Enterprise DNA

Omni by Enterprise DNA

Enterprise DNA Resources

Thought leadership & research. Practical AI operating-system thinking for owners, operators, and teams doing real work.

220k+

Data professionals

Omni

AI agents and apps

Audit

Map the manual work

Key Findings

Most financial advisory firms don't know their AI agents share login credentials. That practice multiplies breach risk for client portfolios.

AI Agents Sharing Credentials Put Client Data at Risk
Insight ai

AI Agents Sharing Credentials Put Client Data at Risk

Sam McKay

Financial advisory firms are deploying AI agents to speed up meeting prep, compliance documentation, and client onboarding. The promise is real: advisers get hours back every week, paraplanner costs drop, and clients move through the pipeline faster. But a new security problem has emerged that most firms haven’t noticed yet.

Recent research from NTT DATA and Snowflake found that 69% of enterprise AI agents share credentials with other systems instead of operating under their own identity. For a financial advisory firm, that means your Meeting Prep Agent logs into your portfolio management system using a shared service account, your Advice Document Agent pulls client data through the same pooled login, and your Client Onboarding Agent accesses KYC databases without a unique audit trail. When a breach happens or a mistake occurs, you can’t trace which agent did what. Worse, if one agent’s access is compromised, every system it touches is exposed.

This isn’t a theoretical risk. Financial data is the second-most targeted category in cybersecurity incidents, and advisory firms hold concentrated pools of it: account numbers, tax files, estate plans, insurance policies. A single compromised credential that multiple agents share can open the door to all of it. The firms we work with typically manage between 200 and 2,000 client households. A breach that exposes even a fraction of that client base triggers mandatory reporting, potential ASIC or regulatory action, and reputational damage that takes years to repair.

The good news is this problem is fixable. The better news is fixing it doesn’t mean shutting down your AI agent work. It means building those agents the right way from the start, with individual identity, scoped permissions, and an audit trail that survives a regulator’s questions. Let’s walk through what shared credentials actually look like in practice, why the risk compounds in financial advisory firms, and how to structure agent permissions so you can move fast without gambling your client data.

How Shared Credentials Creep Into AI Agent Deployments

Most advisory firms don’t set out to build insecure agents. The shared-credential pattern emerges because it’s the path of least resistance when you’re trying to ship something quickly.

Here’s the typical sequence. An adviser or operations manager identifies a pain point: meeting prep takes too long, SOA drafting is a bottleneck, new client onboarding drags into the second month. Someone on the team (or a vendor) builds an AI agent to automate part of the workflow. The agent needs to pull data from your portfolio management system, your CRM, maybe your document storage. The fastest way to grant that access is to create a single service account with broad read permissions and hand the credentials to the agent. The agent works. The pain point eases. No one revisits the security model.

Now you build a second agent for a different task. It needs access to some of the same systems, plus a couple of new ones. You use the same service account because it’s already configured. By the time you have three or four agents running, they’re all sharing one or two sets of credentials, and no single person in the firm can tell you which agent has access to what.

The problem compounds when those agents start taking actions, not just reading data. A Meeting Prep Agent that only pulls portfolio snapshots is lower risk than an Advice Document Agent that writes file notes into your compliance system or a Client Onboarding Agent that updates KYC records. If all three agents share the same login, a mistake by one agent (or a malicious actor who compromises that login) can propagate across every system the firm uses.

We see this pattern in roughly two-thirds of the advisory firms that come to us for the AI audit for financial advisory firms. The firms aren’t negligent. They’re moving quickly in a space where the security playbook for AI agents is still being written. But the cost of getting it wrong is steep, and the window to fix it before a breach happens is narrower than most owners realize.

Why Financial Advisory Firms Face Elevated Risk

Financial advisory firms occupy a unique position in the risk landscape. You hold more sensitive data per client than almost any other professional services business, you’re bound by strict regulatory frameworks (ASIC, privacy law, professional indemnity requirements), and your clients expect a level of confidentiality that goes beyond what they’d expect from, say, their accountant or lawyer.

When an AI agent in your firm shares credentials, the blast radius of a breach is larger. A single compromised login can expose:

  • Portfolio holdings and transaction history for hundreds of clients.
  • Tax file numbers, Medicare numbers, and other identity documents collected during onboarding.
  • Estate planning documents, beneficiary designations, and power of attorney records.
  • Insurance policies with health disclosures and underwriting details.
  • Email and meeting transcripts that discuss financial distress, divorce, or other sensitive life events.

The regulatory exposure is immediate. If a breach occurs and you can’t demonstrate that access was appropriately scoped and audited, you’re facing mandatory breach notification under privacy law, potential ASIC scrutiny, and a professional indemnity claim that could run into six figures. Even if the breach doesn’t result in financial loss to clients, the reputational damage in a referral-driven business is hard to quantify but easy to feel.

The operational risk is just as real. Shared credentials make it nearly impossible to trace agent activity after the fact. If a client disputes a file note or questions a transaction record, you need to show exactly which system touched that data and when. If three agents share the same login, your audit trail is mud. That ambiguity creates liability, slows down incident response, and erodes trust with clients who expect you to know what happened to their information.

Financial advisory firms also face a structural challenge: most firms don’t have dedicated IT or security staff. The principal or GM is often the de facto tech decision-maker, and the firm’s technology stack is a patchwork of vendor platforms (portfolio management, CRM, document storage, compliance tools) that weren’t designed to interoperate securely. Adding AI agents into that environment without a clear permission model is like adding a new lane to a bridge without checking the load-bearing capacity. It might hold. It might not.

What Proper Agent Identity and Permissions Look Like

The fix starts with giving each AI agent its own identity. Instead of a shared service account, each agent gets a unique credential tied to its specific function. Your Meeting Prep Agent has one identity, your Advice Document Agent has another, your Client Onboarding Agent has a third. Each identity is scoped to the minimum permissions the agent needs to do its job, and no more.

In practice, this means:

  • The Meeting Prep Agent can read portfolio data and recent client communications, but it can’t write to your compliance system or update KYC records.
  • The Advice Document Agent can read meeting transcripts and compliance templates, write draft SOAs to a staging folder, but it can’t send emails or access client bank account details.
  • The Client Onboarding Agent can collect documents and populate a fact-find template, but it can’t approve a client for onboarding or modify existing client records.

Each agent’s activity is logged under its own identity, so when you review your audit trail, you see exactly which agent accessed which data and when. If something goes wrong, you can trace the action back to a specific agent, review its permission scope, and determine whether the agent was operating within its intended boundaries or whether a configuration error or compromise occurred.

This model also makes it easier to shut down or modify an agent without disrupting the rest of your operations. If you decide to retire the Meeting Prep Agent or change how it works, you revoke its credentials and nothing else is affected. If you’re using shared credentials, shutting down one agent means reconfiguring every other agent that uses the same login, which creates downtime and introduces new risk.

The firms that build agents this way from the start report fewer security incidents, faster incident response when something does go wrong, and cleaner audit trails when regulators or professional indemnity insurers ask questions. The upfront work to set up individual identities and scoped permissions pays for itself the first time you need to explain what an agent did (or didn’t do) with client data.

The Three Agents Financial Advisory Firms Build First

Most advisory firms start their AI agent work in one of three areas: meeting prep, advice documentation, or client onboarding. These are the highest-pain, highest-frequency tasks in the business, and they’re where the ROI of automation is easiest to measure.

The Meeting Prep Agent pulls together everything an adviser needs before a client meeting: recent portfolio performance, goal progress, upcoming reviews or actions, and a summary of the last few interactions. Instead of spending 30 to 45 minutes before each meeting hunting through systems, the adviser opens a one-page brief that the agent prepared overnight. For a firm with 10 advisers each seeing 15 clients a week, that’s 75 to 110 hours saved every month. The agent reads from your portfolio management system, your CRM, and maybe your email archive. It doesn’t write anything or take actions. Its permission scope is narrow: read-only access to the specific data sources it needs, nothing more.

The Advice Document Agent drafts SOAs, ROAs, and file notes from meeting transcripts and the firm’s compliance templates. A paraplanner reviews and finalizes the draft, but the agent does the first 70% of the work: pulling in client data, structuring the document, inserting standard clauses, and flagging areas that need manual attention. This agent needs broader access: it reads meeting transcripts, client records, and compliance templates, and it writes draft documents to a staging area where paraplanners can review them. The key is that it can’t publish or send anything directly to a client. Its write permissions are scoped to a review folder, and a human must approve before the document goes live.

The Client Onboarding Agent runs a guided fact-find with new clients, collects KYC documents, and prepares a clean onboarding pack for the adviser. Instead of a 30 to 60 day onboarding cycle with multiple back-and-forth emails, the agent walks the client through the process in a structured way, validates that all required documents are present, and flags any gaps before the adviser’s first meeting. This agent writes to your CRM and document storage, but it can’t approve a client for onboarding or modify existing client records. Its permissions are scoped to new client records only, and it hands off to a human for final review.

Each of these agents delivers measurable time savings and cost reduction. The Meeting Prep Agent cuts meeting prep time by 60 to 80 percent. The Advice Document Agent reduces paraplanner hours per SOA by 40 to 60 percent, which translates to $1,200 to $4,800 in cost savings per document. The Client Onboarding Agent compresses onboarding cycles from 30 to 60 days down to 10 to 20 days, which means new clients start generating revenue sooner and drop out less often.

But those gains evaporate if the agents share credentials and a breach exposes client data. The firms that get this right build the agents with individual identity and scoped permissions from day one. The firms that don’t often realize the problem only after an incident, when it’s too late to prevent the damage.

How to Audit Your Current Agent Security Posture

If you’ve already deployed AI agents, the first step is to map what you have. Most firms can’t answer three basic questions: which agents are running, what systems they access, and whether they share credentials. You need to know the answer to all three before you can fix the problem.

Start by listing every AI agent or automation that touches client data. Include agents you built in-house, agents a vendor deployed for you, and any RPA or workflow automation that might not be labeled as “AI” but functions the same way. For each agent, document:

  • What task it performs.
  • Which systems it reads from.
  • Which systems it writes to.
  • What credentials it uses to access those systems.
  • Whether those credentials are unique to the agent or shared with other agents or users.

If you find that multiple agents share the same login, that’s your red flag. The next step is to assess the blast radius: what could a compromised agent do with those credentials? Can it read sensitive client data? Can it modify records? Can it send emails or initiate transactions? The broader the access, the higher the risk.

Once you’ve mapped your current state, prioritize the fixes. Agents with write access to client records or compliance systems are higher risk than agents that only read data. Agents that access multiple systems through a single shared credential are higher risk than agents with narrow, read-only access. Start by isolating the highest-risk agents: give them unique identities, scope their permissions down, and log their activity separately.

For firms that don’t have the internal capability to do this work, the Omni Audit for financial advisory firms walks through the entire exercise in 60 minutes. We map your current agents, identify shared credentials, assess the risk, and give you a prioritized list of fixes with cost and timeline estimates. You leave the call with three outputs: a current-state map, a risk assessment, and a roadmap to close the gaps. No deck, no follow-up meetings, no sales pitch. Just the information you need to make a decision.

The Cost of Inaction

The firms that ignore this problem don’t do so because they think it’s unimportant. They ignore it because it’s invisible until something breaks. Shared credentials work fine right up until the moment they don’t, and by then the damage is done.

The direct costs of a breach in a financial advisory firm typically include mandatory breach notification (legal and communication costs), forensic investigation to determine what was accessed, regulatory response (ASIC inquiries, potential fines), and professional indemnity claims if clients suffer loss. For a mid-sized firm, those costs can run $50,000 to $150,000 even if the breach is contained quickly and no client data is misused.

The indirect costs are harder to measure but often larger. Client churn accelerates when trust is broken. Referrals dry up. Recruitment becomes harder because top advisers don’t want to join a firm with a reputation for sloppy data handling. Vendor relationships suffer because portfolio managers and custodians start asking harder questions about your security posture before they’ll integrate with your systems.

The opportunity cost is the most painful. Every hour you spend responding to a breach is an hour you’re not spending on client work, business development, or building the next agent that could save your firm 500 hours a year. The firms that get agent security right from the start avoid all of that. They move faster, build more agents, and compound the productivity gains without the existential risk of a breach.

What the Omni Audit Delivers

The Omni Audit is a 60-minute working session where we map your current AI agent landscape, identify security gaps (especially shared credentials), and build a roadmap to fix them. You walk away with three outputs:

  1. Current-state map: Every agent you’re running, what it accesses, and whether it shares credentials.
  2. Risk assessment: Which agents pose the highest risk, what the blast radius of a breach would be, and where you’re exposed to regulatory or client liability.
  3. Roadmap: A prioritized list of fixes with cost and timeline estimates, so you know what to tackle first and what it will take to close the gaps.

No deck. No follow-up meetings. No sales pitch. Just the information you need to make a decision about how to secure your agents without slowing down your automation work.

The firms that go through the audit typically find two or three high-risk agents they didn’t realize were sharing credentials, plus another handful of lower-risk agents that could be tightened up with minimal effort. The roadmap we build together gives you a clear path from where you are today to a state where every agent has its own identity, scoped permissions, and a clean audit trail.

If you’re running AI agents now, or you’re planning to deploy them in the next six months, this audit is the fastest way to de-risk your approach. Book a 60-min Omni Audit and we’ll walk through your current state together.

Building Agents the Right Way From the Start

The best time to fix agent security is before you deploy the first agent. The second-best time is today. If you’re in the planning phase, build individual identity and scoped permissions into your design from day one. If you’ve already deployed agents, audit what you have, identify the shared credentials, and start isolating the highest-risk agents first.

The firms that treat agent security as a design constraint, not an afterthought, report fewer incidents, faster deployments, and cleaner audit trails. They also find it easier to scale their agent work because each new agent is built on the same secure foundation. You don’t have to rebuild your security model every time you add a new capability.

The alternative is to wait until a breach happens and then scramble to explain to clients, regulators, and insurers why your agents were sharing credentials and what you’re doing to fix it. That conversation is expensive, stressful, and entirely avoidable.

Financial advisory firms are in a unique position right now. AI agents can deliver massive productivity gains in meeting prep, compliance documentation, and client onboarding. But those gains only compound if you build the agents securely from the start. Shared credentials are the single biggest security risk in enterprise AI deployments, and they’re especially dangerous in firms that hold concentrated pools of sensitive client data.

The fix is straightforward: give each agent its own identity, scope its permissions to the minimum it needs, and log its activity separately. The firms that do this work now will move faster, build more agents, and avoid the existential risk of a breach. The firms that don’t will eventually face a choice between shutting down their agents or gambling their client data. That’s not a choice you want to make under pressure.

If you’re ready to map your current agent security posture and build a roadmap to close the gaps, book your Omni Audit here. Sixty minutes, three outputs, no deck. We’ll figure out where you are and what it takes to get you where you need to be.

For more on how AI agents are reshaping financial advisory operations, explore our insights on AI transformation or learn about the Omni platform we use to build secure, scalable agents for advisory firms.