CategorysafetyManual1.2Evidencedocumented
ProblemA workload genuinely needs its own credential set and the product offers no per-Bot isolation.
TechniqueGive the workload its own Cursor user. Buy the seat.
Why it worksThe only real isolation boundary on offer is the account, because the microVM is assigned per user.
When to useClient confidentiality, regulated data, anything a security review must be able to point at.
When not toWhen shared-session handoff between Bots is the point of the workflow; a second user loses it.