Why Client Collaboration Is Now a Confidentiality Question
The Extranet Trap: Why Client Collaboration Is Now a Confidentiality Question
How law firms can make client collaboration more secure without creating another layer of risk.
A client emails the firm: “Can you give our team access to the documents for this matter?” It sounds straightforward. The firm creates a shared folder, adds the client as a guest, and sends the link. The client gets the documents, and the work continues.
But there is a bigger question behind that simple exchange: who has access to the information, and for how long?
That question becomes harder to answer when firms manage collaboration across shared folders, email attachments, guest accounts, client portals, and multiple document systems. The issue is no longer simply how securely a document is shared. It is whether access remains aligned with the matter, the people involved, and the firm's confidentiality obligations throughout the life of that matter.
The Problem With Access That Follows the User
Consider a firm handling two matters for the same client.
One is a confidential acquisition. The other is an unrelated employment dispute. Different lawyers are involved, and the information needs to remain separate.
Now imagine that access to these matters is managed through a combination of shared folders, guest accounts, email, and collaboration tools. The firm may have strong security controls on each system individually. Yet the overall picture can still become difficult to manage.
A lawyer may have access to one matter but not another. A client contact may need documents for a specific transaction but not the firm's wider workspace. A guest account created for a matter may remain active long after the work is complete.
Confidentiality Is About More Than a Secure Portal
ABA Model Rule 1.6(c) requires lawyers to make reasonable efforts to prevent unauthorized disclosure of information relating to a client. What is reasonable depends on factors including the sensitivity of the information, the likelihood of disclosure, and the safeguards available.
In a digital environment, that means firms need visibility into more than whether a platform is “secure.”
They need to know:
- Who has access to a matter? The firm needs a clear view of every person whose permissions reach the matter.
- What information can each person access? Permission should match the matter and the information that person actually needs.
- When should that access end? Access should not remain simply because an account or guest invitation still exists.
- Can the firm see what happened? Activity needs to be visible enough to investigate an incident and understand how information was handled.
This becomes particularly important when the same client has multiple matters, multiple teams, and multiple external contacts. The challenge is not necessarily a lack of security technology. It is that permissions can become fragmented across systems.
And that problem becomes even more important as AI enters the workflow.
Why AI Makes the Access Problem More Important
AI is not the original security problem. It exposes how well the firm's existing access model actually works.
Suppose a lawyer uses an AI assistant to find information from a matter. For the assistant to provide useful answers, it needs access to the firm's content. If that content is governed by poorly structured permissions, the risk changes.
The important question is no longer only whether the AI tool itself is secure. It is whether the AI is respecting the same boundaries that apply to the lawyer.
If a lawyer can access Matter A but not Matter B, the AI should not be able to retrieve information from Matter B simply because that information exists somewhere within the firm's environment.
This is why client collaboration and AI governance are becoming closely connected. The same permissions that protect confidential information between people should also govern what AI can retrieve and use.
A January 2026 incident involving an AI assistant and sensitivity labels highlighted this broader challenge: even sophisticated AI systems depend on the underlying information-access controls being configured correctly.
AI does not replace the firm's security model. It inherits it.
The Better Approach: Make the Matter the Security Boundary
When firms identify these risks, the obvious response can be to add another system: a dedicated client extranet.
But another portal can also mean another set of users, permissions, accounts, and audit logs to manage.
Instead, firms should consider making the matter itself the security boundary.
The person, the client, and the AI all operate within the same matter-level boundaries.
What Good Matter-Level Access Looks Like
A strong collaboration model should answer three basic questions.
These controls become especially valuable as collaboration moves beyond traditional document sharing and into AI-assisted work.
The Question Clients Are Really Asking
Clients may ask whether a firm has a secure extranet. But the deeper question is usually much simpler:
Can you keep my information separate from everyone else's?
A strong answer is not another login screen or another security badge.
It is the ability to demonstrate that:
- the right people have access to the matter,
- they can see only what they need,
- access can be removed when circumstances change, and
- the same boundaries apply when AI is involved.
That is the shift firms need to make in client collaboration.
The goal is not to keep adding portals and security layers. It is to build collaboration around the firm's existing confidentiality model.
Because in legal work, secure collaboration is ultimately not about where the document sits. It is about who is allowed to see it.