Pull up your firm’s shared drive right now. Find the folder for a client your firm stopped working with two years ago. Check who has access.

Chances are, it’s more people than you’d expect - including at least one person who no longer works there.

The Problem: Permissions Accumulate. Nobody Cleans Them Up.

Permission sprawl doesn’t happen because anyone made a bad decision. It happens because firms make hundreds of small, reasonable ones.

A senior associate needs access to a client’s prior-year tax files for a project. You add them. The project ends. Nobody removes the access. A contractor comes on for busy season, gets broad folder access to meet a deadline, finishes the engagement, and moves on - but their permissions stay behind. A manager gets promoted, picks up new client portfolios, and retains everything they already had.

Do this for five or ten years, and you end up with a shared drive or SharePoint environment where most staff can access far more client data than their current role actually requires. Not because of malice. Just because cleanup never made the priority list.

Here’s what makes this particularly uncomfortable for CPA firms: the data sitting inside those folders isn’t generic business information. It’s Social Security numbers, tax returns, financial statements, and bank account details. It’s exactly the kind of data that draws regulatory scrutiny and, increasingly, client lawsuits when something goes wrong.

The average firm we work with is genuinely surprised during a permissions audit. They expect to find a few stray folders. They find a mess. Former employees with active access. Client folders shared with the wrong department. Root-level permissions that cascade through dozens of subfolders because someone granted them years ago as a shortcut.

The good news: this is fixable. It just takes a structured approach.

Why This Matters for CPA Firms Specifically

Most industries face some version of this problem, but CPA firms carry a specific burden. You’re handling sensitive financial data under a mix of professional and regulatory obligations that are getting stricter.

IRS Publication 4557 - Safeguarding Taxpayer Data - sets clear expectations that tax preparers must limit access to taxpayer information to only those employees who need it to do their job. That’s not a suggestion. It’s a documented expectation the IRS uses when evaluating whether a firm took reasonable precautions after a data breach.

Many state CPA licensing boards layer additional requirements on top of that. California’s own data privacy framework, the California Consumer Privacy Act (CCPA), applies to firms that meet certain thresholds and adds obligations around data minimization and access controls. If your firm handles financial data that falls under the Gramm-Leach-Bliley Act (GLBA) - either directly or as a service provider - those access requirements extend to your internal systems too.

The principle of least privilege - giving each employee access only to the data their role requires - isn’t just a security best practice. For your firm, it’s increasingly a compliance expectation with a paper trail attached.

And practically speaking: if a staff member’s credentials get compromised in a phishing attack, the blast radius of that breach depends entirely on what folders they could reach. Sprawling permissions turn a manageable incident into a reportable one.

How to Conduct a CPA Firm Shared Drive Permissions Audit

A permissions audit sounds daunting. It doesn’t have to be. Here’s a practical framework your firm can actually execute.

Step 1: Export and map current permissions

Before you change anything, get a full picture of what you’re dealing with. In SharePoint or OneDrive for Business, site admins can run permission reports at the site and library level. For Windows-based file servers, PowerShell scripts or third-party auditing utilities can export folder-level access control lists (ACLs) into a readable format.

Document this. You need a before-state. Firms that skip this step and start deleting permissions tend to break workflows and can’t easily roll back.

Step 2: Cross-reference against active staff

Compare your permission list against your current employee roster and active contractor list. Any account belonging to someone who’s left the firm is a priority removal - full stop. Don’t wait for the rest of the audit to finish.

This step alone usually surfaces the most alarming findings.

Step 3: Map permissions to roles, not individuals

The goal isn’t to evaluate each person one by one - that doesn’t scale. Instead, define what access each role in your firm should have. Tax staff need access to tax client folders. Audit staff need access to audit client folders. Admins may need different access than associates.

Once you have role-based expectations documented, anything that deviates from the model is a candidate for removal.

Step 4: Right-size inheritance

Many sprawl problems stem from overly permissive top-level folder settings that cascade down. Review your root folder and department folder permissions carefully. It’s often easier to lock down the top of the tree than to fix hundreds of subfolders individually.

Step 5: Test before you finalize

Before you publish any permission changes broadly, test them. Have a staff member in each affected role verify they can still access what they need. Missing a legitimate dependency is how cleanup projects turn into urgent IT tickets on a Monday morning.

Step 6: Document the new state

Create a permission map that reflects your intended access model. This becomes the reference point for your ongoing process.

What to Look for in an IT Partner

Cleaning up permissions once is valuable. Keeping them clean requires process and tooling - and that’s where the right managed IT services provider (MSP) makes a real difference.

Ask any IT partner you’re evaluating these questions:

  • Do you have experience with CPA firms specifically? Firms in professional services have different compliance drivers than a retail or manufacturing company. Your IT partner should know what IRS 4557 means without you explaining it.
  • Can you automate access reviews tied to our HR process? Offboarding should trigger access removal automatically - not as a separate ticket someone has to remember to file.
  • Do you have tooling to monitor for permission drift? Sprawl will rebuild if there’s no ongoing visibility. Look for partners who can alert you when permissions expand outside your defined model.
  • Can you provide a documented audit trail? For regulatory purposes, you need to demonstrate that access controls exist and are reviewed. That requires logs, not just manual memory.

A good IT partner won’t just fix today’s mess. They’ll help you build the governance that prevents tomorrow’s.

The Bottom Line

Years of permission sprawl aren’t a sign that your firm is careless - they’re a sign that your firm has been busy. But the risk that comes with uncontrolled access to client financial data is real, and regulators are paying attention. A structured audit, executed carefully, can close the gap. Pair it with a governance process tied to onboarding and offboarding, and you turn a one-time cleanup into a lasting control.


Frequently Asked Questions

How do I find out who has access to folders in our CPA firm’s SharePoint?

SharePoint site owners and administrators can view and export permissions through the SharePoint admin center or via Microsoft 365’s compliance tools. For a full audit across multiple sites and libraries, many firms use PowerShell scripts or third-party tools like Varonis or ShareGate, which can generate detailed reports mapping every user to every folder they can access. This is the fastest way to see the full scope of what you’re dealing with.

What does IRS Publication 4557 require about data access controls?

IRS Publication 4557 instructs tax professionals to implement safeguards that limit access to taxpayer data to employees who need it to perform their job functions. It specifically recommends access controls, user permissions, and activity logs as part of a written information security plan (WISP). The IRS uses this publication as a benchmark when evaluating whether a firm acted responsibly after a data incident.

How often should a CPA firm review shared drive permissions?

Most security frameworks recommend a formal access review at least annually, but best practice for professional services firms is to tie reviews to specific events - staff onboarding, staff offboarding, role changes, and the end of client engagements. Annual reviews catch drift, but event-driven reviews prevent it from building up in the first place. If your firm has experienced significant growth or turnover, a one-time catch-up audit before establishing that ongoing cadence is a smart starting point.

What’s the biggest mistake firms make when cleaning up folder permissions?

The most common mistake is removing permissions without first documenting the current state or testing the changes. Firms delete access, break a workflow someone depends on, and then scramble to figure out what the original setup was - with no record to reference. Always export and save your before-state, always test changes in a limited scope before rolling them out broadly, and always communicate with staff that a cleanup is underway so they can flag issues early.


If you’re working through a shared drive permissions audit at your firm, let’s talk. One82 works exclusively with CPA firms, law firms, and financial advisory companies in the Bay Area - we know your world.