Multi-client

One bill. Ten walls between your clients.

Every client gets a workspace with its own accounts, brand kits, calendar, members and API keys. Contractors see one client. Clients see their own calendar, read-only. You see everything, on a single invoice.

Northwind Retailisolated
7 profiles3 membersRetail — warm, seasonal
Halcyon Studioisolated
4 profiles2 membersIndie — lowercase, playful
Meridian Healthisolated
5 profiles4 membersClinical — cautious, cited

up to 10 workspaces · 50 profiles · 20 collaborators on Business

The pattern that works

How to set up a client in four moves

01

One workspace per client

Its own connected accounts, brand kits, calendar, members, API keys and activity log. Not a folder — a boundary.

02

Account manager as Admin

Can invite people, connect and disconnect the client’s accounts, edit brand kits and publish. Cannot touch billing or delete the workspace.

03

Writers as Schedulers

Can draft, schedule, publish and use the AI agent. Cannot manage people or reach the connected accounts themselves.

04

The client as Visitor

Read-only on posts, calendar, brand kits and activity. Full visibility, zero ability to move a scheduled post at 11pm.

The six things that go wrong at an agency, and what prevents each

A contractor sees another client’s accounts

Workspaces are isolated. A member of one has no route to another — not a hidden tab, not an API call.

A client changes something and nobody knows

Visitor is genuinely read-only, and the activity log attributes every change that does happen.

Somebody publishes to the wrong account

Explicit profile targeting is the default; whole-platform fan-out is opt-in. Every API key is bound to one workspace.

A token expires mid-campaign

Account health surfaces connections whose token has expired or is close to it, before a scheduled post fails on one.

Copy drifts off the client’s brand

Each workspace holds its own brand kits, read before every AI generation. Eleven clients, eleven voices.

Onboarding a client takes a week

Create a workspace, run the OAuth connect flows, write a brand kit. Same afternoon.

Client-safe seats

Visitor is read-only in the strict sense — no edit path exists, not even a disabled one that a determined click finds.

Provenance on everything

Author on every post, activity log on every change. The AI agent appears as its own author rather than as whoever was logged in.

One invoice

Workspaces do not multiply billing. Credits and AI tokens are pooled on the account and spent wherever the work happens.

Agency FAQ

How do agencies keep client accounts separated?+

With workspaces. Each holds its own connected social accounts, brand kits, calendar, members, API keys and activity log, and membership does not cross between them. A freelancer invited into one client’s workspace cannot see or reach another client’s accounts by any route.

Can clients review and approve posts?+

Clients get a read-only Visitor seat: they see the calendar, drafts, scheduled posts, brand kits and activity, and can change nothing. For AI-driven work there is an explicit approval gate — anything the agent wants to publish, edit or delete is accepted or rejected by a human first.

How many clients can I run on one account?+

Workspaces by plan: 1 on Free, 3 on Starter, 5 on Professional and 10 on Business — with 50 connected profiles and 20 collaborators at the Business tier. All on a single bill.

Can each client have their own brand voice?+

Yes, and multiple. Brand kits are per workspace and named, holding voice, target audience, guidelines, keywords, a style image and reusable assets. Every AI generation names the kit it should write against, so eleven clients get eleven voices rather than one house tone.

Is there an audit trail?+

Every post carries its author, and the workspace activity log records what changed and who changed it — including the AI agent, which appears as its own author. On a shared calendar with contractors and an agent both writing, that provenance is what makes review possible.

Can I integrate it with our own systems?+

Yes. Every action is available at POST /api/tools/{name} with an API key scoped to a workspace, and multicall batches up to 20 operations per request. Reporting, intake forms and client dashboards can read and write the same queue the team uses.