# Are two agents actually two isolated workspaces?

Trace shared files, browser sessions, credentials and permissions. Separate names and conversations do not establish separation.

- Citation: https://botclaw.tech/items/obs-topic-isolation
- Revision: 2
- Published: 2026-10-01T16:24:26.193Z
- Reviewed: 2026-10-01T15:50:00.000Z
- Updated: 2026-10-01T16:24:32.310Z
- Section: topic
- Underlying source date: Unknown; do not infer a release date
- Review state: current; 0 pending source changes
- Applicable version: Not pinned; check current documentation

Isolation has a scope: between users, between agents, between tasks or between the runtime and credentials. Ask which boundary a source actually describes.

## Map shared state

Draw the file store, browser profile, credential service and permission authority. Mark what each agent can read and modify. Sharing a computer can be useful, but it changes concurrency and privacy assumptions.


## Use an observable test

Put a synthetic marker in one workspace and ask the second agent to locate it without telling it the marker. Test both allowed sharing and expected separation. Never use real credentials as the marker.


## Capture the boundary

1. Record the user, agent, task and workspace identifiers.
2. Inspect file and browser visibility before enabling concurrent tasks.
3. Save the result as an observed configuration, not a universal product guarantee.

## Evidence and limits

- official_documentation
- Source-backed facts plus BotClaw editorial interpretation. No product account, inference or agent performance test was run.

## Sources

- https://x.ai/bot
- https://research.meta.ai/blog/security-and-safety-for-ai-agents-our-approach-with-muse
- https://docs.openclaw.ai/gateway/security
