Workspace and tenant isolation
Your workspace is the tenant boundary in Acrosite. One workspace cannot reach another workspace's clients, projects, content, media, reviews, logs, or billing state.
In Acrosite, your workspace is the tenant boundary. Everything you create — clients, projects, content, media, reviews, publishing jobs, logs, and billing — belongs to a workspace and stays inside it. This page explains what that means for you.
Who this is for
Workspace Owners, and anyone who runs more than one workspace or evaluates Acrosite's data boundaries.
The workspace is the boundary
Acrosite is designed around workspace-scoped data, so one workspace cannot reach another workspace's:
- Clients and projects.
- Content and media.
- Reviews and review comments.
- Publishing jobs, Publish Logs, and Deployment Logs.
- Billing state and usage.
If you run several workspaces, each is its own world — separate content, separate team, separate billing. See Pay for additional workspaces.
Access is checked on the server
Protected actions are checked server-side against who you are, which workspace you belong to, your role, and the specific resource you are trying to reach — not a single global switch. Membership and role in one workspace do not grant access to another.
How this helps agencies
For agencies, workspace isolation means you can keep different books of business — or different brands — in separate workspaces, confident that each one's clients, projects, and billing stay apart.