Features
Workspaces
Separate customers, products and environments
Workspaces are the operating boundary for keys, routing policy, budgets and evidence. Design them around ownership and risk rather than convenience.
Choose a clear boundary
A workspace should make ownership, environment and data policy unambiguous.
- Separate production from development
- Separate customers where policy or evidence must remain isolated
- Give family products explicit ownership
- Document the operator responsible for key rotation and incidents
Issue workspace keys
Applications receive Router credentials for their workspace. Upstream provider credentials stay behind the Router boundary and are never distributed to product clients.
Attach policy and budgets
Workspace policy defines eligible routes and regions. Budget controls limit consumption without requiring each product to implement provider-specific spend logic.
Retain operational evidence
Use request metadata, usage records and service logs according to the workspace's operational and data obligations.
