How to set up secure AI workflows for client data

A build order for firms that hold confidential client data: the right plan, admin settings, file permissions, workflow scope, review, and records.

King & Company

In short

Work in this order: put everyone on one business workspace under the firm's own contract, turn on the identity and admin controls that plan includes, clean up file permissions before connecting anything, then scope each workflow by what goes in, what the AI can reach, and what it may write or send. Add a named reviewer before anything leaves the firm, keep logs and a short written policy, and have outside builders work inside your workspace so they never need their own copy of client data.

To set up secure AI workflows for confidential client data, work in a fixed order: the account and contract, identity and admin settings, file permissions, the scope of each workflow, a named reviewer, logging, and a written record. Most of that list is ordinary IT work that your IT lead or managed service provider already knows how to do, and the vendor contract is the easy part.

The harder parts sit in three places that vendor comparison pages tend to skip: which account the work really runs on, how clean your existing file permissions are, and how each individual workflow is designed. The sections below take them in build order, so you can hand this page to the person who administers your systems.

Start with the account, because the terms differ by plan

A firm can buy a business workspace and still have some of the team doing client work on personal accounts. The terms that apply are the terms of the account the document was pasted into, so the first job is making sure there is one firm workspace and that client work happens there.

Vendors publish these differences. Anthropic states that by default it will not use inputs or outputs from its commercial products, such as Claude for Work and the Anthropic API, to train its models, with an exception when a user submits feedback or otherwise chooses to allow it. For its consumer plans (Free, Pro, and Max), Anthropic says chats may be used to improve its models when the user chooses to allow it, a choice managed in the account's privacy settings, and the same page says conversations flagged for safety review may also be used. On a personal account that choice belongs to the individual, and the firm has no administrator who can see or set it.

Microsoft says prompts, responses, and data accessed through Microsoft Graph are not used to train foundation large language models in Microsoft Copilot for organizations. Google says Workspace content is not human reviewed or used for generative AI model training outside your domain without permission. Read the page for the plan you are buying, on the day you buy it, because these terms change. We go through these terms in more detail in what happens to data you send to an AI model.

Which tier to buy

Choose the tier by the controls you will be asked about. As an example, Anthropic's Team plan lists single sign-on, domain capture, role-based permissioning, and admin tools, and covers 2 to 150 seats. Its Enterprise plan adds audit logs, SCIM, custom data retention controls, a Compliance API, customer-managed encryption keys, and a US-only inference option, with a 20 seat minimum when bought self-serve. If a client questionnaire or your compliance owner will ask for activity logs or a defined retention period, check that the tier you are pricing includes them.

Turn on the admin controls you are already paying for

Buying the plan does not switch its controls on. Ask your IT lead to do four things in the first week:

  1. Connect the workspace to your identity provider with single sign-on, so that disabling a departing person's firm login also closes their route into the AI workspace.
  2. Turn on domain capture where the plan offers it, so accounts created with a work email address land in the firm workspace.
  3. Require multi-factor authentication through that identity provider.
  4. Set retention for AI conversations to match your document retention policy. In Microsoft 365, for example, admins can use Microsoft Purview to set retention policies for data from chat interactions with Copilot.

Then decide which connectors and agents are allowed at all. Microsoft notes that admins select which agents are allowed in their organization. Look for the equivalent connector setting in whichever workspace you use, and start with the short list your first workflows need.

Fix file permissions before you connect anything

Workspace assistants work with whatever the signed-in user can already open. Microsoft says Copilot only surfaces organizational data to which individual users have at least view permissions and that it is important to use the permission models in services such as SharePoint so the right people have the right access. Google says Gemini only retrieves relevant content in Workspace that the user has access to.

That design is sensible, and it means the assistant inherits every sharing mistake the firm has made. A payroll folder shared with the whole company, or a client folder still open to a former contractor, was hard to stumble on before. With an assistant it can come back in answer to a plain question.

So permission cleanup is step one of the AI project. Review who can open HR, partner compensation, and client engagement folders. Remove "anyone with the link" sharing on client material. Close out guest accounts that are no longer needed. None of this is new work for an IT provider, and it is worth doing whether or not you switch AI on.

Scope each workflow: what goes in, what the AI can reach, what it can do

Security is decided one workflow at a time. For each one, write down three things.

QuestionExample: lease abstraction at a brokerage team
Which documents go inThe executed lease and its amendments for one deal
What the AI can reachOne deal folder, through one connector, with no access to email
What it may write or sendA draft abstract saved to that folder, with nothing sent outside the firm

The table is an illustration of the method, and your own answers will differ. The point is that a workflow for drafting a proposal from a precedent library needs read access to that library and nothing else, while a workflow that files data into a CRM needs write access to specific fields. Give each one the narrowest reach that lets it do the job. Once a workflow can take actions on its own, such as sending email or updating records, the questions get more detailed, and we cover them in AI agent permissions and governance.

Put a person at the step that matters

No setting removes the need for a person to check the work. Microsoft's own documentation says responses from generative AI are not guaranteed to be 100% factual and that users should use their judgment when reviewing output before sending it to others.

The review step serves accuracy and security at once. The reviewer confirms the figures against the source document, and the same pause is where someone notices that a draft contains another client's information or is addressed to the wrong recipient. Name the reviewer by role for each workflow, and place the review before anything is sent to a client, filed, or entered in a system of record.

Keep a record: logs, an inventory of AI tools, and a written policy

Three records are enough to start:

  • Logs. Turn on the audit logging your plan includes, and know who can read it.
  • An inventory. List each AI tool in use, the plan it is on, who administers it, and which workflows run on it.
  • A written policy. One or two pages covering approved tools, what client information may go where, who reviews, and what to do when something goes wrong. Our guide to writing an AI acceptable use policy covers what to include.

What your regulator and your clients will ask to see

For firms that prepare tax returns, the FTC lists tax preparation firms among the financial institutions covered by the Safeguards Rule. The same guidance names nine elements of a required information security program, including a designated Qualified Individual, a risk assessment, staff training, monitoring of service providers, and a written incident response plan. It also tells covered firms to implement multi-factor authentication for anyone accessing customer information, to maintain a log of authorized users' activity, and to write security expectations into service provider contracts. The FTC notes that firms maintaining customer information on fewer than five thousand consumers are exempt from certain provisions. If an AI vendor will receive or process customer information for you, ask your Qualified Individual or counsel how the rule's service provider requirements apply to it. Our article on the Safeguards Rule and AI at a tax or accounting firm goes through what the FTC guidance says.

Firms outside that rule can borrow structure from voluntary guidance. NIST's AI Risk Management Framework, released January 26, 2023, is organized around four functions (Govern, Map, Measure, Manage), and NIST published a Generative AI Profile for it on July 26, 2024. CISA, the NSA, the FBI, and international partners published joint guidance on AI data security on May 22, 2025.

Clients tend to ask simpler questions: which tools, on what terms, who can see our files, and who checks the output. The records above answer all four. What your firm is required to do, and what it must tell clients, depends on your profession, your state, and your engagement terms, so confirm with your own counsel or compliance lead. No tool or plan makes a firm compliant by itself.

Where an outside builder should and should not touch your data

The arrangement that keeps the most control with the firm is one where the work runs inside the firm's own workspace, under the firm's own contract, so an outside builder never needs their own copy of client data. The builder gets a named account in your identity system, with access to the folders the workflow needs, and that access ends when the engagement does. This is how we work at King & Company: inside the client's AI workspace, under NDA, with every workflow and skill owned by the client.

Be cautious with any arrangement that asks you to export client files to a builder's system, or that runs your workflow on an account your firm does not administer. If you want to talk through the setup for your firm, you can get in touch.

A one-page checklist

  1. One business workspace under a contract the firm signed, on a tier that includes the logs and retention controls you will be asked about.
  2. Single sign-on, multi-factor authentication, and domain capture turned on.
  3. Retention set to match your document retention policy.
  4. Connectors and agents limited to an approved list.
  5. Sharing reviewed on HR, compensation, and client folders, with stale guest access removed.
  6. For each workflow, a written note of what goes in, what the AI can reach, and what it may write or send.
  7. A named reviewer by role, placed before anything leaves the firm.
  8. Audit logging on, an inventory of AI tools, and a short written policy.
  9. Outside builders working inside your workspace on named accounts that are removed at the end of the work.
  10. A date on the calendar to re-read the vendor's terms and repeat the permission review.

Common questions

Is it safe to put client documents into Claude, ChatGPT, or Copilot?

It depends on the plan the account is on, the settings your administrator has chosen, and what your client agreements and regulators allow. Business plans from the major vendors publish different training and retention terms than personal plans, so read the terms for the exact plan you are buying and confirm with your counsel or compliance lead before client documents go in.

Do we need an Enterprise plan or is a Team plan enough?

Decide by the controls you need. Anthropic's Team plan lists single sign-on, domain capture, and role-based permissioning, and its Enterprise plan adds audit logs, SCIM, custom data retention controls, and a Compliance API. If a client or regulator will ask for activity logs or a set retention period, that usually points to the higher tier.

Does a SOC 2 report from the AI vendor mean we are compliant?

No. A vendor's report describes the vendor's controls. Your firm still decides who has an account, which files the AI can reach, who reviews output, and what is written down, and those are the things a client or regulator will ask your firm about.

Can AI see files that staff are not supposed to see?

A workspace assistant works with the permissions the user already has. Microsoft says Copilot only surfaces organizational data the individual user has at least view permission to, and Google says Gemini only retrieves Workspace content the user has access to. If a folder is shared more widely than it should be, the assistant makes that easier to find, so fix the sharing first.

What should we do about staff using personal AI accounts?

Give them a firm account that is at least as good, turn on domain capture or single sign-on where the plan offers it so work email addresses land in the firm workspace, and write one plain rule that client information goes only into approved tools. Then ask people which tasks they were using personal accounts for, because those are the workflows worth building properly.

Tell us where the time is going

King & Company embeds with your team and builds the AI workflows, skills, and integrations around the work you already do. Describe the work your team would rather not be doing, and we will come back with how we would approach it.