Skip to content
Praval Technologies

Case study

The ethical wall was a policy everyone signed. And a permission no system enforced.

They asked us whether they were ready for Copilot, and to fix what wasn't. Readiness was never an AI question: the ethical walls lived in the handbook, not the file system, and documents had sprawled across drives for years. The estate wasn't just Copilot-unready; it was ungoverned.

Access remediated
Need-to-knowAccess remediatedOver-broad, org-wide permissions cut back to least privilege, and evidenced for audit
Governance posture
Audit-readyGovernance postureEvery matter classified and every access provable
Estate foundation
Copilot-readyEstate foundationA governed, permission-trimmed base, so AI adds capability, not risk

What they asked for

"Tell us if we're Copilot-ready, and re-architect the estate and governance so we are."

Not an AI-readiness problem, a governance-debt problem. The walls were written but never enforced, and the estate had sprawled unaudited for years. The risk existed with or without AI; AI just made it impossible to keep ignoring.

Enforced, not just written. The ethical wall moved from a signed policy into a control the system applies to every matter, not a rule left to trust.

The situation

A law firm came to us with what sounded like an AI question: are we ready to turn on Microsoft 365 Copilot, and if not, what do we fix? The readiness review answered a far bigger question than the one on the page.

The firm's document estate had accreted for two decades: matters upon matters spread across network drives, personal folders and a scatter of legacy SharePoint sites, with metadata that was inconsistent where it existed at all. And the confidentiality controls a law firm lives or dies by, the ethical walls that separate conflicting matters, existed as a policy in the staff handbook that everyone had signed, but not as a permission the file system actually enforced. The separation depended on people remembering the wall was there.

That was already a serious exposure: an audit finding waiting to happen, entirely independent of AI. Copilot did not create the risk. It simply meant the risk could no longer be deferred, because an AI that can instantly search everything a user can open makes latent over-exposure immediate and obvious.

What we found

Our diagnostic surfaced three compounding issues.

The estate had sprawled for years. Documents lived across network drives, personal folders and legacy SharePoint sites with inconsistent or missing metadata, so nothing could be classified or controlled at scale.

Ethical walls were policy, not permissions. The barriers between conflicting matters lived in the signed handbook, but the file system never enforced them, so the separation was procedural rather than technical.

Permissions had never been remediated. Access had accreted over many years, over-broad and unaudited, so who-could-see-what was genuinely unknown, and almost certainly far wider than anyone would have intended.

The scale of this kind of over-exposure is well documented. Cross-industry data-risk research finds that, on average, around 17% of an organization's sensitive files are accessible to every employee, and that a new joiner can typically reach roughly a fifth of the company's data on their first day. For a law firm, those are not efficiency statistics; they describe an ethical wall that is already porous, waiting to be found by an auditor, a regulator, or an AI that makes everything instantly searchable. (Source: Varonis, Data Risk Report.)

The firm is far from alone in fixing it the right way round. DLA Piper, one of the world's largest law firms, has said publicly that it first made its data governance solid, using information-barrier controls and Microsoft Purview, and that only then did that foundational work let it confidently roll Copilot out to the wider firm. Governance first, AI second. So that is exactly how we sequenced the work.

What we did

Re-architect the estate. We rebuilt the firm's documents on SharePoint with a consistent information architecture and metadata model, so every matter and every document has a known home, a clear owner and a sensitivity classification, instead of living wherever it happened to land over the past twenty years.

Enforce the walls in Purview. We expressed the firm's ethical walls and confidentiality rules as enforced Microsoft Purview policy (sensitivity labels and information barriers) so conflicting matters are separated by the system itself. The wall stopped depending on anyone remembering it was there.

Remediate and prove it. We cut the over-broad, org-wide access back to a need-to-know model and stood up the reporting to evidence it, so the firm can demonstrate (to an auditor, a regulator, or its own risk committee) exactly who can reach what, and can turn on Copilot knowing the answer is defensible.

How we rolled it out

We didn't boil the ocean. We governed one practice group first, proved the walls held and the access was clean and evidenced, then extended the information architecture and the Purview policy group by group, keeping risk, compliance and IT in the build, so the controls matched how the firm actually protects client confidence.

The shift

BeforeAfter
DocumentsSprawled across drivesStructured on SharePoint
Ethical wallsA signed policyAn enforced control
AccessOrg-wideNeed-to-know

Who could open a given confidential matter went from roughly one in five of the firm (in line with cross-industry oversharing benchmarks) to the matter team alone.

Outcomes

  • Ethical walls enforced: conflicting matters separated by Purview policy and information barriers, not by people remembering the wall is there.
  • Access remediated to need-to-know: over-broad, org-wide permissions cut back to least privilege, and the exposure evidenced for audit.
  • A Copilot-ready estate: a classified, governed, permission-trimmed foundation, so switching on AI adds capability, not risk.

The win wasn't getting ready for AI. It was closing a confidentiality risk the firm had carried for years, and the AI-readiness came free.

An illustrative engagement. The scenario and figures are representative, drawn from outcomes across comparable SharePoint and Microsoft Purview governance deployments, not the audited results of a single named client.