Every law firm that hires an outside marketing agency eventually hits the same standoff. The agency wants access to performance data to do its job well: which campaigns are producing leads, which keywords are converting, what the call volume looks like by source. The firm wants to give it to them. But “performance data” and “client data” usually live in the same systems, and handing over a login often means handing over more than intended.
Call recordings that include a caller describing their legal problem in detail. Lead names and contact information tied to sensitive matters, like a family law intake or a criminal defense inquiry. Case values and settlement figures that reveal privileged information about specific clients. None of that is what the agency actually needs to do good marketing work, but it’s frequently what they get, because most tools weren’t built with a “vendor” role in mind, only “user” and “admin.”
The Ethics Problem This Creates
Model Rule 1.6 and its state equivalents put the duty of confidentiality on the firm, not the vendor. If your SEO agency’s junior analyst can see a client’s name next to their intake notes because that’s just what the dashboard shows everyone, the firm carries that exposure regardless of whether anything ever goes wrong. Most managing partners understand this in the abstract. Far fewer have actually audited what their ad platform, call tracking tool, or CRM shows a vendor once given credentials.
The usual workaround is worse than the problem. Firms either give vendors full access and hope for the best, or they lock vendors out entirely and lose the benefit of outside expertise, forcing someone in-house to relay screenshots and summaries back and forth. Neither is a real solution. One creates risk. The other creates friction that slows down the exact optimization work you’re paying the vendor to do.
What Actually Solves It
The fix isn’t a policy memo. It’s a role that structurally can’t see what it shouldn’t. A vendor account should be able to see everything relevant to performance, spend by channel, cost per lead, conversion rates, campaign-level results, without ever rendering a client’s name, contact information, or the substance of what they said on an intake call.
Kenzsys builds this in as a standing role, not a manual export process. An agency invited under NDA gets a locked-down, view-only account that automatically redacts client identity across the platform: names are hidden, call transcripts are excluded, and depending on how the firm configures its access profile, even traditional media spend or specific financial detail can be scoped out. The agency sees the marketing story. They don’t see the client’s story. Nobody has to remember to scrub a spreadsheet before sending it, because there’s nothing to scrub.
What to Ask For, Even If You’re Not a Kenzsys Customer
If you’re evaluating any marketing platform and plan to give a vendor access, ask these questions before you sign anything:
- Is there a role between “admin” and “no access,” or only those two?
- Does that role hide client names, or just hide a “clients” tab while leaving names visible elsewhere, like inside a lead list or call log?
- Are call recordings and transcripts included by default, and can they be excluded specifically for non-employee roles?
- If you revoke the vendor relationship, is access to historical data removed immediately, or does the export they already downloaded live on their machine indefinitely?
Most platforms fail at least two of these. The answers usually reveal whether client-data exposure was actually designed for, or just something nobody thought about until a firm asked.
Outside expertise is valuable. Your SEO agency probably does know more about technical search optimization than anyone on staff. The point isn’t to keep vendors out. It’s to structure access so bringing them in doesn’t require trusting a spreadsheet-scrubbing process to catch every mistake, every time, forever.