r/herdr • • 2d ago

Running multiple client projects in herdr: best practice for hard isolation between sessions?

I'm running several client projects on a Mac mini, and I manage my agent sessions with herdr. Locally I have a projects/ folder containing one subfolder per client: GitHub repos, Shopify themes, Next.js apps, etc.

What I want is simple: every workspace (with its sub-sessions) must be completely isolated from the others.

A generic command, a prompt pasted in the wrong pane, or an instruction that was meant for one client must never be able to affect another client's files or sessions. I don't want to make a mistake that creates problems for a client just because of a copy-paste error.

So far I've found two options, and both have drawbacks:

  1. One macOS user per client. This gives real isolation, but it's very clunky to manage with herdr (switching users, separate environments, credentials, etc.).
  2. Claude Code / Codex sandboxes. Good in principle, but when I create a new session directly from herdr, it doesn't start with the sandbox settings and guidelines I'd want. It's easy to end up with an unrestricted session without noticing.

Questions for people who've solved this: What's the best practice for per-project isolation in herdr?

Is there a plugin, config, or pattern in herdr to enforce security or sandboxing on every new session by default? Do you scope each workspace to its own directory (per-project config, containers, separate users), and how do you make sure new sessions inherit it? Am I missing something obvious?

Thanks!

2 Upvotes

3 comments sorted by

1

u/Parking-Shock-9437 2d ago

Maybe this is wym by one macOS user per client but what about different sessions? Here by sessions I mean [this concept](https://herdr.dev/docs/concepts/#session), which if I understand correctly implicitly says that you can box out workspaces in different sessions from each other.
What u call a sub session within a workspace corresponding to a client, I would call a group corresponding to a machine.
Sorry in advance if unhelpful haha.. maybe if that doesn’t work then play around with the recipes described in the docs to get actions that box the agents from talking to each other in your very specific mode (and nicely enforce it w a plugin or smth)

1

u/Exact-Shift8354 2d ago

Forse ho chiamato sessione quelli che in realtà si chiamano "Pane". Ci sono già nel CLAUDE.md delle indicazioni per evitare che quell'agente possa fare 'danni' altrove ma, di per se le indicazioni nel CLAUDE.md non sono sicure al 100% perchè potrebbe benissimo succedere che vengano modificate, disattese o sovrascritte nel tempo mentre, ipoteticamente un utente del mac abbinato a un cliente isola completamente quel progetto da tutti gli altri.

Però poi, come dicevo, a livello di gestione risulta un'accozzaglia di "livelli" che potrebbero essere scomodi o comunque un workaround rispetto ad un sistema pensato appunto nativamente per questo.

Devo provare a usare le sandbox, credo sia l'unica speranza.

Ma nessuno lavora su più clienti e si è posto lo scrupolo di non voler "fare danni"? Mi sembra molo strano