Skip to main content

Protect what the firm and its clients depend on.

Protection of client and family information, institutional continuity and hard-earned client trust depend on deliberate operating decisions.

Joans makes responsibilities and control mechanisms explicit so leaders have clarity and confidence when they approve technology change.

Sensitivity determines the handling standard.

Identify the authoritative source, sensitivity, permitted purpose, users, retention need and disposal path before information is copied or exposed to another capability. Use the smallest set of information required for the stated purpose.

Seven-class information-sensitivity modelIllustrative decision model

As sensitivity increases, control, review and evidence increase.

  1. A Public

    Approved for public distribution.

  2. B Operational

    Routine firm operations without confidential content.

  3. C Internal confidential

    Restricted internal business information.

  4. D Client-identifying

    Information that identifies a client, family or related party.

  5. E Client financial

    Financial positions, plans, transactions and reporting.

  6. F Client sensitive personal

    Highly sensitive personal and family information.

  7. G Privileged / regulatory

    Privileged, examination, investigation or regulatory material.

A service, system, workflow or change inherits the highest information class it can touch.

The classification follows information through systems and files, provider access, integrations, automation and AI-assisted capabilities.

The model orders seven information classes from public material to privileged or regulatory material. Each step upward requires stronger control, review and evidence. A service, system, workflow or change takes the highest class of any information it can touch.

Control areas and implementation questionsThe depth of work changes with the system, information and risk. These areas keep the decision and its operating evidence connected.

Identity and access

Establish the authoritative identity source, role and privilege model, approval path, service-account ownership, and joiner, mover and leaver controls. Access should reflect current responsibility and be reviewable without reconstructing it from individual systems.

Data classification and minimization

Identify the authoritative source, sensitivity, permitted purpose, users, retention need and disposal path before information is copied or exposed to another capability. Use the smallest set of information required for the stated purpose.

Environment and provider boundaries

Record where data is processed, how development and production are separated, which providers can gain access, and where each operating responsibility begins and ends. Contracted controls and technical configuration need to describe the same boundary.

Logging and auditability

Preserve a reviewable record appropriate to the decision: access and configuration changes, releases, approvals, material automated actions, exceptions and security-relevant events. Logs require an owner, a retention policy and a practical review path.

Testing and rollback

Define acceptance, security and recovery tests before release. Record who can approve production use, what would stop the release, how a prior state can be restored, and how restoration has been verified.

Incident readiness and continuity

Name the incident authority, escalation route, provider contacts, recovery priorities and manual fallback for essential operations. Continuity depends on current records and rehearsed decisions as much as technology.

Human authority for AI-assisted capabilities

Specify approved information sources, permitted actions, review requirements, exception handling and the record to retain. AI assistance remains inside the institution’s authority model; qualified people approve professional judgments and consequential action.

Controls follow the information, authority and service model.

A control becomes useful when it is connected to the people, systems, information and providers that operate it. The boundary map makes those dependencies visible before production use.

Trust boundaries for protected firm informationIllustrative trust-boundary view

Institution-controlled boundary

Firm authority, records and access decisions remain inside this boundary.

Authoritative firm systems

  • CRM and client-service records
  • Portfolio and reporting systems
  • Documents and Microsoft 365

Identity and access gate

  • Named identities and approved service accounts
  • Least-necessary and revocable access
  • Separately approved privileged access

Authoritative firm record-return target

Accepted results return to the correct firm record; working material follows its agreed retention or removal path.

Integration trust boundary

Approved provider boundary

Provider access boundary

Provider access reaches this boundary only after the same institution identity and access gate.

Approved provider interface

  • Approved service identity and interface
  • Permitted purpose and information class
  • Input, output and exception validation

Controlled capability

Agreed firm or provider environment

Operation stays inside the documented purpose, configuration, change and support boundary.

Accountable approval and record-return path

  1. Path 01

    Firm systems

    Authorized information begins in the institution record.

  2. Path 02

    Identity and access gate

    A named person or service receives least-necessary access.

  3. Path 03

    Approved provider interface

    Only the permitted purpose and information class cross.

  4. Path 04

    Controlled capability

    Configuration, validation and support stay inside scope.

  5. Path 05

    Accountable approval

    Accountable human approval accepts consequential use or release.

  6. Return to 01

    Authoritative firm record

    The approved result returns; working material follows its retention path.

  • Audit and retention apply across the round trip.
  • Release, rollback and recovery precede production use.

Authoritative firm systems, the identity and access gate, and the record-return target remain inside the institution-controlled boundary. An approved provider interface and controlled capability remain inside the approved provider boundary. The approved path crosses from firm systems through identity and access, the provider interface and capability, then accountable approval returns the accepted result to the authoritative firm record.

Engagement information standardsHow Joans handles engagement information and keeps operating responsibility named.

Scope without sensitive material

A high-level description is enough to establish the matter. Client names, account information, credentials, investment documents and other sensitive material do not belong in the public contact path.

Handling agreed before access

Before engagement work requires access, the institution and Joans agree which systems and information are needed, the permitted purpose, where work may occur, who may receive it and which retention requirements apply.

Named, revocable access

Access is assigned to named people or service identities, limited to what the work requires and removed when it is no longer needed. Shared credentials are not an acceptable access model.

Firm records remain authoritative

The institution and its providers retain the authoritative systems and records. Engagement working material does not quietly become a replacement system of record.

AI use requires explicit approval

Client or family material is not sent to an AI or model provider unless the institution has documented the permitted purpose, information, provider, controls, human review, retention and approval.

Closeout is part of the scope

Return, removal or agreed retention of engagement material is established at close, together with access removal, the records the institution keeps and any unresolved exception.

The institution
Policy, risk acceptance, information authority, user approval, business decisions and professional judgment.
Joans
Technology strategy, architecture, implementation design, provider coordination, test results and transition into operation within the agreed engagement.
Specialist providers
The platforms, infrastructure and managed services they are contracted to operate, including their service and security commitments.

Joans works on technology, operations, and implementation. Investment, legal, tax, compliance, and other professional judgments remain with the client and its appointed professionals.

Specialist providers remain responsible for the managed infrastructure and security services they are contracted to operate.

A useful decision can be inspected, tested and revisited.

Joans records the operating context, authority, information sources, controls, provider responsibilities, test results and rollback conditions that support a technology decision.