digital-documents--670-article1

Firm Management | August 7, 2026

What Should Not Become Part of the Client Archive

The mistake is assuming that every piece of information used to reach that outcome must follow the same path.

Shawn Bure

Accounting firms are right to preserve what matters. Final tax returns, signed authorizations, engagement records, client approvals, and documented decisions belong in governed systems with retention policies, access controls, and auditability.

The mistake is assuming that every piece of information used to reach that outcome must follow the same path.

A missing digit discussed by email, a temporary recovery code pasted into chat, a draft document attached to a ticket, and a screenshot sent to explain a portal problem can become permanent secondary archives. They may be copied into inboxes, mobile devices, backups, ticketing systems, and forwarded threads. Long after the task is complete, the firm still carries the exposure.

Data minimization is not record avoidance. It is the discipline of distinguishing the record the firm must keep from the temporary material used to create it.

Start with the firm’s obligations

For firms covered by the Federal Trade Commission’s Safeguards Rule, the information security program must include administrative, technical, and physical safeguards for customer information. The FTC also directs covered firms to inventory where customer information is collected, stored, and transmitted; assess applications; control access; oversee service providers; and securely dispose of information when there is no continuing business or legal need.

The IRS similarly tells tax professionals to maintain a Written Information Security Plan tailored to the size, scope, complexity, and sensitivity of the practice. That plan should govern the tools and workflows a firm approves. A new messaging product, deletion feature, or clever workaround does not replace the WISP, the firm’s retention schedule, professional obligations, discovery duties, supervision, or the judgment of legal and security advisers.

That is the starting point: preserve required records in approved systems. Then ask whether every transient input needs to become another retained copy.

Separate three kinds of exchange

Most client-information workflows can be clarified by placing the material into one of three categories:

  1. A durable record. A final return, signed authorization, filed document, approval, material advice, or completed decision may need to remain in the firm’s governed system of record.
  2. A one-way secret. A value that only needs to be revealed once may fit a firm-approved, purpose-built secret-delivery process. It should not automatically become an email or chat thread.
  3. A temporary conversation. A short clarification, recovery step, exception discussion, or live coordination exchange may require several messages without requiring a permanent transcript in every participant’s inbox.

The category should be chosen before the exchange begins. If staff make that decision in the moment, convenience usually wins and the most familiar tool becomes the archive.

Use four questions before choosing the channel

Firm leaders can add four questions to workflow reviews and WISP discussions:

  • What fact must remain? Preserve the authorization, decision, receipt, final document, or case outcome in the correct system.
  • What material is merely in transit? Identify drafts, troubleshooting details, temporary credentials, screenshots, and clarifications that have no continuing purpose after the task.
  • Who can end the exchange? Define expiration, revocation, destruction authority, and the process for preserving any required outcome before deletion occurs.
  • What cannot be erased? Document metadata, logs, backups, screenshots, downloads, endpoint artifacts, and participant copies that remain outside the channel’s control.

These questions are useful even when the approved answer is the client portal. A mature portal with multifactor authentication, controlled access, monitoring, and a defined retention policy is usually the correct place for tax documents and ongoing client work. The exercise simply prevents employees from creating unnecessary copies in parallel systems.

Make deletion claims testable

“Disappearing” is not a complete control description. A vendor or internal system should be able to explain what disappears, when it disappears, who can trigger deletion, which logs remain, what administrators can access, how backups behave, and whether recipients can export or capture the content.

Firms should also test the failure cases. What happens when a participant disconnects, forwards an invitation, loses a device, or leaves the exchange open? Does a deletion control remove only the server copy, or also local copies? Can the provider reconstruct the content? What metadata remains visible even when content is encrypted?

The answer will rarely be “nothing remains.” Honest scope is more valuable than an absolute promise.

Treat experimental tools as experiments

I built elm.chat, an open-source disposable-room prototype, to explore whether a server can relay an encrypted short conversation without retaining a transcript. The exercise exposed the limits as clearly as the design opportunity: recipients can still save content, endpoints can be compromised, ordinary relay metadata remains visible, and deletion cannot reach copies outside the system.

The project is early-stage, has not completed an independent security audit, and still has unfinished message-authentication and replay-protection work. It should not be used for tax documents, regulated client data, production financial workflows, or other high-risk information. Its useful role here is not as a recommendation, but as a reminder to interrogate every product’s deletion boundary and evidence.

Keep the record; reduce the residue

The practical goal is not to make client work disappear. It is to keep the evidence the firm is obligated to preserve while reducing sensitive residue that serves no continuing purpose.

Add temporary information to the firm’s data inventory. Map where it travels. Assign each exchange to an approved channel. Record the required outcome in the governed system. Set defensible retention and disposal rules. Train staff not to improvise with personal email, consumer messaging, or unapproved tools.

When firms separate the accountable record from the temporary conversation, they do not weaken governance. They make governance more precise.

==——==

Shawn Bure is an AI professional and technologist with decades of operating and software experience. He leads Workrr AI and Workrr One and has more than 25 years of experience building software, cloud platforms, communications systems, and operating companies. He created elm.chat as an open-source experiment in disposable encrypted communication. Learn more at https://elm.chat.

Sources for editorial review

  • Federal Trade Commission, “FTC Safeguards Rule: What Your Business Needs to Know”: https://www.ftc.gov/business-guidance/resources/ftc-safeguards-rule-what-your-business-needs-know
  • Internal Revenue Service, Publication 5708, “Creating a Written Information Security Plan (WISP) for your Tax & Accounting Practice”: https://www.irs.gov/pub/irs-pdf/p5708.pdf
  • CPA Practice Advisor contributor guidelines: https://www.cpapracticeadvisor.com/2020/05/13/contributor-guidelines/38321/

==——==

Sign in to get access to this free resource, and all of our whitepapers and reports.

Download this content today!

Register to get free access to this content, as well as newsletters, continuing education, podcasts, and more…

Leave a Reply