Data isolation between workspaces and clients
Agencies trust a platform with many clients' data. AdAce Ads isolates it at the database level, not only in the application code.
What it does
Every table with customer data uses enforced row-level security in PostgreSQL: each query sees only rows of the current workspace, and managers and analysts only rows of their assigned clients. Separate processes — analytics collection, the executor, automations, token revocation — run under separate database roles with the minimum rights they need.
Automated tests check that data from another workspace is invisible, that forbidden writes are refused by the database itself, and that each process can touch only the columns it needs.
Why it helps
- Defense in depth: application bugs cannot leak data across agencies.
- Client confidentiality inside one agency.
- Least-privilege processes limit the impact of any failure.
How to set it up
- Nothing to configure — isolation is always on.
- Use client assignments to control what managers and analysts see.
Good to know
- Public dashboards and kits expose only what you explicitly share.
- Service staff access is governed by the privacy policy.



Try it on your own accounts
Create a workspace, connect Google or Meta in a couple of clicks and see your accounts clearly. Changes follow your approvals or the policy you configure.
Create your workspace