First and main separation is at the Organization level. This is the separation of security for each tenant. Compute and storage resources can run on same hosts or different hosts depending on the way you set it up. These resources get carved up as Virtual Datacenters (VDC) and assigned to earch organization. Deploying vShield Edge devices separates network connectivity as well, if needed. It all depends on use case and SLA needs.
Eric