appleby.systems

Clearer control of client information in Microsoft 365

A fictional professional services firm has grown through new offices and staff changes. A client asks who can access its documents, and the firm cannot give a clear answer.

The business situation

The firm uses Microsoft 365 for email, shared documents and collaboration with clients. Its IT provider keeps the service running, but access arrangements have accumulated as people have joined, left or moved between roles.

Some external collaborators still have access to old projects. Staff are unsure which sharing options to use. The operations director wants to understand the position before buying another security product.

What the review would establish

I would work with the firm and its provider to establish who can reach important information, where that access is still needed and who is responsible for approving it. The review would include the arrangements for staff leaving and projects ending.

The findings would distinguish between protection already available in the existing services and any additional capability the business actually needs. Recommendations would explain the effect on client work as well as the security benefit.

How improvements could be introduced

The firm could agree clearer access rules, remove permissions that are no longer needed and give staff a consistent way to share documents. Changes would be discussed with the people affected before they were introduced.

The provider would have an agreed process to maintain, with a named business contact for access decisions. Reviewing those arrangements when staff or client work changes would help prevent the same uncertainty returning.

What a useful result would look like

The firm should be able to explain who has access to client information and why, supported by the review. Staff would have clearer guidance, and the operations director could understand what had changed without interpreting a technical settings report.

That would provide a better basis for answering client questions and managing future changes. It would not amount to a guarantee against an incident or proof of compliance with every client requirement.

How the business could assess progress

  • Can the firm account for access to important client documents?
  • Do staff and the IT provider know who approves and removes access?
  • Can the firm explain which changes were made and why?

Related services

Microsoft 365 security

Review how your business email and documents are protected, and decide which changes are worth making.

IT security

Understand how well your business is protected, address weaknesses and make security part of the way your systems are managed.

Other example situations

A recovery plan the business can assess

A fictional distribution business relies on one system for orders, stock and dispatch. Its backups report success, but nobody knows how long a serious outage would interrupt deliveries.

Potential benefit: Recovery expectations supported by evidence, clearer responsibilities and a practical basis for reducing disruption.

Invoice automation with financial control retained

A fictional construction and property business handles invoices across several teams. Repeated data entry and unclear approvals cause delays, and the finance lead is considering AI.

Potential benefit: Less repeated entry and fewer avoidable queries, if the trial demonstrates a worthwhile improvement after checking and running costs are included.

Facing a similar question?

Tell me what you want to improve or understand. The initial conversation is free.