Last reviewed: 2026-09-14
Client organizations
Separate agency or multi-client security work with clear organization boundaries, least privilege, and tokens that are never shared across clients.
Keep client work separated
Agencies and multi-client teams should place each client’s work in separate organizations, or maintain explicit boundaries where separation is not possible. Results, policies, exports, and audit evidence must remain attributable to the right client.
Access and automation
Give people access only to the client organization they need. Create separate service tokens and secret-store entries for each client; never share a token across clients. Automations should set and verify the intended organization before resolving repositories or reading results.
Who can list or create client organizations: owners and admins of the parent organization. Platform CC admins may also list and create client organizations when operating in a customer org (they do not need a membership row on that parent).
Edge cases
A consultant who can access several clients can accidentally operate in the wrong organization. Check the organization and repository identity before an export, policy change, or scan. When an engagement ends, remove membership and rotate client-specific credentials according to the client’s process.