Enterprise DNA

Omni by Enterprise DNA

Enterprise DNA Resources

Thought leadership & research. Practical AI operating-system thinking for owners, operators, and teams doing real work.

220k+

Data professionals

Omni

AI agents and apps

Audit

Map the manual work

Key Findings

Sixty-nine percent of enterprises share API keys across AI agents. For law firms, that practice creates discoverable security gaps that can breach privilege.

Shared API Keys Put Client Privilege at Risk in Law Firms
Insight ai

Shared API Keys Put Client Privilege at Risk in Law Firms

Sam McKay

A Brownstone Worldwide survey found that 69% of enterprises share API keys among AI agents and staff. For most businesses, that’s a security headache. For law firms, it’s a privilege nightmare.

When three associates use the same ChatGPT Team login to draft motions, summarise discovery, and review client emails, you’ve created a single point of failure. If one person’s laptop is compromised, opposing counsel can argue that every document touched by that credential is discoverable. You can’t prove who accessed what, when, or why. The audit trail doesn’t exist.

Most managing partners don’t realise this is happening. An associate signs up for an AI tool, shares the login with two colleagues to save on seats, and suddenly your firm is running privileged work through a shared credential with no logging. It feels efficient until you’re sitting in a sanctions hearing trying to explain why you can’t produce access records for a client file that was summarised by an AI agent.

This isn’t theoretical. We’re seeing it in intake for the AI audit for law firms every month. Firms with 8 to 40 attorneys, doing solid work, billing $2M to $15M a year, and running half their AI usage through two or three shared accounts. The IT person doesn’t know. The partners assume someone else is handling it. And the associates are just trying to get the work done faster.

Why Law Firms Share API Keys in the First Place

The pattern starts innocently. A junior associate hears about a tool that can summarise depositions or flag contract clauses. She signs up, tries it on a case, and it works. She tells the paralegal. The paralegal tells another associate. Within a week, four people are using the same login because no one wants to wait three days for the IT vendor to provision new seats.

Multiply that by six different tools and you’ve got a mess. One firm we worked with had 11 active AI subscriptions across three practice groups. Only two had individual credentials for each user. The rest were shared logins written on a Post-it note in the break room.

The financial logic makes sense on the surface. Why pay for eight seats at $30 each when three people can share one login for $30 total? You save $210 a month. But you’ve also made it impossible to prove who accessed a privileged document, and you’ve handed opposing counsel a discovery weapon.

The security risk isn’t abstract. If one person’s email is phished and the attacker gets into the shared AI account, every matter that account touched is potentially compromised. You can’t isolate the breach to one case or one client. You have to assume everything is exposed, because your logs can’t tell you otherwise.

What Discoverable Means in This Context

Discoverability in litigation isn’t just about whether a document exists. It’s about whether the other side can compel you to produce records of who accessed what, when, and for what purpose. If you’re using AI tools to review client files, draft work product, or analyse case strategy, those tools are part of your workflow. The access logs are discoverable.

If you can’t produce individual access records because five people shared one login, the court may assume the worst. Judges don’t like gaps in the record. Opposing counsel will argue that your firm’s sloppy security practices waived privilege, and you’ll spend $40,000 in motion practice trying to claw it back.

We’ve seen this play out in discovery disputes over email access and document management systems. The same logic applies to AI tools. If you’re running privileged work through a shared credential, you’re creating a gap that opposing counsel can exploit.

The fix isn’t complicated, but it requires intention. Every attorney and paralegal needs their own credential for every AI tool they use. The credential needs to log every action. And someone at the firm needs to own the audit trail, so when you get a discovery request, you can produce clean records in 48 hours instead of scrambling for two weeks.

The Audit Trail You Need and Probably Don’t Have

A proper audit trail for AI tool usage logs four things: who accessed the tool, what file or matter they worked on, what the tool did, and when it happened. If you’re using an AI agent to summarise a deposition, the log should show which attorney initiated the request, which case file was accessed, what summary the agent produced, and the timestamp.

Most shared logins don’t capture any of that. The log shows that “the account” accessed the tool at 3:47 PM. It doesn’t tell you if it was the senior associate working on the Smith matter or the paralegal reviewing intake forms for the Jones case. You can’t tie the activity to a specific person or a specific file.

That gap is a problem in three scenarios. First, if you’re defending a malpractice claim and you need to prove that your team followed proper procedure on a case. Second, if you’re responding to a discovery request and you need to produce records of who reviewed what. Third, if you’re investigating an internal breach and you need to know which files were accessed by a compromised account.

Individual credentials solve this. Each attorney gets their own login. The tool logs every action under that login. When you need to pull records for a case, you can filter by attorney, by date, and by matter. You can produce a clean CSV in 20 minutes instead of spending three days reconstructing activity from memory.

The cost difference is real but manageable. For a 12-attorney firm, moving from three shared logins to 12 individual seats might add $300 a month across all your AI tools. That’s $3,600 a year. One discovery dispute where you can’t produce audit logs will cost you $30,000 in motion practice and sanctions. The math is straightforward.

How Omni Handles Credentials and Logging by Default

When we build an AI agent for a law firm, individual credentials and audit logging are baked in from day one. It’s not an add-on feature. It’s the foundation.

Our Intake Voice Agent answers every inbound call, captures the matter details, runs a conflict check, and books a consultation. Every call is logged under the agent’s activity record, timestamped, and tied to the case file it created. If a prospect calls at 9 PM on a Saturday and the agent books them for a Tuesday consultation, you can pull the call transcript, the conflict check result, and the calendar entry in one report.

The Matter Triage Agent reviews every form submission and email that comes into your intake queue. It classifies the practice area, scores the lead, and routes it to the right partner with a brief attached. Every action is logged under the agent’s credential. If opposing counsel asks how a particular lead was handled, you can produce a record showing exactly what the agent did, when it did it, and which partner it routed the matter to.

The Document Review Agent performs first-pass review on contracts, discovery batches, and matter files. It flags clauses, summarises positions, and produces a memo. Every document it touches is logged with a timestamp, the attorney who initiated the review, and the output the agent produced. If you need to prove that a privileged document was reviewed only by your team and the agent, the log shows exactly that.

This isn’t magic. It’s infrastructure. Every agent runs under its own service credential. Every attorney who uses an agent has their own login. Every action is logged to a database that you can query by matter, by attorney, by date, or by agent. When you get a discovery request, you pull the records in 20 minutes and move on.

We’ve had firms tell us this level of logging feels like overkill until they need it. Then it’s the only thing standing between them and a sanctions motion. One partner described it as “the boring part that saved us $50,000 in a fee dispute.” That’s exactly right.

The Real Cost of Shared Credentials

The financial cost of shared API keys isn’t the subscription fee you’re saving. It’s the billable time you lose when a discovery dispute blows up, the malpractice premium increase after a breach, and the client relationships you damage when you can’t prove you handled their matter securely.

A mid-sized firm in our network spent $80,000 defending a motion to compel after opposing counsel argued that shared AI logins meant the firm couldn’t prove privilege. The firm won the motion, but it took four months and ate 200 hours of partner time that could’ve been billed at $400 an hour. That’s $80,000 in legal fees plus another $80,000 in opportunity cost.

Another firm lost a client after a data breach exposed case files that had been processed through a shared AI account. The breach was contained to one matter, but the firm couldn’t prove which other matters had been accessed by the compromised credential. The client walked, taking $120,000 in annual billings with them.

These aren’t edge cases. They’re predictable outcomes of running privileged work through shared credentials. The cost of fixing it is a few thousand dollars a year in additional software seats. The cost of not fixing it is six figures when something goes wrong.

If you’re a managing partner reading this and you’re not sure whether your associates are sharing logins, the answer is yes. They are. The question is whether you’re going to fix it before it becomes a problem or after.

What an Omni Audit Uncovers in 60 Minutes

We run a 60-minute audit for law firms that want to know where their AI usage sits today and what gaps need closing. It’s not a sales pitch. It’s a diagnostic. We look at your current tools, your workflows, and your credential management. Then we hand you three outputs: a risk map, a cost model, and a 90-day build plan.

The risk map shows where you’re exposed. Shared logins, missing audit trails, tools that don’t log activity. We rank them by likelihood and impact. A shared ChatGPT login used by three associates to review discovery is a high-likelihood, high-impact risk. A single-user account with no logging is medium. We don’t sugarcoat it.

The cost model shows what you’re losing today and what you’d gain by fixing it. If your associates are spending six hours a week on first-pass document review at $250 an hour, that’s $1,500 per associate per week. Multiply by 12 associates and 48 working weeks, and you’re looking at $864,000 a year in review time. An agent that handles first-pass review cuts that by 60%, saving you $518,000 annually. That’s the math we walk through.

The 90-day build plan is the roadmap. Which agents to build first, which workflows to automate, and how to phase in individual credentials without disrupting your team. We’ve done this enough times that we know which sequence works and which doesn’t. You get a plan you can hand to your IT person or your COO and say, “Start here.”

Most firms come out of the audit with a clear picture of what’s broken and what it’s costing them. Some decide to move forward with Omni. Some take the plan and fix it themselves. Either way, they’re not guessing anymore.

Book a 60-min Omni Audit and we’ll map your current state in one sitting.

A Practical Checklist for Client Intake Security

If you’re not ready for a full audit but you want to tighten up your intake process, we’ve built a checklist that walks through the credential, logging, and security steps every law firm should have in place. It covers conflict checks, client data handling, and AI tool access controls.

You can grab the AI Client Intake Checklist for Law Firms and work through it with your team in an afternoon. It’s not a substitute for proper infrastructure, but it’s a good forcing function to surface the gaps you didn’t know you had.

How to Move from Shared Logins to Individual Credentials

The transition doesn’t have to be disruptive. Start with your highest-risk tools, the ones that touch privileged documents or client data. Provision individual seats for every attorney and paralegal who uses those tools. Set a cutover date two weeks out. Send a reminder email three days before. On cutover day, disable the shared login.

You’ll get complaints. Someone will say it’s inconvenient. Someone else will say the old way was faster. Ignore them. Explain once that individual credentials are a privilege protection issue, not a convenience issue, and move on.

For tools where individual seats are expensive, evaluate whether the tool is worth keeping. If you’re paying $200 a month for a shared account and individual seats would cost $800, ask whether the tool is delivering $800 of value. If it’s not, cut it and reallocate the budget to a tool that logs properly.

For new tools, make individual credentials a requirement before you sign the contract. If a vendor can’t provision individual seats with audit logging, don’t buy the tool. There are always alternatives, and the ones that take security seriously will have proper credential management built in.

This isn’t a one-time project. It’s a policy. Every new hire gets their own credentials on day one. Every tool gets evaluated for logging before you buy it. Every quarter, someone pulls the access logs and spot-checks them for shared activity. It becomes part of how your firm operates, like conflicts checks and client intake forms.

What This Looks Like in a 15-Attorney Firm

A 15-attorney firm doing $8M in annual billings typically has 8 to 12 different AI tools in use across the team. Half are sanctioned by the managing partner. The other half are shadow IT, tools that associates signed up for and started using without telling anyone.

In a typical audit, we find three or four shared logins. One is a legal research tool that four associates share. Another is a contract review tool that two partners share. A third is a transcription service that the whole intake team shares. None of them log individual activity.

The fix costs about $400 a month in additional seats. That’s $4,800 a year. The firm is billing $8M, so it’s 0.06% of revenue. The risk they’re eliminating is a six-figure discovery dispute or malpractice claim. The ROI is obvious.

We usually phase the rollout over 30 days. Week one, we provision individual seats for the legal research tool and the contract review tool. Week two, we migrate the transcription service and set up logging. Week three, we audit the shadow IT tools and either provision proper seats or shut them down. Week four, we train the team on the new login process and run a spot-check to make sure no one’s sharing credentials.

By day 30, the firm has individual credentials for every tool, audit logs for every action, and a policy that makes shared logins a terminable offense. It’s not dramatic. It’s just infrastructure.

The Argument You’ll Hear Against This

The pushback usually comes from two places. First, associates who don’t want the hassle of managing multiple logins. Second, partners who think the risk is overblown and the cost isn’t worth it.

The associates are wrong because password managers exist. You set up 1Password or Bitwarden, store all your credentials in one place, and you’re done. The extra friction is 10 seconds per login. If 10 seconds is too much to ask to protect client privilege, you’re in the wrong profession.

The partners are wrong because the risk isn’t theoretical. We’ve seen firms lose clients, pay sanctions, and burn six figures in legal fees over shared credentials. The cost of fixing it is a rounding error. The cost of not fixing it is a business risk.

The real argument isn’t whether to do this. It’s whether to do it now or after something goes wrong. Firms that wait usually regret it. Firms that fix it early don’t think about it again.

Why Omni Builds This In From the Start

We don’t offer a version of Omni without individual credentials and audit logging because we don’t want to build agents that create liability for our clients. Every agent we ship logs every action, ties it to a user, and stores it in a queryable database. It’s not optional. It’s the product.

This makes our agents more expensive to run than a shared ChatGPT login, but it also makes them defensible in court. If you’re using an Omni agent to handle intake, review documents, or triage matters, you can prove exactly what the agent did, when it did it, and who initiated the action. That’s worth the cost.

We’ve built agents for firms that handle class actions, white-collar defence, and family law. The logging requirements are the same across all of them. Privilege is privilege. If you can’t prove who accessed a file, you can’t defend the privilege claim. It’s that simple.

If you want to see how this works in practice, see Omni for law firms and book a working session. We’ll show you the logging interface, walk through a sample audit trail, and explain how it integrates with your existing practice management system.

The 90-Day Path to Secure AI Usage

Month one is audit and inventory. We map every AI tool in use, identify shared credentials, and rank the risks. We pull access logs where they exist and document the gaps where they don’t. By the end of month one, you know exactly what’s broken.

Month two is remediation. We provision individual seats, migrate shared accounts, and set up logging for every tool. We train your team on the new process and run spot-checks to make sure no one’s reverting to old habits. By the end of month two, every tool has individual credentials and every action is logged.

Month three is automation. We build the agents that replace the manual work your team is doing today. Intake, triage, document review. Each agent runs under its own credential, logs every action, and integrates with your practice management system. By the end of month three, you’ve cut 60% of the manual work and eliminated the shared-credential risk.

This isn’t a consulting engagement that drags on for six months. It’s a 90-day sprint with clear milestones and measurable outcomes. Most firms see ROI by month four, when the time savings from the agents start to compound.

If you’re ready to start, book my Omni Audit and we’ll map the first 30 days in the session.

What Happens If You Don’t Fix This

The most likely outcome is nothing. You’ll keep using shared logins, your team will keep working, and you’ll never face a discovery dispute that exposes the gap. That’s what most firms are betting on.

The second most likely outcome is a minor incident that costs you $10,000 to $20,000 in legal fees and makes you wish you’d fixed it earlier. A discovery request you can’t fully respond to, a client question you can’t answer cleanly, a vendor audit that flags your credential management as non-compliant.

The least likely outcome is a catastrophic breach or privilege waiver that costs you a client, a case, or your malpractice coverage. It’s rare, but it happens. And when it does, the cost is seven figures.

The math is simple. Fixing it costs $5,000 to $10,000 a year in additional software seats and maybe 40 hours of setup time. Not fixing it costs nothing until it costs everything. You’re betting that you’ll be lucky. Most firms are. Some aren’t.

We work with the firms that don’t want to bet. If that’s you, we’ll help you build the infrastructure in 90 days and move on. If it’s not, keep doing what you’re doing and hope the survey stat doesn’t apply to you.

For more on how AI agents fit into a law firm’s workflow, visit our insights section or explore Omni Voice and Omni Ops to see what individual agents can handle today.