Take a firm of twenty two people, an illustration rather than a real one, running a matrimonial matter for a client on the same road as one of its paralegals. That paralegal has never been asked to touch the file and has no reason to read it, yet she can open every attendance note and bank statement in it in the time it takes to type a surname into the search box.

Nothing has gone wrong in that firm. The case management system was installed the way most of them are installed, with a single permission level covering everyone in the office, and the question of who ought to be able to read which matter was never put. From the first morning the whole office holds every matter the firm has ever opened.

The duty of confidentiality in the SRA Standards and Regulations runs to each client individually. It is not owed to the world at large and discharged by keeping information in one building. A client who tells her solicitor about a diagnosis she has kept from her family is confiding in that solicitor and in whoever needs to know to act for her. That everyone able to read her file draws a salary from the same partnership answers a different question.

The harm arrives in situations any firm will recognise. A matrimonial or employment matter where a party is known to a member of staff, a neighbour or a former employer, becomes a file people have a private reason to read. A matter against a former client needs an information barrier, and a barrier that amounts to an instruction not to look is no barrier. A redundancy consultation the firm runs for itself sits in the same system as everything else, within reach of the people whose positions are being discussed. A file belonging to a member of staff, or to a staff member's mother, raises the plainest question of all.

The firm is also the data controller for everything those files contain, and UK GDPR imposes a separate obligation to limit access to what a role requires. Confidentiality asks whether a person has any business knowing. Data protection asks whether the access that person holds is proportionate to the work they do. A cashier needs the ledger and the payment details rather than the statement setting out a client's medical history, and the firm has to be able to explain why that access exists.

Three files and one question

A firm can test its position in an afternoon without buying anything. Pick three live matters, chosen because they are sensitive rather than convenient, and ask two things of each. Who in this building can open this file, and can we prove who already has. Answer the first by looking at the system with whoever administers it, because the policy records intentions and the system records reality. In firms that have never revisited the original installation the answer is usually everyone, including anyone whose login outlived their leaving date.

The second question catches firms out. Access rules and access logs do different work, and the rules are the easier half. If a firm cannot produce a record showing which user opened which matter and when, its information barrier is an assertion rather than a control. A regulator asking how a conflict was managed wants evidence, and an account of what the firm intended is not evidence. A firm that keeps a log answers within the hour rather than interviewing staff about a Tuesday eight months ago.

Who takes the decision

Restricting access looks like a software task, which is how it ends up with whoever administers the system. It is a supervision task. Deciding that a barrier stands between two fee earners who once acted for the same person, or that a staff member's own divorce is visible to two named people, calls for judgement about the client and about the risk of harm. The COLP and the supervising partner hold that judgement and the administrator carries it out. It needs revisiting too, because people move between teams and cover during illness should be granted deliberately rather than left open all year.

Bracton was built on that separation. Its permission model decides which matters appear in a fee earner's list, which files an information barrier conceals and who can approve a payment, and the firm sets and changes those permissions rather than Bracton Ltd. Every access is recorded in an audit trail the firm reads for itself, so a question about who opened a file on a given afternoon has an answer instead of a recollection. Where the Bracton AI Assistant connects to a case management system the firm already runs, it reads under the permissions the firm has set on that system, so a barrier stays where the firm drew it.

The three file test tells you where you stand and costs nothing but an afternoon. If you would rather see permissions, barriers and an audit trail working on matters that look like your own, with your team names against them, book a client account review.