invitation time. A consultant working alone can keep every workspace to themselves; a practice can put an associate on three workspaces and a partner on all of them, and the team access overview keeps the picture honest.

## Billing stays separate from workspaces

Plans and credits belong to the account, not to a client workspace. Every workspace draws from the same credit pool, and adding or deleting a client never touches billing. The [pricing page](/pricing) describes the pool.

## What crosses between clients, and what does not

Public research is shared. If two of your clients compete with the same company, what the workspace learned about that competitor from its public site and the open web is available to both, because it was never private. Nothing else crosses. Uploads stay in the workspace they were added to. Overrides, notes, reports, conversations and the agent's knowledge stay where they were made.

Experiments are sandboxed too. A positioning scenario runs in its own copy of the workspace, so a pivot you model for one client cannot leak into that client's live workspace, let alone another client's.

## One client, one agent

Each workspace can have one agent, and that agent is grounded in that workspace alone. It says only what the workspace's checked profile says, within the guardrails you and the client agree, and it learns nothing from any other client's workspace. Nothing about a client is published until you publish it, and publishing requires the client's domain to be verified first.

## What the client receives

- A workspace that is theirs, separate from every other client you serve.
- Access under a role built for clients, seeing exactly what you switched on.
- A workspace they can be invited into at the right stage, with a preset that fits.
- Confidence that their uploads, corrections and reports never leave their workspace.
- An agent that represents only them.

## How it shows its work

Isolation is visible, not implied. The sidebar shows one client at a time. The team access overview lists every member and role per workspace. Client View lists every switch and its state, and the preview mode shows the result before the client does. The [security page](/security) states the controls plainly, including what is not claimed.

## What a result looks like

A practice with a dozen clients runs a dozen workspaces. Two associates each sit on four; the partner sits on all twelve. Six clients have been given access with the Client role, each on the preset for their engagement stage. Nobody, including the partner, ever sees two clients on one screen, and the client who asks "can our competitor's consultant see this" gets a straight answer.

## Questions consultants ask

### Can one client ever see another client's workspace?

No. Each client is a separate workspace with its own data. A person invited to one workspace has no access to any other unless they are separately invited there.

### What roles are there?

Per workspace: Administrator, User and a dedicated Client role. Administrators manage the workspace and its members, Users work in it, and Clients see what Client View lets them see.

### What does Client View control?

About two dozen switches, one per part of the workspace, plus whether the client can edit. Six presets cover the usual engagement stages, and a preview mode shows you the workspace exactly as the client would see it.

### Is billing tied to a workspace?

No. Plans and credits belong to your account and are shared across every workspace on it. Adding or deleting a client workspace does not touch billing.

### Does research on one client help another?

Only through the public web. If two clients share a competitor, what the workspace learned about that competitor from public sources is available to both. Nothing private to one workspace reaches the other.

### Can the client's agent learn from other clients?

No. One workspace, one client, one agent. The agent is grounded in its own workspace and nothing else.

---

Canonical: https://haycion.com/what-it-does/keeping-client-data-separate
Source: Haycion, https://haycion.com/
