Enterprise DNA

Omni by Enterprise DNA

Enterprise DNA Resources

Thought leadership & research. Practical AI operating-system thinking for owners, operators, and teams doing real work.

220k+

Data professionals

Omni

AI agents and apps

Audit

Map the manual work

Key Findings

How financial advisory firms can prevent shared AI credentials from exposing client accounts, records, and compliance obligations.

AI Agent Credentials in Advisory Firms
Insight ai

AI Agent Credentials in Advisory Firms

Sam McKay

AI access is now a client-account control issue

AI agents are moving beyond drafting emails and summarising meeting notes. They are beginning to retrieve portfolio data, read CRM records, collect KYC documents, prepare advice packs, and trigger workflow steps across a firm’s systems.

That creates a security question that partners and compliance leaders can’t leave to the IT team alone.

When an AI tool accesses a client account, whose credentials is it using?

The recent discussion around Portnox adding Microsoft Defender integration to police AI agent access points to a practical problem. Firms need visibility into which agents are operating, what systems they can reach, and whether their access can be traced to a defined business purpose.

For a financial advisory firm, shared agent credentials are a weak point.

A single AI automation account with broad access to the CRM, document store, portfolio platform, and email inbox might look efficient. It can also make it hard to answer basic questions after an incident:

  • Which client records did the agent access?
  • Which adviser or team approved that access?
  • Did the agent retrieve only the data needed for a task?
  • Can the firm prove who initiated an action?
  • What happens if a former staff member, contractor, or connected application retains access?
  • Could one client’s data be exposed during work on another client’s file?

Those aren’t theoretical concerns. Advisers hold identity documents, tax records, family information, asset data, investment preferences, health-related insurance information, and correspondence that can reveal sensitive life events. A poorly controlled AI account can turn a useful workflow into a regulatory and reputational problem.

The right objective isn’t to avoid AI. It’s to build agents that operate with controlled, attributable access.

For a view of the broader operating opportunity, See Omni for financial advisory firms. The audit starts with the work your team does, then maps the systems, data, controls, and financial impact around it.

Why shared credentials create an avoidable risk

Shared credentials usually appear because a firm wants to get an automation working quickly.

Someone creates a generic account such as automation@firm.com. That account is given access to a shared mailbox, a CRM integration, a document-management folder, or a portfolio reporting tool. An AI workflow uses the account to retrieve information and prepare outputs.

At first, the arrangement may seem contained. Then the workflow expands.

The agent begins with meeting briefs. A month later it pulls correspondence. Then it needs access to client fact-finds. A compliance team member asks it to draft file notes. Operations adds onboarding document collection. One shared identity now touches many client records across the business.

The issue isn’t just the password. It is the lack of boundaries.

A shared AI credential can make it difficult to enforce least-privilege access. It can blur the difference between a task performed for Client A and one performed for Client B. It can also create poor audit evidence when the firm needs to demonstrate how information was handled.

Financial advisers already understand this principle in human workflows. Not every staff member should access every client file. A paraplanner may need documents for a specific advice document. A client services team member may need to follow up on missing KYC. An adviser may need the complete relationship view for their own client.

AI agents should follow the same operating model.

Each agent needs a defined role, a defined set of systems, narrow permissions, and logs that make its actions explainable. In higher-risk environments, the access should be scoped to the specific client record or work item where the task is taking place.

That is more than a technical preference. It is a business control.

The work agents can support without opening every door

Most advisory firms in the USD 1M to USD 25M range don’t need a generic autonomous bot with unrestricted access. They need practical agents that remove recurring administrative work while preserving judgement, review, and accountability.

Three workflows show where credential design matters.

Meeting preparation

Client review preparation often involves logging into several systems, checking portfolio changes, reviewing recent communications, looking at goal progress, and finding outstanding actions from the last meeting.

Advisers commonly lose 5 to 10 hours per week to preparation, note-taking, follow-up, and the work surrounding client meetings. Some of that work is valuable thinking. Much of it is searching, assembling, formatting, and copying information between systems.

The Meeting Prep Agent in Omni ops pulls portfolio data, recent communications, and goal progress into a one-page brief an adviser reads before every client meeting.

That agent should not have broad access to every relationship in the firm.

A better design looks like this:

  1. The adviser or approved scheduler initiates a meeting-prep request for a named client.
  2. The agent receives a client identifier and meeting context.
  3. It accesses only approved data sources for that client, such as CRM notes, recent communications, portfolio reporting, and the current goals record.
  4. It produces a brief in a controlled location.
  5. The adviser reviews the brief before using it in the meeting.
  6. The system records the request, sources used, output location, time, and approving user.

The agent doesn’t need permission to change holdings, submit transactions, edit client risk profiles, or browse the entire client database. It needs read access for a defined purpose and a short execution window.

That distinction matters when you are asked to evidence your controls.

Advice documents and file notes

The Advice Document Agent drafts SOAs, ROAs, and file notes from meeting transcripts and the firm’s compliance template. This can reduce the time between a client interaction and a review-ready document, particularly where paraplanners are carrying a substantial document queue.

Advice documentation is also where firms need to be most careful. A draft SOA is not a finished advice document. An AI output must not bypass the authorised adviser, the review process, approved templates, disclosure requirements, or recordkeeping obligations.

Paraplanner cost per advice document can often fall in the USD 3,000 to USD 8,000 range once research, drafting, revisions, review, and rework are included. The real figure depends on advice complexity and how much of the process is handled internally. A capable agent can reduce repetitive drafting effort, but only if the workflow captures the right source information and routes output through the correct controls.

Unique credentials help keep this clean.

The Advice Document Agent should operate under its own service identity, not an employee’s login and not a generic shared credential that also runs unrelated automations. Its permissions should be limited to approved templates, the relevant client workspace, transcript inputs, and the document workflow.

It should not have the authority to approve advice, alter a signed document, or send documents to a client without a human release step.

The audit record should show:

  • the client or matter reference
  • the source transcript or meeting record used
  • the template version used
  • the agent identity and workflow version
  • the user who initiated the draft
  • the reviewer who approved or amended it
  • the final storage location

That gives your compliance function a far stronger starting point than “the AI drafted it.”

If you are considering where this fits operationally, Omni ops is built around the recurring processes that drain team capacity without needing to hand over business judgement.

Client onboarding and KYC

Onboarding is another workflow where firms can unintentionally create overbroad access.

A typical new-client journey may take 30 to 60 days. Clients need to provide identity documents, complete fact-finds, answer risk questions, share account statements, and respond to follow-up requests. Every delay increases the chance that momentum fades before the relationship is fully established.

The Client Onboarding Agent runs a guided fact-find with new clients, collects KYC documents, and prepares a clean onboarding pack for the adviser.

This is useful work, but it handles some of the firm’s most sensitive data.

The agent should have a dedicated identity and a controlled intake environment. It should collect documents into a client-specific folder or case workspace. It should validate that required items are present. It can flag gaps and prepare a pack. It should not give itself access to all historical client folders simply because the document system makes that convenient.

A sound onboarding workflow also separates collection from approval. The agent can request a driver’s licence or proof of address. A trained staff member should determine whether the documents satisfy the firm’s KYC policy and whether further verification is required.

That is the operating pattern to aim for. AI accelerates preparation and follow-up. People retain responsibility for advice, approvals, exceptions, and risk decisions.

What unique credentials should mean in practice

“Use unique credentials” can sound simple until you get into the details. For most firms, it means designing access at three levels.

First, each agent has its own service identity.

The Meeting Prep Agent should not use the Advice Document Agent’s token. The Client Onboarding Agent should not share a mailbox password with a marketing automation. Each identity should be visible in your identity platform, integration register, and access review process.

Second, each workflow uses task-level context.

The agent needs to know which client, matter, or meeting it is working on. It should only retrieve records tied to that context. In a mature setup, the workflow checks the user’s permissions before allowing the agent to act.

Third, each agent has limited rights.

Read access, write access, send permissions, deletion rights, and administrative controls should be separated. An agent that produces a meeting brief generally needs read access. An agent that creates a draft document needs permission to write to a draft folder, not to overwrite final client records.

There are also several controls worth putting in place early:

  • Use short-lived tokens where your systems support them.
  • Store secrets in a managed vault, not inside workflow scripts or shared spreadsheets.
  • Rotate credentials on a defined schedule and immediately after a suspected incident.
  • Require multi-factor authentication for people who administer agent identities.
  • Log every connection, data retrieval, document creation, and external transmission.
  • Block agents from accessing personal email, consumer file-sharing tools, or unmanaged storage.
  • Review inactive agents and unused integrations at least quarterly.
  • Maintain a register of AI tools, data sources, owners, purposes, and approval status.

The point is not to create bureaucracy for its own sake. The point is to make access proportionate to the task.

You can find practical material on operating models and AI adoption through our guides and learning resources. The firms that move well tend to document the workflow before they automate it.

Don’t confuse monitoring with permission design

Tools that monitor endpoints, identities, and AI activity can provide important visibility. The Portnox and Microsoft Defender conversation is useful because it brings attention to detection and enforcement around agent access.

But monitoring alone doesn’t fix a badly designed workflow.

If an agent is allowed to access every client record, a security tool may detect unusual behaviour. It doesn’t change the fact that the permissions were excessive from the beginning.

The better approach has two parts.

Permission design prevents unnecessary access. Monitoring helps identify misuse, anomalies, compromised credentials, or policy breaches that still occur.

Ask your technology team, managed service provider, or software vendor these questions before connecting an AI agent to client systems:

  1. Can the agent use its own service account?
  2. Can we limit access to specific client records, teams, or folders?
  3. Can the integration issue short-lived tokens rather than maintain a permanent password?
  4. Are the agent’s actions logged in a way we can export and review?
  5. Can we disable the agent immediately without affecting staff access?
  6. Does the platform distinguish an AI action from a human user’s action?
  7. Where is client data processed and stored?
  8. Is information retained to train a third-party model, and can that be disabled?
  9. Can the agent transmit data outside our approved systems?
  10. Who is accountable for reviewing access every quarter?

If a vendor can’t answer these questions clearly, don’t connect the tool to client information yet.

The dollar cost is bigger than an IT ticket

For an advisory firm, the annual leakage from manual work, rework, slow onboarding, fragmented documentation, and weak process controls often sits in the USD 70,000 to USD 200,000 band.

That doesn’t mean every dollar can be removed with an AI agent. It means there is usually a meaningful pool of wasted capacity in the operating model.

A partner might see it as an adviser who stays back to prepare review notes. A client services manager sees it in repeated document chasing. A paraplanner sees it in re-drafting the same information across templates. A compliance lead sees it in incomplete records and the time spent reconstructing what happened.

Poor credential design adds another cost layer. It can slow down every future automation because the firm has to untangle access after the fact. It can create expensive remediation work after a staff change or vendor incident. It can also force a firm to pause useful automation because nobody is confident about the control environment.

Build secure access properly at the start and you make it easier to deploy more workflows later.

If you want help identifying the first workflow, the control gaps, and the commercial upside, Book a 60-min Omni Audit. It is a working session, not a software demonstration.

What an Omni Audit produces

Most firms don’t need a 40-page AI strategy document. They need clarity on what to fix first.

The Omni Audit takes 60 minutes and produces three useful outputs.

First, we identify the manual workflows where the firm is losing the most capacity. That may be meeting preparation, advice documentation, onboarding, client communications, or another process specific to your team.

Second, we map the data and access requirements for the agent. This includes source systems, client-data classifications, approval points, unique service identities, audit records, and human handoffs.

Third, we prioritise an implementation path based on impact, effort, and risk. You leave with a practical starting point rather than a deck of generic opportunities.

The exercise often reveals that a firm can begin with a lower-risk agent, such as meeting preparation, while it improves controls around advice documents or KYC. That is a sensible sequence. You don’t need to automate the most sensitive process first to get a return.

For more context on the approach, review the AI audit for financial advisory firms and see how Omni connects operating workflows with the systems your team already uses.

Make access part of the workflow design

AI agents can give advisory firms time back. They can reduce preparation work, shorten document cycles, improve onboarding follow-up, and give advisers better context before client conversations.

They should not become invisible users with broad access to client data.

Treat every agent as a worker with a role description. Give it a unique identity. Limit what it can access. Record what it does. Keep approval decisions with the people accountable for advice and compliance.

That approach protects the firm while making automation easier to scale.

If shared credentials, unmanaged AI tools, or unclear access controls are already creeping into your workflows, deal with it before connecting another system. Book my Omni Audit and we will identify the workflow, the access model, and the most practical next move.