Professional services firms depend on access to information. Employees need client documents, correspondence, financial records, project files and specialist systems to deliver their work. Clients and external advisers may also need access to shared information during an engagement.
Access is therefore granted for good reasons. The problem is that the original reason can disappear while the access remains. Employees change roles. Project teams are reorganised. Contractors finish their assignments. Client engagements end. External advisers move on to other work.
Unless someone reviews the access created during these periods, people may continue to reach client information they no longer need. This is often treated as a technical permissions problem. However, the more important question is one of business ownership:
Who is responsible for deciding whether access to client information is still appropriate?
Client information rarely sits in one carefully controlled location. It may be distributed across:
Each platform may have its own permissions, users and sharing options. Information can also be copied, downloaded or moved between systems as employees complete their work. For business leaders, this can make it difficult to answer a seemingly simple question: Who can currently access a particular client’s information?
The answer may extend beyond the people actively working with that client. It could include employees from previous project teams, former contractors, external guests or anyone included in a broadly shared workspace. The firm may not have intended to provide long-term access to these people. Their access may simply never have been reconsidered.
Most unnecessary access does not begin with a careless decision. An employee is added to a project because their expertise is required. A senior manager receives access so they can review a client deliverable. A consultant joins a Team for the duration of an engagement. An external adviser receives a shared link to collaborate on a document.
At that moment, the access may be completely appropriate. The risk emerges later, when circumstances change but the permissions do not. Common examples include:
No single example necessarily indicates a serious governance failure. Across years of projects, role changes and client relationships, however, these decisions can accumulate. The result is an information environment that reflects the firm’s history rather than its current responsibilities.
IT teams can administer platforms, manage accounts and apply security controls. They cannot always determine whether a person still has a legitimate business reason to access a client file.
That decision requires context. IT may know that an employee belongs to a particular Microsoft 365 group. It may not know whether that employee still works with the client represented by the group.
It may be able to identify an external guest account. It may not know whether the adviser behind that account is still engaged by the firm. It may know that a SharePoint site remains active. It may not know whether the site contains a current client matter, an archived project or information that should have been moved elsewhere.
Business leaders, practice managers and project owners understand those relationships. They know who is working with each client, when an engagement has ended and which information is particularly sensitive. This means access governance needs shared responsibility.
IT should provide the systems, visibility and technical controls needed to manage access. Business owners should decide who genuinely requires access and confirm when that need has changed.
Without that division of responsibility, IT can be left making business decisions without enough information, while business teams assume IT is already handling them.
Professional services firms often need to collaborate with people outside the organisation. Clients may need access to a shared workspace. Consultants and specialist advisers may contribute to a project. Suppliers may need documents to complete a task. Other professional firms may work alongside your people on the same engagement.
Microsoft 365 and other cloud platforms make this collaboration relatively simple. A user can be invited as a guest, added to a workspace or given access through a shared link. Removing access later requires another decision. If the firm does not have a consistent review process, external users may retain access after:
External sharing should not automatically be viewed as unsafe. It is essential to modern professional work. The issue is whether the firm knows what has been shared, with whom, for how long and under whose authority.
AI is making existing information easier to find and use. Tools integrated with workplace platforms can help employees retrieve documents, summarise discussions, locate answers and connect information across different sources.
These capabilities can improve productivity, particularly in firms where employees work with large amounts of written and structured information. They also increase the importance of accurate permissions.
An employee may technically have access to an old client workspace without remembering that it exists. In the past, they might have needed to navigate to the site, search through folders and recognise the relevant documents.
AI can reduce that friction. It can surface information based on the access already available to the user. If the permissions are current, this is valuable. If access has accumulated over time, AI may make outdated or excessive access easier to exercise.
This does not mean the AI tool has bypassed the firm’s security. It may be working exactly as intended. The underlying problem is that the user can still reach information they no longer require.
Before expanding AI across the organisation, leadership should have confidence that access to sensitive information reflects current roles and responsibilities.
Client confidentiality may be a shared organisational responsibility, but individual information repositories still need clear owners. An owner should understand:
The owner does not need to configure permissions personally. Their role is to make and confirm the business decisions behind those permissions. Depending on the firm, ownership might sit with:
What matters is that someone can answer for the access granted to that information. Workspaces without active owners deserve particular attention. If nobody is responsible for reviewing access, temporary decisions can quietly become permanent.
Most organisations understand the need to remove access when an employee leaves. Internal role changes can be harder to manage. An employee who moves between departments still needs a Microsoft 365 account and access to the organisation’s systems. Their old access may therefore remain in place unless someone deliberately reviews it.
Over time, experienced employees can accumulate access from several previous roles, projects and client teams. This is sometimes described as permission creep. Each additional permission may have been justified when it was granted, but the total level of access no longer matches the employee’s current responsibilities. A role-change process should therefore consider:
The same principle applies when contractors change assignments or when responsibilities move between teams. Access should follow the work. It should not automatically follow the individual forever.
Many firms assume that access is appropriate because nobody has reported a problem. That is difficult to rely on when information is spread across many systems and workspaces.
Leadership does not need to inspect every permission personally. It should be able to obtain reasonable assurance that the organisation has a repeatable process for managing access. Useful evidence might include:
The purpose is not to create paperwork for every routine access decision. It is to give the firm visibility over the areas where inappropriate access could affect clients, regulatory obligations or the firm’s reputation.
A professional services firm may have thousands of files and many years of collaboration history. Reviewing every permission immediately may not be realistic. A risk-based approach provides a more practical starting point. Leadership and IT can first identify information that would cause the greatest concern if accessed by the wrong person. That might include:
The next step is to identify who owns those locations and when their access was last reviewed. This often reveals the most important gaps: broadly accessible workspaces, inactive owners, old guest accounts and links created without an expiry date. The organisation can then extend the review process to other information as its governance matures.
Professional services firms earn trust through the way their people handle client matters. Technology now plays a significant role in maintaining that trust. It determines where information is stored, how it is shared and who can reach it.
The question is not whether access was justified when it was originally granted. The question is whether it remains justified today. That requires cooperation between business leaders and IT teams.
IT can provide visibility and manage the technical controls. Business owners can confirm who needs access, how long they need it and when the decision should be reviewed.
Together, they can ensure that permissions reflect current client relationships rather than the accumulated history of old projects and organisational changes. Because protecting client information begins with knowing who can still access it.
These questions can help identify whether access governance requires further attention:
If the answers are unclear, the first step is to establish ownership. Once someone is responsible for each important information location, the firm can begin reviewing whether access still reflects the work, relationships and responsibilities that exist today.