Client Governance: Keeping AI Agents Inside Each Client's Account
When your team works for several clients, one person can have access to all of them, and so can the AI agent they connect. Client governance gives each client account its own rules, so an agent connected for one client can't reach another client's work. It's optional, and accounts that don't need it carry on as before.
One account per client
Start by giving each client its own Raq.com account. People who work across clients can belong to several accounts, which is where the controls come in.
In Settings, open Security, switch the account to Client governance and press Select Client Boundaries. That picks three settings together: one client per connection, keep agent runs inside this account, and block cross-account agent requests. Nothing changes until you've reviewed the choices and saved them.
From then on, Raq.com checks which account every agent request is aimed at, including requests made inside other tools and steps queued by automations. If an agent connected for one client asks for another client's records, Raq.com refuses, even when the person who connected it can open both accounts. The agent doesn't have to get the boundary right, because the check happens before the request reaches any data.
A connection approved for several accounts won't meet the one-client rule, so set up a fresh connection for the client when you onboard them.
Who can get in, and for how long
You can require two-factor authentication for everyone in a client's account, or sign-in through the client's verified Google Workspace or Microsoft organisation. Session limits sign people out after a set time, or when they've been idle. Anyone who doesn't meet a rule gets a step to sign in again or set up two-factor before they can open the account.
Agent connections can be read-only, and they can expire after a set number of days. Removing a connection on the Security page stops it straight away, including tokens the assistant is already holding.
IT partners can manage client accounts from their own account. The client's owner approves the management link and any policy the partner proposes. Partner staff get access that expires, and they can't rewrite the client's security settings. Access from the Raq.com support team can need the owner's approval too.
Where AI processing happens
Text and chat AI use global routing by default, with Zero Data Retention. For a client that needs it, lock the account to EU/EEA or US processing. Supported model requests then only go through endpoints in that region. If a model isn't available there, the request fails rather than quietly taking a global route, and retries stay in the region too.
Features that can't honour the lock are switched off for that account. That includes sandboxed agents, which hold their own model access, and the document design service. Shared PDF exports are rendered on Raq.com's own servers instead. You can also lock Zero Data Retention, choose which models are allowed and block individual suppliers.
The region setting covers AI processing. Whichever region you pick, your workspace is stored on our servers in Germany and Finland and in European file storage. Image, video and voice generation use their own providers, so block those suppliers if a client shouldn't use them. The subprocessor list shows where each service runs.
Showing a client what happened
Each client account has its own audit log. With client governance on, it records sign-ins, security changes and every agent tool call, next to the person the agent acted for. A refused request is logged in the account the agent tried to reach. You can filter the log by person, category or date and export it as CSV.
The Data and processing page exports a trust pack with the account's current settings, connections and processing services, ready to share with the client or an auditor. Another setting keeps prompt and response content out of new AI diagnostic logs, and there are switches to turn off shared links, AI web search and support transcript emails for the account.
Working with health and care data
If you're planning to use health or social care records, talk to us first. We'll agree the processing purpose, a data processing agreement and any supplier terms with you, alongside your own impact assessment. The settings are one part of that.
Raq.com controls what an assistant can read or change. Once information has reached ChatGPT, Claude or another assistant, that provider's terms apply, so use a separate conversation or environment for each client.
A useful first trial uses two client accounts with made-up records. Connect an agent to one, ask it for the other's work, then find the refusal in the audit log. Email security@vu.co.uk if you'd like us to walk through it with you.