JJC SystemsBook a Consultation
SharePoint · Legal

Knowledge management and the ethical wall

Most firms have a conflicts policy and a matter site structure. Very few have tested whether the wall exists anywhere other than in the site.

PublishedJune 14, 2026
Length15 pages · 16 min read
SectorLegal
PlatformSharePoint
Service areaModern Work & Automation
Abstract

Knowledge management and the ethical wall

Summary

A firm creates a site per matter, restricts membership, and considers the ethical wall built. The problem is everything around the site: the email thread in personal mailboxes, the document saved to a partner's own storage, and the search result that returns a title and a snippet to somebody who cannot open the file.

This paper argues that an ethical wall built only at the site level is not a wall, sets out the four layers that must agree for it to be one, and proposes a test firms can run themselves before their risk partner has to.

Key findings

Four things this paper argues

If you read nothing else, read these. The analysis that follows sets out the evidence for each.

01

A site-level wall leaks through search, email and personal storage

None of these are configuration errors in isolation. Together they mean the wall exists in the site and nowhere else.

02

The search snippet is the most common and least expected leak

It reveals the existence and subject of a matter without revealing the file, which is a confidentiality event in its own right.

03

Barriers built on Department reorganise when the firm does

A dedicated directory attribute changes only when somebody deliberately changes it. Department changes for reasons unconnected to conflicts.

04

AI content discovery raises the stakes without changing the remediation

The work required is identical whether or not you deploy an assistant. What changes is how quickly the gap is found and by whom.

Analysis

The argument in full

The four layers

A defensible ethical wall in Microsoft 365 is not one control. It is four, and they have to be designed together rather than added in sequence.

Information barriers provide policy-level segmentation preventing communication and collaboration between defined groups, enforced across Teams, SharePoint and OneDrive. Access design drives matter site membership from the practice management system rather than maintaining it by hand. Sensitivity labels apply protection that travels with the document when it leaves the site. Retention aligns to matter lifecycle rather than to a calendar date, so closed matters actually close.

Firms that implement one of these and consider the wall built are the norm rather than the exception.

  • Information barriers segmenting communication and collaboration by defined group
  • Matter site membership driven from the practice management system, not maintained by hand
  • Sensitivity labels applying protection that persists outside the tenant
  • Retention triggered by matter closure rather than by a calendar date
  • A maintained directory attribute that survives organizational change

Why firms are structurally exposed

Three characteristics compound. Partnerships resist mandated process, so configuration that fights how partners work is worked around. Matter teams form and dissolve continuously, so membership drifts faster than in a corporate structure. And the content is unusually sensitive, so the consequence of a leak is professional rather than merely commercial.

Microsoft is investing heavily in making content discoverable and answerable by agents — automated metadata, stale content detection, assistants that reason over libraries. For a firm with a properly built wall this is straightforwardly useful. For a firm whose wall exists only at the site level, it is a considerably faster way to discover the gap.

The remediation work is the same either way. The question is only whether the firm does it deliberately or after an incident.

The test

The single most useful hour in this work is a deliberate attempt to breach your own wall.

Take an account on the wrong side of a barrier and try, methodically, to reach the material: search, direct URL, a link forwarded by a colleague, a document opened on a personal device, an export to a spreadsheet. Write down what worked.

In our experience the search result snippet surprises risk partners most often. It is not a permissions failure in the conventional sense — the file cannot be opened — and it still discloses that the firm is acting on a matter and what the matter concerns.

Framework

Something you can apply without us

Every paper in this series ends with a framework you can run internally. We would rather you used it and reached your own conclusion than took ours on trust.

Framework

The four-layer wall

Five stages including the test. Firms that stop after stage two have a site, not a wall.

1

Attribute

A dedicated directory attribute populated for 100% of users. Unpopulated users sit outside every policy.

2

Segment

Barriers defined and membership signed off by the risk partner before enforcement.

3

Protect

Sensitivity labels so protection travels with the document beyond the site.

4

Retain

Retention triggered by matter closure, so closed matters leave the discoverable estate.

5

Breach

Attempt to defeat your own wall, in writing, before anybody else does.

Implications

What this means, depending on your seat

The same argument lands differently across an executive team. These are the three versions worth separating.

For the risk partner

For the managing partner

For the IT director

References

Where to check this for yourself

Microsoft's own documentation for the product behaviour described above. We would rather you verified the basis than accepted our summary of it.

01
Information barriers in Microsoft Purview
02
Information barriers and SharePoint
03
Sensitivity labels in Microsoft Purview
04
Retention labels and event-based retention
05
SharePoint Advanced Management

On these references: each entry names a Microsoft Learn article or documentation area by title, because deep links change while titles are stable. Searching the title on learn.microsoft.com will reach the current version. Where we have cited a figure or a product behaviour, it is Microsoft's statement rather than ours; where we have given a number of our own it is labelled as such in the text.

Recognise the situation?

We will run a scoped information barrier review against one practice group, including the deliberate breach test, and give you the findings in writing whether or not you take the remediation further with us.

Discuss this paper Run the related checklist We reply to every message within one business day.
Keep reading

Related papers

Get In Touch

Tell us what you're trying to fix

Describe the situation in your own words.

Please enter your first name.
Please enter your last name.
Please enter a valid email address.
Please enter your company name.
Please choose an option.
Please add a short description.

We reply to every message within one business day.