Subnet Blog

Who Still Has Access to Your Clients’ Information?

Written by Ben Luks | 14 September 2026, 05:14:16 Z

Professional services firms depend on access to information. Employees need client documents, correspondence, financial records, project files and specialist systems to deliver their work. Clients and external advisers may also need access to shared information during an engagement.

Access is therefore granted for good reasons. The problem is that the original reason can disappear while the access remains. Employees change roles. Project teams are reorganised. Contractors finish their assignments. Client engagements end. External advisers move on to other work.

Unless someone reviews the access created during these periods, people may continue to reach client information they no longer need. This is often treated as a technical permissions problem. However, the more important question is one of business ownership:

Who is responsible for deciding whether access to client information is still appropriate?

Client information moves through more systems than most leaders see

Client information rarely sits in one carefully controlled location. It may be distributed across:

  • Email accounts
  • Microsoft Teams workspaces
  • SharePoint sites
  • OneDrive folders
  • Document-management platforms
  • Finance and practice-management systems
  • Customer relationship management platforms
  • Project applications
  • Files shared with clients and external advisers

Each platform may have its own permissions, users and sharing options. Information can also be copied, downloaded or moved between systems as employees complete their work. For business leaders, this can make it difficult to answer a seemingly simple question: Who can currently access a particular client’s information?

The answer may extend beyond the people actively working with that client. It could include employees from previous project teams, former contractors, external guests or anyone included in a broadly shared workspace. The firm may not have intended to provide long-term access to these people. Their access may simply never have been reconsidered.

Access granted for a good reason can become outdated

Most unnecessary access does not begin with a careless decision. An employee is added to a project because their expertise is required. A senior manager receives access so they can review a client deliverable. A consultant joins a Team for the duration of an engagement. An external adviser receives a shared link to collaborate on a document.

At that moment, the access may be completely appropriate. The risk emerges later, when circumstances change but the permissions do not. Common examples include:

  • An employee moves to another team but retains access to previous client matters.
  • A temporary project group remains active after the work finishes.
  • A contractor’s involvement ends without their access being removed.
  • A client contact changes roles but remains a guest in a shared workspace.
  • A document link remains active long after its original purpose has passed.
  • A former workspace owner leaves the organisation without responsibility being reassigned.

No single example necessarily indicates a serious governance failure. Across years of projects, role changes and client relationships, however, these decisions can accumulate. The result is an information environment that reflects the firm’s history rather than its current responsibilities.

IT cannot make every access decision alone

IT teams can administer platforms, manage accounts and apply security controls. They cannot always determine whether a person still has a legitimate business reason to access a client file.

That decision requires context. IT may know that an employee belongs to a particular Microsoft 365 group. It may not know whether that employee still works with the client represented by the group.

It may be able to identify an external guest account. It may not know whether the adviser behind that account is still engaged by the firm. It may know that a SharePoint site remains active. It may not know whether the site contains a current client matter, an archived project or information that should have been moved elsewhere.

Business leaders, practice managers and project owners understand those relationships. They know who is working with each client, when an engagement has ended and which information is particularly sensitive. This means access governance needs shared responsibility.

IT should provide the systems, visibility and technical controls needed to manage access. Business owners should decide who genuinely requires access and confirm when that need has changed.

Without that division of responsibility, IT can be left making business decisions without enough information, while business teams assume IT is already handling them.

External sharing can outlast the engagement

Professional services firms often need to collaborate with people outside the organisation. Clients may need access to a shared workspace. Consultants and specialist advisers may contribute to a project. Suppliers may need documents to complete a task. Other professional firms may work alongside your people on the same engagement.

Microsoft 365 and other cloud platforms make this collaboration relatively simple. A user can be invited as a guest, added to a workspace or given access through a shared link. Removing access later requires another decision. If the firm does not have a consistent review process, external users may retain access after:

  • A project is completed
  • A contract expires
  • A client contact leaves their organisation
  • An adviser is replaced
  • A shared document is no longer required
  • The employee who created the link changes roles or leaves the firm

External sharing should not automatically be viewed as unsafe. It is essential to modern professional work. The issue is whether the firm knows what has been shared, with whom, for how long and under whose authority.

AI increases the importance of accurate access

AI is making existing information easier to find and use. Tools integrated with workplace platforms can help employees retrieve documents, summarise discussions, locate answers and connect information across different sources.

These capabilities can improve productivity, particularly in firms where employees work with large amounts of written and structured information. They also increase the importance of accurate permissions.

An employee may technically have access to an old client workspace without remembering that it exists. In the past, they might have needed to navigate to the site, search through folders and recognise the relevant documents.

AI can reduce that friction. It can surface information based on the access already available to the user. If the permissions are current, this is valuable. If access has accumulated over time, AI may make outdated or excessive access easier to exercise.

This does not mean the AI tool has bypassed the firm’s security. It may be working exactly as intended. The underlying problem is that the user can still reach information they no longer require.

Before expanding AI across the organisation, leadership should have confidence that access to sensitive information reflects current roles and responsibilities.

Client confidentiality needs named owners

Client confidentiality may be a shared organisational responsibility, but individual information repositories still need clear owners. An owner should understand:

  • Why the workspace exists
  • What information it contains
  • Which employees need access
  • Whether external users are involved
  • When access should be reviewed
  • What should happen when the work ends

The owner does not need to configure permissions personally. Their role is to make and confirm the business decisions behind those permissions. Depending on the firm, ownership might sit with:

  • A practice leader
  • A client relationship manager
  • A project director
  • A department head
  • An engagement partner
  • Another senior employee responsible for the work

What matters is that someone can answer for the access granted to that information. Workspaces without active owners deserve particular attention. If nobody is responsible for reviewing access, temporary decisions can quietly become permanent.

Role changes need the same attention as departures

Most organisations understand the need to remove access when an employee leaves. Internal role changes can be harder to manage. An employee who moves between departments still needs a Microsoft 365 account and access to the organisation’s systems. Their old access may therefore remain in place unless someone deliberately reviews it.

Over time, experienced employees can accumulate access from several previous roles, projects and client teams. This is sometimes described as permission creep. Each additional permission may have been justified when it was granted, but the total level of access no longer matches the employee’s current responsibilities. A role-change process should therefore consider:

  • Which existing access the employee should retain
  • Which client workspaces they should leave
  • Whether their privileged access remains necessary
  • Who will take ownership of their previous information
  • Whether external relationships associated with their former role need to change

The same principle applies when contractors change assignments or when responsibilities move between teams. Access should follow the work. It should not automatically follow the individual forever.

Leadership needs evidence rather than assumptions

Many firms assume that access is appropriate because nobody has reported a problem. That is difficult to rely on when information is spread across many systems and workspaces.

Leadership does not need to inspect every permission personally. It should be able to obtain reasonable assurance that the organisation has a repeatable process for managing access. Useful evidence might include:

  • A list of high-risk information locations and their owners
  • Regular reviews of sensitive Teams and SharePoint sites
  • Reports showing external guest access
  • Expiry controls for temporary sharing
  • Access reviews following role changes
  • Consistent offboarding records
  • Monitoring of privileged accounts
  • Escalation processes for workspaces without owners
  • Defined review dates for sensitive client information

The purpose is not to create paperwork for every routine access decision. It is to give the firm visibility over the areas where inappropriate access could affect clients, regulatory obligations or the firm’s reputation.

Begin with the most sensitive information

A professional services firm may have thousands of files and many years of collaboration history. Reviewing every permission immediately may not be realistic. A risk-based approach provides a more practical starting point. Leadership and IT can first identify information that would cause the greatest concern if accessed by the wrong person. That might include:

  • Highly confidential client matters
  • Financial and payment information
  • Commercial transactions
  • Intellectual property
  • Personal or employee information
  • Executive correspondence
  • Legal or contractual documents
  • Information shared with multiple external parties

The next step is to identify who owns those locations and when their access was last reviewed. This often reveals the most important gaps: broadly accessible workspaces, inactive owners, old guest accounts and links created without an expiry date. The organisation can then extend the review process to other information as its governance matures.

Access should reflect the relationship today

Professional services firms earn trust through the way their people handle client matters. Technology now plays a significant role in maintaining that trust. It determines where information is stored, how it is shared and who can reach it.

The question is not whether access was justified when it was originally granted. The question is whether it remains justified today. That requires cooperation between business leaders and IT teams.

IT can provide visibility and manage the technical controls. Business owners can confirm who needs access, how long they need it and when the decision should be reviewed.

Together, they can ensure that permissions reflect current client relationships rather than the accumulated history of old projects and organisational changes. Because protecting client information begins with knowing who can still access it.

Questions for your leadership team

These questions can help identify whether access governance requires further attention:

  • Can we identify where our most sensitive client information is stored?
  • Does each important workspace have an active business owner?
  • Who decides whether employees still require access?
  • Are permissions reviewed when employees change roles?
  • Can we identify all external users with access to client information?
  • Do temporary links and guest accounts expire?
  • What happens to access when a project or client engagement ends?
  • Are inactive workspaces archived or reviewed?
  • Have we considered permissions as part of our AI adoption plans?
  • Can leadership obtain evidence that high-risk access is reviewed regularly?

If the answers are unclear, the first step is to establish ownership. Once someone is responsible for each important information location, the firm can begin reviewing whether access still reflects the work, relationships and responsibilities that exist today.