What the Agent Is Allowed to Touch, and What It Must Never Do
A plain-language account of access, approval, and the owner playbook, written for the CPA or lawyer who will not hand a model the client file.
By Paul Buckley
The question that stops the conversation is not whether the agent can answer a form. It is what it is allowed to open.
A partner hears “AI” and pictures the client file, the tax software, the matter, the vault. That picture is usually wrong, and it is the right picture to insist on anyway. A firm that cannot say, in writing, what the agent can read, what it can send, and what it must never touch should not turn it on. The firms that get a first agent working are the ones that settle those three lists before anyone connects a tool.
This is not a technical preference. It is the same duty the firm already has. A lawyer does not get to be casual with information relating to a representation because the tool is new. A CPA does not get to disclose confidential client information because a vendor’s demo made the connection look easy. The agent does not change the duty. It makes the duty visible, because someone has to write down the access before it runs.
The three lists
Every first agent we build ships with an owner playbook. The playbook is short on purpose. It has three lists, and the owner approves them before the agent runs on its own.
What it can read. Only the records the one job needs. An after-hours intake agent needs the new form and the calendar. An invoice agent needs the aging list and the reminder language the firm already uses. A content agent needs the brief in the review queue. None of them needs the client file because the job is not the client file.
What it can send. The sentences the firm has already approved, to the people the firm has already decided may receive them. A qualifying question. A consult link. A reminder that an invoice is past due, in the firm’s voice. Anything outside that script waits. The log shows what went out, when, and why.
What it must never touch. The return. The matter. The document vault. The tax software. The client portal. A fee the firm has not approved. Advice. A second client’s file, reached because two inboxes were connected “just in case.” If a job seems to require any of those, it is not the first job.
Least privilege is the old name for this. The bookkeeper who chases invoices does not get a login to the tax software. The person who answers the new-inquiry form does not get the closed files. An agent should not be granted a broader key than the person whose job it is taking.
What this looks like in a real firm
A two-partner CPA firm wants the unpaid-invoice follow-up off the owner’s Sunday list. The agent can read which invoices are past the firm’s own threshold in QuickBooks, and it can send the reminder the firm already approved. It logs the reply. If the client disputes the amount, mentions a hardship, or writes anything that is not a payment promise, it stops and leaves a note. It cannot open the return, the workpapers, or the document request. It cannot write a new fee. The cash note to the owner in the morning is a count and a short exception list, not a narrative about the client.
A family law practice wants a reply waiting when someone fills out the form at 8 p.m. The agent can read that form. It can ask the two questions the firm already asks: what kind of matter, and is there a hearing date. It can offer the consult link if the answers clear the bar the firm wrote down. It cannot open a matter, read a prior file, or tell the sender what their rights are. A conflict, a matter type the firm does not take, or a message that sounds like an emergency goes to a person, not to a template. The thank-you page can still say to call if it is immediate. The agent does not pretend to be that call.
A limited-client advisory firm routes prospects to email on purpose. The principal does not want a public booker filling the calendar. The agent can read the new email, ask the three questions the principal already uses, and offer a time only if the answers fit the firm’s client limit. It cannot see the client portal, the portfolio, or last quarter’s letter. Silence was protecting the practice from the wrong calls. A scoped reply protects it better, because the wrong call is declined before it is booked, and the right one is not left until Thursday.
A small studio wants the brief turned into a draft and two social versions before the owner sits down. The agent can read the brief in the review queue. It can draft. It cannot publish, post, or send the draft to the client. Approval stays with the person whose name is on the work. The failure mode here is not a leaked file. It is a sentence that went out in the firm’s voice before anyone read it.
The pattern in each case is the same. The agent gets the trigger and the approved script. The system of record stays where it was. The owner can still close the laptop at 6.
Why “connect everything” is the wrong demo
Most of the tools sold to a small firm start by asking for the widest login available. The whole inbox. The whole accounting file. Admin on the workspace. The demo looks fluent because the agent can see everything a partner can see.
That is the demo to refuse. Fluency is not a control. A partner who cannot point to the list of what the agent opened last Tuesday does not have an agent. They have a shared password with a better interface.
The narrower build is slower to show and easier to defend. An invoice agent with read access to an aging report, and send access to one template, can be explained to a client, a partner, or a successor in a page. An agent with admin on QuickBooks, the tax software, and the vault cannot be explained, because nobody can say what it might have read.
There is a second reason to keep the connection narrow. Generative tools differ in what they keep. Some are set so prompts are not used to train a model. Some are not. Some are a firm’s own closed environment. Some are a consumer account someone opened because it was fast. A playbook that says “the invoice list, and nothing else” still fails if that list is pasted into a tool whose terms the firm has not read. The access list and the vendor terms are the same decision.
The duty does not move
None of this is a new rule invented for agents. It is the rule the firm already works under, applied to a new desk.
For a law practice, the American Bar Association’s Formal Opinion 512, issued in July 2024, is the clearest statement. A lawyer using generative AI still owes competent representation, and competence includes a reasonable understanding of the benefits and risks of the technology being used. The lawyer does not have to become an expert in the tool. The lawyer does have to know what it can and cannot be trusted to do. Model Rule 1.6 still requires the lawyer to keep confidential all information relating to the representation, and to make reasonable efforts against inadvertent or unauthorized disclosure. Opinion 512 is specific about self-learning tools: because their output can lead to disclosure of information relating to a representation, informed client consent is required before that information is put into such a tool. Consent, when it is required, means a real explanation of what will be disclosed, the risk, and the benefit. A sentence in an engagement letter that says “we use AI” is not that conversation.
For a CPA firm, the AICPA Code of Professional Conduct’s Confidential Client Information Rule, ET §1.700.001, bars a member in public practice from disclosing confidential client information without the client’s specific consent, outside a short list of exceptions. The professional-liability guidance from the AICPA’s member insurance program makes the operational point: information entered into a generative tool is information shared with that tool’s owner, and the firm should read the terms before anyone pastes a client’s numbers into it. Several of those guidance notes go further and tell firms to prohibit staff from sharing confidential client information with generative tools at all, and to treat a prompt with the same care as a public post.
A first-reply agent or an invoice agent should be designed so that those duties are not tested. Do not put information relating to a representation into a self-learning tool. Do not put a client’s return, workpapers, or portal into the agent because the reminder job does not need them. If a later workflow genuinely requires client information to leave the firm’s systems, that is a different project, with its own consent conversation, and it is not the first one.
This article is not legal, tax, or ethics advice. Texas and other states add their own rules, and a firm’s counsel is the right reader of a vendor contract. The playbook is how the owner stays able to have that conversation, because the access is already written down.
What approval actually means
“A human in the loop” is too vague to operate. Approval means a named person, a named kind of message, and a place the exception waits.
Before the agent runs on its own, the owner reads the playbook and the sample sends. The samples are the firm’s words, not a model’s. After it runs, three things stay true. Ordinary messages that match the script go out, and they appear in the log. Anything that does not match waits. The owner can turn the send off without turning the read off, so a bad week does not become a silent week or an unsupervised one.
At 30 days the review is the same four numbers used for any first agent: hours returned, response time, error rate, and how many of the owner’s minutes the agent still needs. For this subject, add one more. How often did it touch, or try to touch, something outside the list? If the answer is not zero, the list was wrong or the connection was wider than the job. Either way, it stops until the playbook is rewritten.
The office can still close at 5. The client file does not have to be open for the form to get an answer.
If the question in the partnership meeting is what the agent would be allowed to open, that is the right first meeting. A 45-minute audit ends in a written brief: the workflow, the tools, the risks, and a recommended sprint, or a clear no. Book a first agent audit. How the sprint works: berrybuckley.com/first-agent. Where firms usually start: berrybuckley.com/agents.
Questions owners ask
What should a workflow agent be allowed to access?
Only the records its one job needs. An intake agent needs the new inquiry and the calendar. An invoice agent needs the aging list and the approved reminder. A content agent needs the brief in the review queue. Access to the whole inbox, the accounting file, or the document vault is a different and worse decision.
What must an agent never touch in a CPA or law firm?
The client file, the tax return and workpapers, the matter, the document vault, and the client portal, unless that access is the job and the firm has handled consent. It also must not give legal, tax, or financial advice, quote an unapproved fee, or send anything that is not in the owner’s playbook.
Is an automatic reply a disclosure of client information?
A reply to the person who just wrote in, using only what they submitted and language the firm approved, is the firm answering its own inquiry. Putting that person’s information, or anyone else’s file, into a self-learning generative tool is a different act. ABA Formal Opinion 512 treats input of information relating to a representation into such a tool as something that requires informed consent.
Who approves what the agent sends?
The owner, before it runs. The playbook lists the messages that can go on their own, the messages that wait, and the named person who clears the exceptions. A log shows what was sent. “Someone will keep an eye on it” is not an approval.
Do we have to connect QuickBooks, the inbox, and the client portal?
No. Connect the system the job actually uses. An invoice reminder does not need the tax software. An after-hours form reply does not need the vault. A wider connection is harder to explain to a client and harder to unwind.
Sources
American Bar Association, Standing Committee on Ethics and Professional Responsibility. Formal Opinion 512, Generative Artificial Intelligence Tools, July 29, 2024.
AICPA Code of Professional Conduct, ET §1.700.001, Confidential Client Information Rule.
AICPA member insurance guidance, “What are the risks of accounting firms using Generative AI?”