Skip to main content

From the client’s perspective, a professional services engagement may appear straightforward. They appoint the firm, provide information, collaborate with a team and receive advice or a completed piece of work. Behind that experience, however, the engagement may pass through a surprisingly large number of technology systems.

The opportunity could begin in a CRM platform. The engagement may then be created in a practice-management or project-management system. Documents are exchanged through email or a client portal, stored in Microsoft 365 or a document-management platform and discussed in Teams. Employees may use specialist applications to complete the work before recording their time, issuing an invoice and archiving the final records.

Each platform may serve a legitimate purpose. Collectively, they create an environment that an internal IT team must integrate, secure, support and maintain. As the number of systems increases, so does the complexity behind every client engagement.

Follow one engagement through the firm

Consider what happens when a new client appoints a professional services firm. The engagement may involve:

  1. Recording the opportunity and client details in a CRM.
  2. Creating the client or matter in a practice-management platform.
  3. Establishing a project team and assigning responsibilities.
  4. Creating folders, Teams channels or SharePoint sites.
  5. Inviting employees and external parties to collaborate.
  6. Collecting information through email, forms or a client portal.
  7. Moving data into specialist applications for analysis or delivery.
  8. Recording time and project costs.
  9. Producing and approving client deliverables.
  10. Raising an invoice through the finance system.
  11. Closing the engagement and retaining its records.

This process may involve Microsoft 365, document management, finance, CRM, communication, workflow, identity and industry-specific applications. It may also involve integrations that transfer data between them.

When everything works correctly, most employees and clients will never see the complexity. They simply experience a connected workflow. Keeping it that way requires significant work behind the scenes.

Complexity usually accumulates gradually

Few firms deliberately set out to create a complicated technology environment. Complexity generally develops one reasonable decision at a time.

A team adopts a specialist application because the existing platform cannot support an important service. A new collaboration tool is introduced for one major client. A manual process is replaced with a cloud application. Another system arrives through a merger, acquisition or new business unit.

Over time, the firm may accumulate overlapping applications, integrations and information repositories. The result can be difficult to see because each decision solved a legitimate problem. However, the combined environment may create questions such as:

  • Which system contains the authoritative client record?
  • Where should engagement documents be stored?
  • Which integrations transfer sensitive information?
  • Who approves access to each platform?
  • Which applications support single sign-on and multifactor authentication?
  • What happens to access when an employee changes roles or leaves?
  • Which vendor is responsible when an integrated workflow fails?
  • Can the firm see where client information is being shared?

Without a complete view of the environment, small gaps can develop between otherwise well-managed systems.

Integration can improve productivity and increase dependency

Integrations help employees avoid entering the same information repeatedly. They can automate administrative work, improve reporting and create a more consistent client experience. They can also create dependencies that are easy to underestimate.

If information is created in one platform and automatically transferred to three others, a failure at the source can affect the entire workflow. A change to an application programming interface, user account or security setting may interrupt a process that employees assumed would continue automatically.

Integrations may also use service accounts or third-party connectors with broad access to company data. If those connections are not documented and reviewed, the IT team may not have a clear picture of what information an application can access or where it sends that information. For every important integration, firms should understand:

  • Which systems it connects.
  • What information it transfers.
  • How frequently the transfer occurs.
  • Which account or credential supports the connection.
  • Who owns the business process.
  • Who monitors failures.
  • What happens if the integration stops working.
  • Whether the connection remains necessary.

An integration should not become invisible simply because it usually works.

The same client information may exist in several places

A client’s contact details might appear in the CRM, finance system, practice-management platform, email marketing database and individual employees’ address books. Client documents may be stored in SharePoint, Teams, a specialist document-management system, email attachments, local folders and an external collaboration portal.

This duplication can create productivity and governance problems. Employees may not know which copy is current. Updates made in one system may not reach another. Retention policies may be applied inconsistently. The firm may struggle to identify every location containing information relevant to a client request or security incident.

Duplicated information also expands the firm’s exposure. Protecting a document in one location is not enough if earlier versions or downloaded copies remain available elsewhere.

The objective is not necessarily to keep every piece of information in a single platform. That may be impractical for many firms. The more realistic goal is to define:

  • Which system is authoritative for each type of information.
  • Where employees should create, store and share client documents.
  • How information moves between approved applications.
  • How long records should be retained.
  • How duplicate or temporary copies will be managed.
  • Which platforms should no longer hold particular information.

Clear ownership is essential. Without it, technology decisions can become disconnected from information-governance requirements.

Access becomes harder to manage across multiple platforms

Every additional application creates another place where access may need to be granted, reviewed and removed. Some platforms may connect to the firm’s central identity system. Others may require separate accounts. External collaborators may be invited directly into specific tools, while service accounts and integrations can retain access long after their original purpose has changed.

This makes it difficult to answer a simple question: Who can access this client’s information? The answer may be different across email, SharePoint, Teams, document-management systems, client portals and specialist applications.

When access is managed independently in each platform, employees can lose access to one system but retain it elsewhere. A contractor may be removed from a project workspace while their account remains active in a related application. A shared link may continue working after an engagement finishes.

Centralised identity management, multifactor authentication and consistent onboarding and offboarding processes can reduce this risk. They do not eliminate the need to review application-level permissions and external access. The firm still needs someone who understands the business reason behind each permission.

Supporting the environment requires broad knowledge

When an employee reports that they cannot complete a task, the visible symptom may not reveal the underlying cause. The problem could relate to:

  • The employee’s identity or access permissions.
  • The application itself.
  • A Microsoft 365 service.
  • An integration between two platforms.
  • A browser, device or network issue.
  • A vendor-side service disruption.
  • Incorrect or incomplete data from an earlier stage of the workflow.
  • A licensing or configuration change.

Diagnosing the problem may require coordination between internal IT, software vendors, cloud providers and application consultants. Responsibility is not always clear. One provider may confirm that its own platform is working and direct the issue to another vendor. Meanwhile, the employee remains unable to complete the client work.

A documented technology environment helps the IT team resolve these issues faster. It should show how critical applications connect, who owns each vendor relationship, which processes depend on each system and how support should be escalated. Without that information, troubleshooting depends heavily on individual knowledge and experience.

More platforms can mean less security visibility

Security teams and IT managers need to understand what is happening across the environment. That is easier when systems provide consistent logs, alerts and access information. In practice, different applications offer different levels of visibility.

One platform may provide detailed audit records. Another may retain only basic login information. Security alerts may be sent to different administrators, buried among routine notifications or available only through separate dashboards.

This fragmentation makes it harder to identify suspicious activity across a complete client workflow. For example, the firm may need to connect several events to recognise a potential incident:

  • An employee account signs in from an unusual location.
  • A large number of documents are downloaded.
  • A forwarding rule is created in the employee’s mailbox.
  • Information is transferred into a connected third-party application.
  • An external sharing link is generated.

Viewed independently, each event may attract limited attention. Viewed together, they may indicate a serious problem. Improving visibility does not always require replacing the firm’s applications. It begins with identifying the systems that hold sensitive information, confirming what monitoring they support and ensuring important alerts reach the right people.

AI can expose existing complexity

Artificial intelligence introduces another reason to understand where information is stored and who can access it. AI tools can help employees locate, summarise and work with information more efficiently. That benefit depends on the quality of the firm’s permissions and information governance.

If documents are overshared, duplicated or stored across poorly governed locations, AI may make those existing access problems easier to discover. An employee could surface information they technically have permission to access but do not require for their role.

Employees may also introduce new AI applications into the workflow. Information copied into an unapproved tool creates another location to manage and another vendor relationship to assess. Before connecting AI to business information, firms should understand:

  • Which data sources the tool can access.
  • Whether existing permissions accurately reflect current roles.
  • How prompts and uploaded information are processed.
  • Where generated content will be stored.
  • Whether information may be used to train external models.
  • How the new tool fits within the approved application environment.

AI does not create every information-governance problem. It can reveal and amplify the ones that already exist.

Simplification does not mean removing every specialist application

Application complexity cannot always be solved by reducing the technology environment to one platform. Professional services firms often need specialist systems to deliver their work effectively. Replacing a valuable application purely to reduce the number of vendors could create more disruption than benefit.

The aim should be intentional complexity. Every platform should have a defined purpose, an accountable owner and a clear relationship with the rest of the environment. The firm should understand what information it holds, how it is secured and whether it continues to provide sufficient value. This creates an opportunity to:

  • Remove applications that are no longer required.
  • Consolidate overlapping tools where practical.
  • Improve integrations between important systems.
  • Standardise identity and access controls.
  • Clarify where information should be stored.
  • Document vendor and support responsibilities.
  • Strengthen monitoring around critical workflows.
  • Plan changes around business priorities.

An environment can contain several specialist platforms and still be well governed. Problems arise when complexity becomes unmanaged or invisible.

Questions for IT teams

A useful review can begin with the systems involved in one common client engagement. Map each stage of the process and ask:

  • Which applications support this stage?
  • What client information enters or leaves each system?
  • Which platform holds the authoritative record?
  • How does information move between applications?
  • Who owns each system and vendor relationship?
  • How is employee and external access managed?
  • Which integrations depend on shared or service accounts?
  • What monitoring and audit information is available?
  • How would the business continue if this platform became unavailable?
  • Does the application still serve a necessary purpose?

This exercise can reveal duplication, undocumented dependencies and security gaps that may not be visible when each platform is reviewed separately. It also provides a clearer foundation for future technology planning.

Make the complexity visible

A seamless client experience depends on a complex network of applications, integrations, identities, devices and vendors. That complexity is not inherently a problem. It becomes a risk when the firm cannot see it clearly, assign ownership or understand how one change will affect the rest of the environment.

Internal IT teams need more than a list of applications. They need a practical view of how technology supports the firm’s actual client workflows. Once those relationships are visible, the firm can make better decisions about security, integration, support and future investment.

The important question is not simply how many systems the firm uses. It is whether those systems operate as a deliberately managed environment—or as a collection of individual decisions that have accumulated over time.

Ben Luks
Post by Ben Luks
23 September 2026, 14:01:50 GMT+09:30

Comments