The Extranet Trap: Why Client Collaboration Is Now a Confidentiality Question

Why Client Collaboration Is Now a Confidentiality Question

The Extranet Trap: Why Client Collaboration Is Now a Confidentiality Question
Legal101

The Extranet Trap: Why Client Collaboration Is Now a Confidentiality Question

How law firms can make client collaboration more secure without creating another layer of risk.

A client emails the firm: “Can you give our team access to the documents for this matter?” It sounds straightforward. The firm creates a shared folder, adds the client as a guest, and sends the link. The client gets the documents, and the work continues.

But there is a bigger question behind that simple exchange: who has access to the information, and for how long?

That question becomes harder to answer when firms manage collaboration across shared folders, email attachments, guest accounts, client portals, and multiple document systems. The issue is no longer simply how securely a document is shared. It is whether access remains aligned with the matter, the people involved, and the firm's confidentiality obligations throughout the life of that matter.

The Problem With Access That Follows the User

Consider a firm handling two matters for the same client.

One is a confidential acquisition. The other is an unrelated employment dispute. Different lawyers are involved, and the information needs to remain separate.

Now imagine that access to these matters is managed through a combination of shared folders, guest accounts, email, and collaboration tools. The firm may have strong security controls on each system individually. Yet the overall picture can still become difficult to manage.

A lawyer may have access to one matter but not another. A client contact may need documents for a specific transaction but not the firm's wider workspace. A guest account created for a matter may remain active long after the work is complete.

Confidentiality Is About More Than a Secure Portal

ABA Model Rule 1.6(c) requires lawyers to make reasonable efforts to prevent unauthorized disclosure of information relating to a client. What is reasonable depends on factors including the sensitivity of the information, the likelihood of disclosure, and the safeguards available.

In a digital environment, that means firms need visibility into more than whether a platform is “secure.”

They need to know:

  • Who has access to a matter? The firm needs a clear view of every person whose permissions reach the matter.
  • What information can each person access? Permission should match the matter and the information that person actually needs.
  • When should that access end? Access should not remain simply because an account or guest invitation still exists.
  • Can the firm see what happened? Activity needs to be visible enough to investigate an incident and understand how information was handled.

This becomes particularly important when the same client has multiple matters, multiple teams, and multiple external contacts. The challenge is not necessarily a lack of security technology. It is that permissions can become fragmented across systems.

And that problem becomes even more important as AI enters the workflow.

Why AI Makes the Access Problem More Important

AI is not the original security problem. It exposes how well the firm's existing access model actually works.

Suppose a lawyer uses an AI assistant to find information from a matter. For the assistant to provide useful answers, it needs access to the firm's content. If that content is governed by poorly structured permissions, the risk changes.

The important question is no longer only whether the AI tool itself is secure. It is whether the AI is respecting the same boundaries that apply to the lawyer.

If a lawyer can access Matter A but not Matter B, the AI should not be able to retrieve information from Matter B simply because that information exists somewhere within the firm's environment.

This is why client collaboration and AI governance are becoming closely connected. The same permissions that protect confidential information between people should also govern what AI can retrieve and use.

A January 2026 incident involving an AI assistant and sensitivity labels highlighted this broader challenge: even sophisticated AI systems depend on the underlying information-access controls being configured correctly.

AI does not replace the firm's security model. It inherits it.

The Better Approach: Make the Matter the Security Boundary

When firms identify these risks, the obvious response can be to add another system: a dedicated client extranet.

But another portal can also mean another set of users, permissions, accounts, and audit logs to manage.

Instead, firms should consider making the matter itself the security boundary.

What Good Matter-Level Access Looks Like

A strong collaboration model should answer three basic questions.

Who can access the matter?

Permissions should reflect the person's role, client relationship, and any applicable ethical walls.

What can they access?

Access to one matter should not automatically provide access to the client's wider workspace or unrelated matters.

What happened?

The firm should maintain an audit trail of access and activity, making it possible to investigate an incident and demonstrate how information was protected.

These controls become especially valuable as collaboration moves beyond traditional document sharing and into AI-assisted work.

The Question Clients Are Really Asking

Clients may ask whether a firm has a secure extranet. But the deeper question is usually much simpler:

Can you keep my information separate from everyone else's?

A strong answer is not another login screen or another security badge.

It is the ability to demonstrate that:

  • the right people have access to the matter,
  • they can see only what they need,
  • access can be removed when circumstances change, and
  • the same boundaries apply when AI is involved.

That is the shift firms need to make in client collaboration.

The goal is not to keep adding portals and security layers. It is to build collaboration around the firm's existing confidentiality model.

Because in legal work, secure collaboration is ultimately not about where the document sits. It is about who is allowed to see it.