Tenancy
One Monroe per workspace. Always.
Every customer gets a dedicated Monroe instance, isolated, with its own state, skills, memory, and credentials. Agent compute, state, and context are isolated per workspace, never shared with another customer’s Monroe.
- Dedicated agent runtime per workspace: compute is never shared
- Per-workspace encrypted volume, with access scoped to that workspace alone
- Broker-only ingress: nothing but Monroe’s own broker can reach an agent
- Database rows tenant-scoped with row-level security, so cross-tenant reads are structurally blocked