Guides · For consultants
Letting an AI agent work on one client's files and nothing else
You can use AI on confidential client work when two things are true: the client’s contract allows it, and the agent can see one client’s files and nothing else. Check the contract first, then set the scope, so you stay inside the NDA and one client’s details never end up in another client’s work.
Below: the do-it-yourself setup and its limits, what to keep out, and a checklist. None of it is legal advice.
Why scope matters more than the model
Pointing an AI at client work brings three risks, and scope handles each one:
- Confidentiality. NDAs and engagement letters limit where client information can go, and some now name AI tools directly. The AI provider that processes the files is one more place the information goes.
- Mixing clients. An agent that can read two clients’ files can blend them: one client’s numbers in another’s deck. Even without a leak, it answers from the wrong context.
- Damage. An agent that can write across your drive can rename, move or overwrite the wrong files. With one client in scope, a mistake stays inside that client.
The question isn’t whether the AI is smart enough. It’s what it can see.
The do-it-yourself setup: one folder per client
-
Give each client its own folder, holding only that client’s files: the engagement note, call notes, data extracts, drafts. Keep your frameworks and templates elsewhere, and copy in what the engagement needs.
-
Open the agent inside that folder, not at the top of your drive. Agents such as Claude Code, Codex and Cursor treat that folder as their workspace. It’s a default, not a wall: many can still read outside it, so check your tool’s permission settings.
-
Put a rules file in the folder, for example:
# Client: Lone Sock Supply Co. This folder holds one client's work. It is confidential. # Rules for any AI working here - Work only with the files in this folder. - Never quote this client's data anywhere else. - Don't search the web with client names, numbers or plans. - Draft only. I review and send.Rules like these are instructions, not enforcement: the agent usually follows them, and a long session or a new model can break them (more on rules files).
-
Start a fresh session when you switch clients. What an agent read for one client stays in that session until it ends.
-
In chat apps, give each client its own project and upload only that client’s files. Never two clients in one project, and check that the app’s memory can’t carry details from one project into another.
What to keep out entirely
Some things don’t belong in any agent’s reach, whatever the scope:
- Credentials. Passwords, API keys and client portal logins belong in a password manager, never in the folder.
- Personal data you don’t need. Customer lists, staff records, payroll, health data. Ask the client for an export with names removed, or work from totals.
- What the contract excludes. Anything the agreement puts off-limits, unless the client has said yes in writing.
- Other clients, and your own life. Another client’s files, your journal, your money. The agent working for one client has no reason to see them.
A checklist before you point an agent at client files
- You’ve read what the contract, NDA or engagement letter says about AI tools, and it allows this use.
- You know which AI provider processes the files, and what its terms say about retention and training.
- The agent can reach one client’s files, and only that client’s.
- Nothing in scope belongs to another client, including old templates with their names in them.
- Credentials and raw personal data are out of the folder.
- The agent drafts. You review, and you send.
- Changes can be undone: the folder is backed up or under version control.
- The session is fresh.
Where Oknola fits
In Oknola, scope isn’t a rule the agent is asked to follow. It’s set per agent, per tag. Tags are the permission model, not folders: each client carries its own tag, and an agent allowed one client reads that client’s files and nothing else, whatever folder they sit in. Run one agent per client if you like.
Agent off, your files never leave your device. Agent on, you chose the scope. Oknola types, tags and files what lands in the folder, and nothing is sent without your yes. Check what each engagement letter permits. More in scoping an agent with tags, and what is available today is on the roadmap.
Questions people ask
Is it safe to paste client data into ChatGPT or Claude?
Only if the contract allows it and you’ve checked your plan’s data settings. A useful test: treat the AI provider like a subcontractor. If the contract wouldn’t let you share the file with one, don’t paste it.
Does a rule in CLAUDE.md or AGENTS.md keep an agent in one folder?
No. It’s an instruction the agent usually follows, not a permission. The boundary comes from where you open the agent, the tool’s own permission settings, or a system that only hands the agent certain files.
Should I tell clients I use AI?
If the contract is silent, asking is cheaper than explaining later. A short written yes that names the tool and what it will see settles it before the work starts. For what your contract requires, ask a lawyer.
What if a client’s contract rules out AI tools?
Then no AI touches that client’s files, unless the contract allows a model that runs on your own machine. You can still use AI on your own side of the work: your templates, your scheduling, your writing, with no client data in it.