---
title: "Separate Client Context Before an Agent Touches the Work"
description: "Keep each client's sources, permissions, drafts, and receipts in a separate context packet before an agent begins work."
canonical: "https://scalewithsearch.com/articles/separate-client-context-before-agent-work"
date: "2026-08-17"
modified: "2026-09-19"
---
## Site navigation

- [Scale With Search](https://scalewithsearch.com/)
- Real estate
  - Real estate
    - [Real estate](https://scalewithsearch.com/for/real-estate)
- Work
  - Start here
    - [Send your brief](https://scalewithsearch.com/work#send-your-brief)
    - [Prepare your six-question brief](https://scalewithsearch.com/work#prepare-your-six-question-brief)
  - Build
    - [Site build, content library with SEO, signal desk](https://scalewithsearch.com/work)
- For your business
  - Trades and home services
    - [Auto body and collision shops](https://scalewithsearch.com/for/auto-body-and-collision-shops)
    - [Foundation and home repair contractors](https://scalewithsearch.com/for/foundation-and-home-repair)
    - [Garage door and fencing contractors](https://scalewithsearch.com/for/garage-door-and-fencing-contractors)
    - [HVAC contractors](https://scalewithsearch.com/for/hvac-contractors)
    - [Janitorial and commercial cleaning companies](https://scalewithsearch.com/for/janitorial-and-commercial-cleaning)
    - [Locksmiths](https://scalewithsearch.com/for/locksmiths)
    - [Moving companies](https://scalewithsearch.com/for/moving-companies)
    - [Pest control companies](https://scalewithsearch.com/for/pest-control-companies)
    - [Plumbing and electrical contractors](https://scalewithsearch.com/for/plumbing-and-electrical-contractors)
    - [Restoration and water or fire damage companies](https://scalewithsearch.com/for/restoration-and-water-fire-damage)
    - [Roofing companies](https://scalewithsearch.com/for/roofing-companies)
    - [Towing companies](https://scalewithsearch.com/for/towing-companies)
    - [Tree services and landscaping companies](https://scalewithsearch.com/for/tree-services-and-landscaping)
    - [Solar installers](https://scalewithsearch.com/for/solar-installation)
    - [General contractors](https://scalewithsearch.com/for/general-contractors-and-construction)
    - [Paving, concrete, and flooring contractors](https://scalewithsearch.com/for/paving)
  - Practices and professional services
    - [Bookkeeping and tax practices](https://scalewithsearch.com/for/bookkeeping-and-tax-practices)
    - [Dental practices](https://scalewithsearch.com/for/dental-practices)
    - [Family and criminal defense law firms](https://scalewithsearch.com/for/family-and-criminal-defense-law-firms)
    - [Med spas and aesthetics practices](https://scalewithsearch.com/for/med-spas-and-aesthetics)
    - [Personal injury law firms](https://scalewithsearch.com/for/personal-injury-law-firms)
    - [Veterinary clinics](https://scalewithsearch.com/for/veterinary-clinics)
    - [Gyms and fitness studios](https://scalewithsearch.com/for/fitness)
    - [Therapy and outpatient health practices](https://scalewithsearch.com/for/therapy-and-outpatient-health)
    - [Medical billing companies](https://scalewithsearch.com/for/medical-billing)
    - [Insurance agencies](https://scalewithsearch.com/for/insurance-agencies)
    - [Financial advisors](https://scalewithsearch.com/for/financial-advisors)
    - [Property management companies](https://scalewithsearch.com/for/property-management)
    - [Recruiting and staffing agencies](https://scalewithsearch.com/for/recruiting-and-staffing)
    - [Architects and interior designers](https://scalewithsearch.com/for/architects-and-interior-designers)
    - [Logistics and supply chain companies](https://scalewithsearch.com/for/logistics-and-supply-chain)
  - Agencies, MSPs, and manufacturing
    - [IT and managed service providers](https://scalewithsearch.com/for/it-and-managed-service-providers)
    - [Machine shops and precision manufacturers](https://scalewithsearch.com/for/machine-shops-and-precision-manufacturing)
    - [Marketing agencies and freelancers](https://scalewithsearch.com/for/marketing-agencies-and-freelancers)
    - [SEO agencies and consultants](https://scalewithsearch.com/for/seo-agencies-and-consultants)
    - [Small manufacturers and fabricators](https://scalewithsearch.com/for/small-manufacturers-and-fabricators)
  - Restaurants, shops, studios, and nonprofits
    - [Restaurants and hospitality businesses](https://scalewithsearch.com/for/restaurants-and-hospitality)
    - [Retail stores and ecommerce sellers](https://scalewithsearch.com/for/retail-and-ecommerce)
    - [Photographers, event planners, and travel agents](https://scalewithsearch.com/for/photographers)
    - [Churches and nonprofits](https://scalewithsearch.com/for/churches-and-nonprofits)
  - [All industries](https://scalewithsearch.com/for/)
- Learn
  - For your office
    - [Office job guides](https://scalewithsearch.com/guides/)
    - [Browser calculators](https://scalewithsearch.com/tools/)
  - Start here
    - [How it works](https://scalewithsearch.com/how-it-works)
    - [Free Starter Kit](https://scalewithsearch.com/kit/business-memory-starter-kit.zip)
    - [Synthetic specimen](https://scalewithsearch.com/specimen/working-session-specimen.zip)
  - Guides
    - [The Complete Guide to Business Memory for AI Agents](https://scalewithsearch.com/articles/business-memory-for-ai-agents-guide)
    - [The Complete Small-Business Guide to AI Agent Governance](https://scalewithsearch.com/articles/ai-agent-governance-guide-small-business)
    - [The Complete Guide to Leaving Vendor AI Memory](https://scalewithsearch.com/articles/leaving-vendor-ai-memory-guide)
  - Articles by cluster
    - [Business memory](https://scalewithsearch.com/articles/business-memory-for-ai-agents-guide)
    - [Agent governance](https://scalewithsearch.com/articles/ai-agent-governance-guide-small-business)
    - [Migration and ownership](https://scalewithsearch.com/articles/leaving-vendor-ai-memory-guide)
  - For machines
    - [llms.txt](https://scalewithsearch.com/llms.txt)
    - [llms-full.txt](https://scalewithsearch.com/llms-full.txt)
    - [Machine view](https://scalewithsearch.com/?view=machine)
- Company
  - Evidence
    - [Proof](https://scalewithsearch.com/proof)
  - Company
    - [About](https://scalewithsearch.com/about)

# Separate Client Context Before an Agent Touches the Work.

The draft looks right until the client reads the final paragraph. It uses another company's offer, another owner's tone, and a deadline from an unrelated project.

Nothing was invented. The agent retrieved the wrong truth.

Client separation starts before the prompt. Each job should resolve to one client identity, one allowed source set, one output location, and one approval owner. If identity cannot be resolved, the agent stops.

## A folder is useful, but a manifest is the boundary

Separate folders reduce accidental mixing:

```text
clients/
  CL-001/
    context/
    sources/
    drafts/
    approvals/
    receipts/
  CL-002/
    context/
    sources/
    drafts/
    approvals/
    receipts/
```

The folder alone is not enough. Search tools, shared indexes, copied templates, and broad credentials can still cross the line. A manifest must state which paths and systems belong to the job.

NIST's AI RMF is a voluntary framework, and its Generative AI Profile describes recording provenance and addressing personal, privileged, proprietary, and sensitive data in the AI system inventory as an outcome. [NIST AI 600-1, Generative AI Profile](https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf)

## Resolve identity before retrieval

Do not let the model infer the client from a company name inside an email. Resolve a stable identifier first.

The intake can map a domain, account ID, or project ID to `CL-001`. If two records match, stop. If no record matches, stop. A human resolves the identity before retrieval begins.

Once resolved, every source and output path should carry that identifier. The receipt should carry it too.

## Keep retrieval client-scoped

The retrieval layer should search only approved roots and indexes. Do not retrieve from the entire drive and ask the model to discard unrelated results.

The allowed set may include:

- the current client brief;
- signed scope or accepted project record;
- approved brand rules;
- client-provided source documents;
- prior accepted deliverables;
- current correction record.

Shared templates may be read as structure. They must not contain another client's data.

## Match provider controls to the data

Local separation does not answer what an external model provider retains. OpenAI's guide to your data states, in general terms, how API data is retained and how training defaults apply to API traffic. Read the current version of that page and your own contract before sending confidential client records anywhere. [OpenAI: Data controls in the API platform](https://developers.openai.com/api/docs/guides/your-data)

The same check applies to every provider and connected tool. A vendor setting does not replace your own access control, minimization, and client agreement.

## Client or regulated data is not automatically safe to include

There is no universal "safe for AI" label.

The answer depends on the data, the buyer's authority, the client agreement, the provider contract, the account configuration, the endpoint or product used, retention behavior, access controls, region, and the purpose of processing.

OpenAI's current API data-control documentation distinguishes training, abuse-monitoring retention, application-state retention, and eligibility for controls such as Zero Data Retention by endpoint. It also notes that some capabilities may retain application state even when a stricter control is enabled. [OpenAI: Data controls in the API platform](https://developers.openai.com/api/docs/guides/your-data)

That page supports a decision process. It does not grant permission to send a client's records to the service.

Before real client or regulated data enters a workflow, write `data-use-decision.md`:

```text
job:: prepare internal account brief
data_owner:: client account owner
data_classes:: business confidential, contact data
prohibited_data:: payment card data, health data, credentials
provider_product:: exact workspace or API project
provider_terms_reviewed:: URL and date
retention_setting:: confirmed account setting
training_setting:: confirmed account setting
region_or_residency:: confirmed when required
client_authority:: contract or written approval reference
minimum_fields:: account ID, active scope, current status
decision:: permitted, permitted with redaction, or prohibited
reviewer:: named data owner
```

If the workflow involves protected health information, financial records, legal privilege, employment records, children's data, or another regulated class, require qualified review of the applicable agreement and configuration. Do not infer suitability from a marketing page or a generic enterprise label.

When the decision is unclear, use synthetic or redacted fixtures and stop before real records are transmitted.

## The file to inspect

Create `clients/CL-001/context-manifest.yaml`:

```yaml
client_id: CL-001
display_name: Example Client One
allowed_roots:
  - clients/CL-001/context/
  - clients/CL-001/sources/
  - templates/approved/
output_root: clients/CL-001/drafts/
receipt_root: clients/CL-001/receipts/
forbidden_roots:
  - clients/CL-002/
  - prospects/
  - private-notes/
approved_connectors:
  - client_one_drive_readonly
approval_owner: client_account_owner
stop_before:
  - external_send
  - publish
  - production_write
  - crm_write
stop_early_if:
  - client identity is ambiguous
  - a requested source is outside allowed_roots
  - the output requests another client identifier
```

## Test separation directly

Put a harmless marker in `clients/CL-002/sources/isolation-test.txt`. Ask the CL-001 workflow a question that would tempt it to retrieve that marker.

The test passes only when:

- the CL-002 path is not read;
- the marker is absent from the output;
- the receipt lists only CL-001 and approved shared paths;
- the workflow stops if the answer requires the forbidden source.

Also test output routing. A CL-001 job must not write to the CL-002 draft or receipt folders.

## Test connector and index boundaries

Folder isolation can pass while a shared search index still leaks results.

Run the same marker test through every retrieval route the agent can use: local search, vector index, cloud-drive connector, CRM query, and cached result store. The receipt should name the route and client identifier used for each lookup.

Also test a copied template. Use the [business-file prompt-injection test](/articles/test-ai-agent-prompt-injection-business-files) to confirm the workflow treats template content as structure only. Shared examples should never become a path for another client's facts.

Test the output side too. A correct draft written to the wrong client folder is still a separation failure. Validate the client identifier in the output path, receipt path, and any proposed external destination before the workflow presents the run as complete.

## Keep access narrower than model capacity

An agent may be capable of searching an entire drive. That does not make broad drive access appropriate.

Give the workflow a client-scoped credential or query when the connected system supports it. If the provider offers only broad access, add a deterministic filter before model retrieval or keep the workflow manual. Prompt text should not be the only client boundary.

Record who can change the manifest and connector scope. The agent can request a missing source. It cannot approve wider access for itself.

Test revocation as well as access. Remove the client-scoped credential or manifest entry in a test environment and confirm the workflow stops. A cached index, old token, or copied local file should not let the next run continue silently. Record which caches and derived stores require deletion or isolation when access ends.

The test does not prove compliance with every client or regulatory obligation. It proves that the implemented path respects the boundary you named.

## Approval boundary and stopping point

The agent may prepare work inside the resolved client folder. It stops before any external send, public publication, production write, booking, spending, or CRM change.

It stops immediately when identity is ambiguous or a source falls outside the manifest. A human may expand the manifest after checking authority and confidentiality. The agent cannot expand its own source boundary.

## Sources

- [NIST: Generative AI Profile](https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf)
- [OpenAI: Data controls in the API platform](https://developers.openai.com/api/docs/guides/your-data)


## Questions about Separate Client Context Before an Agent Touches the Work

### Under one assistant, is context shared between threads?

Do not rely on a broad assistant or shared index as the client boundary. Resolve one stable client identifier first, then retrieve only from the approved roots and indexes named in that client's manifest.

### If I want to make sure that only user A's messages are used for User A and only user B's messages are used for User B, do I need dedicated threads or dedicated assistants?

The workflow should carry a resolved client or user identifier through every source, output path, receipt, connector, and retrieval query. Test each route for cross-context leakage instead of asking the model to discard unrelated results after broad retrieval.

### How do you handle user authentication and authorization in multi-tenant RAG systems?

Use client-scoped credentials or queries when available, and restrict retrieval to approved roots and indexes before the model sees results. Test local search, vector indexes, cloud connectors, CRM queries, and cached stores with forbidden-client markers.

### Has anyone here done security auditing on multi-tenant or user-isolated RAG systems?

Put a harmless marker in a forbidden client's source folder and verify that the workflow cannot retrieve, output, or route it. Also test output folders, receipts, connector boundaries, shared indexes, revocation, and cached results.

## Save the visual summary

A folder is useful, but a manifest is the boundary | Resolve identity before retrieval | Keep retrieval client-scoped | Test separation directly

[Download the PNG](/infographics/separate-client-context-before-agent-work-1200x1500.png)


## Related: Agent Governance

- [How to Keep Businesses, Clients, and Roles Separate for AI Agents](/articles/separate-business-contexts-ai-agents)
- [Voice AI Context Retention: What Should Survive the Next Call?](/articles/voice-ai-context-retention-across-sessions)
- [How to Keep Customer Conversation History Across Gmail, HubSpot, Notion, ChatGPT, and Claude](/articles/customer-conversation-memory-across-tools)

----

```text
                  .|########||.                                       .|########||.                                       .|########||.
               |##||.      .||##|.                                 |##||.      .||##|.                                 |##||.      .||##|.
             |#|.              .|#|.                             |#|.              .|#|.                             |#|.              .|#|.
           |#|                    |#|                          |#|                    |#|                          |#|                    |#|
         .#|                        |#.                      .#|                        |#.                      .#|                        |#.
        .#.                          .#|                    .#.                          .#|                    .#.                          .#|
       |#.                            .#|                  |#.                            .#|                  |#.                            .#|
      |#             ......             #|                |#             ......             #|                |#             ......             #|
     .#           ||#########|           #|              .#           ||#########|           #|              .#           ||#########|           #|
    .#.         |######||######|.        .#.            .#.         |######||######|.        .#.            .#.         |######||######|.        .#.
    #.        .##|###|##|#|######|        .#            #.        .##|###|##|#|######|        .#            #.        .##|###|##|#|######|        .#
   ||        |##|#||||||||||||#||#|        ||          ||        |##|#||||||||||||#||#|        ||          ||        |##|#||||||||||||#||#|        ||
   #        |#||||||||||||||||||||#|        #.         #        |#||||||||||||||||||||#|        #.         #        |#||||||||||||||||||||#|        #.
  ||       |#||||||||||||||||||||||#|       ||        ||       |#||||||||||||||||||||||#|       ||        ||       |#||||||||||||||||||||||#|       ||
  #       .#||||||||||||||||||||||||#|       #        #       .#||||||||||||||||||||||||#|       #        #       .#||||||||||||||||||||||||#|       #
 ||   ....|||#||||||##|#|||#|#||##||||....|. ||      ||   ....|||#||||||##|#|||#|#||##||||....|. ||      ||   ....|||#||||||##|#|||#|#||##||||....|. ||
 #.  .  ....|#  ....#|||   ||| .#|||  ....#. .#      #.  .  ....|#  ....#|||   ||| .#|||  ....#. .#      #.  .  ....|#  ....#|||   ||| .#|||  ....#. .#
 #   .  ||||#| .#####||  . .#| .#|||  ||||#   #.     #   .  ||||#| .#####||  . .#| .#|||  ||||#   #.     #   .  ||||#| .#####||  . .#| .#|||  ||||#   #.
.|   |||||  #. |#|||||. ||  #. |#||. .|||||   ||    .|   |||||  #. |#|||||. ||  #. |#||. .|||||   ||    .|   |||||  #. |#|||||. ||  #. |#||. .|||||   ||
||   |....  #. ....|#.      |. ...|. ....||   ||    ||   |....  #. ....|#.      |. ...|. ....||   ||    ||   |....  #. ....|#.      |. ...|. ....||   ||
#.  .||||||##||||||##||####|||||||#||||||#|   .#    #.  .||||||##||||||##||####|||||||#||||||#|   .#    #.  .||||||##||||||##||####|||||||#||||||#|   .#
#    .||####|###########################|.     #    #    .||####|###########################|.     #    #    .||####|###########################|.     #
#      .#||||||.#.|| # |. ..# #| #|||||#|      #    #      .#||||||.#.|| # |. ..# #| #|||||#|      #    #      .#||||||.#.|| # |. ..# #| #|||||#|      #
#      .#|||||| ..  |# ## |#| ...#|#|||#|      #    #      .#|||||| ..  |# ## |#| ...#|#|||#|      #    #      .#|||||| ..  |# ## |#| ...#|#|||#|      #
#      .#|||#|# .# .#| #| ##|.#..#|||||#|      #    #      .#|||#|# .# .#| #| ##|.#..#|||||#|      #    #      .#|||#|# .# .#| #| ##|.#..#|||||#|      #
#      .#||||||############|######|||||#|      #    #      .#||||||############|######|||||#|      #    #      .#||||||############|######|||||#|      #
#   |...||#||||||#||||#|#||||||#|||||#||| |.|  #    #   |...||#||||||#||||#|#||||||#|||||#||| |.|  #    #   |...||#||||||#||||#|#||||||#|||||#||| |.|  #
#. .. ||||# .|||##|.  |#| .|| || .|||#. #|  # .#    #. .. ||||# .|||##|.  |#| .|| || .|||#. #|  # .#    #. .. ||||# .|||##|.  |#| .|| || .|||#. #|  # .#
|| |  ...||  ...##| |  #| .|. |. #####  .. .| ||    || |  ...||  ...##| |  #| .|. |. #####  .. .| ||    || |  ...||  ...##| |  #| .|. |. #####  .. .| ||
|| ||||| || ||||#|  .  |. |. |#. ||||| |#| || ||    || ||||| || ||||#|  .  |. |. |#. ||||| |#| || ||    || ||||| || ||||#|  .  |. |. |#. ||||| |#| || ||
.# |.....#|....|#.||||.|||##.|#|....||.#||.#. #.    .# |.....#|....|#.||||.|||##.|#|....||.#||.#. #.    .# |.....#|....|#.||||.|||##.|#|....||.#||.#. #.
 #.|||||||#############################| ||| .#      #.|||||||#############################| ||| .#      #.|||||||#############################| ||| .#
 ||       ##||#||#||||||#||#||#||#||##.      ||      ||       ##||#||#||||||#||#||#||#||##.      ||      ||       ##||#||#||||||#||#||#||#||##.      ||
  #       .#|||||||||#||#|||||||||||#|       #        #       .#|||||||||#||#|||||||||||#|       #        #       .#|||||||||#||#|||||||||||#|       #
  ||       |#||||||||||||||||||||||#|       ||        ||       |#||||||||||||||||||||||#|       ||        ||       |#||||||||||||||||||||||#|       ||
  .#        |#||||||||||||||||||||#|        #.        .#        |#||||||||||||||||||||#|        #.        .#        |#||||||||||||||||||||#|        #.
   ||        |#||||||||||||||||||#|        ||          ||        |#||||||||||||||||||#|        ||          ||        |#||||||||||||||||||#|        ||
    #.        .######|#|#########|        .#            #.        .######|#|#########|        .#            #.        .######|#|#########|        .#
    .#.         |#####||||#####|         .#.            .#.         |#####||||#####|         .#.            .#.         |#####||||#####|         .#.
     |#           ||########||           #.              |#           ||########||           #.              |#           ||########||           #.
      |#             ......             #|                |#             ......             #|                |#             ......             #|
       |#.                            .#|                  |#.                            .#|                  |#.                            .#|
        |#.                          .#.                    |#.                          .#.                    |#.                          .#.
         .#|                        |#.                      .#|                        |#.                      .#|                        |#.
           |#|                    |#|                          |#|                    |#|                          |#|                    |#|
            .|#|.              .|#|.                            .|#|.              .|#|.                            .|#|.              .|#|.
               |##||.      .||##|                                  |##||.      .||##|                                  |##||.      .||##|
                 .||########||.                                      .||########||.                                      .||########||.

Scale With Search  2026  [scalewithsearch.com](https://scalewithsearch.com)
```
