Consulting and recruiting
Separating firm-owned knowledge from client-confidential material
By SourceX Editorial · Updated
Short answer
A client confidential carve-out separates what a consulting firm owns and may reuse from material its clients own or control. Sort every record into three buckets: firm-owned, client-owned and mixed. Firm-owned records can be reused or licensed, client-owned records stay out, and mixed records need preparation that removes client identity and confidential details first.
Key takeaways
- Ownership and confidentiality are separate tests; a firm-owned record can still carry a client's secrets.
- Most valuable consulting records sit in the mixed bucket, so preparation rules matter more than labels.
- Removing the client's name is rarely enough; figures, locations and quirks can identify a client.
- Record each sorting decision with the contract clause it relies on and the person who approved it.
- Sort by record type first, then check exceptions engagement by engagement.
What is a client confidential carve-out?#
A client confidential carve-out is the set of rules, and often the contract language, that keeps material a client owns or controls apart from knowledge the firm owns. Without one, a firm cannot safely reuse its own methods, train internal AI tools or license records, because nobody knows which files carry client obligations.
The carve-out has two halves. Ownership asks who holds rights in the material under the MSA and SOW. Confidentiality asks whether the material reveals information the client is entitled to protect, regardless of who owns the document. A record must pass both tests before it leaves the engagement folder.
The three buckets#
The three-bucket framework sorts every consulting record into firm-owned, client-owned or mixed. The buckets describe default treatment, not final decisions; contract terms can move a record from one bucket to another.
Expect the mixed bucket to be the largest. That is not a problem, because most of the firm's practical knowledge lives in mixed records and can be recovered through preparation.
| Bucket | Definition | Typical examples | Default treatment |
|---|---|---|---|
| Firm-owned | Created by the firm for its own operations, with no client content | Blank templates, training materials, internal methods, pricing models | Reuse and license after a light review |
| Client-owned | Assigned to the client or built from the client's data | Final deliverables under assignment, client data sets, client-provided documents | Exclude from reuse outside that client |
| Mixed | Firm-authored but containing client facts, names or figures | Project reviews, proposals, staffing plans, issue logs, worked examples in playbooks | Prepare before reuse: remove identity and confidential details, or exclude |
Sorting rules for common consulting records#
Sorting rules work best by record type, because the same kinds of records recur in every engagement. Apply the usual bucket first, then look for the condition that moves a record elsewhere.
Keep the rules short enough that an engagement manager can apply them without calling counsel for every folder. Escalate only the exceptions.
| Record type | Usual bucket | Rule that moves it |
|---|---|---|
| Proposals and SOWs | Mixed | Client-owned if the client co-wrote it or it quotes client confidential data at length |
| Playbooks and methods | Firm-owned | Mixed if worked examples use a real client's facts |
| Timesheets and time narratives | Mixed | Firm-owned once narratives are stripped of client names and matter details |
| Internal project reviews | Mixed | Client-owned if the MSA defines work product to include internal reviews |
| Staffing and resource plans | Firm-owned | Mixed if they name client staff or reveal the client's project plans |
| Final deliverables | Client-owned | Firm-owned elements only where a background IP or license-back clause applies |
| Interview notes | Mixed | Excluded if interviewees were promised confidentiality or are outside the firm and client |
How to prepare records in the mixed bucket#
Records in the mixed bucket become usable when preparation removes whatever ties them to a client while keeping the firm's reasoning intact. The aim is a record that still shows how the work was scoped, staffed and resolved, but not whose work it was.
Removing the client name is rarely enough. A combination of industry, region, revenue band and an unusual problem can identify a client to anyone in that sector, so preparation also generalizes figures, locations and distinctive details.
- Replace client, person and product names with consistent placeholders.
- Generalize figures to ranges or ratios, and remove absolute amounts.
- Broaden locations and dates to a level that no longer points to one client.
- Remove quoted client documents, data extracts and screenshots.
- Keep the firm's analysis, decisions, issues and outcomes in the record.
- Have someone who knows the client read the result and confirm it is not recognizable.
Who decides, and how to record the decision#
Sorting decisions belong to a small group: the engagement partner who knows the client, the general counsel or outside counsel who reads the contract, and the knowledge management lead who applies the rules consistently. One person cannot see all three angles.
Write each decision down with the record family, the bucket, the contract clause relied on, the preparation applied and the approver. Industry provenance standards treat confidentiality as a recorded attribute: the Data and Trust Alliance's Data Provenance Standards include a confidentiality classification element alongside license to use and intended data use, so a decision log in this shape follows a published provenance vocabulary rather than an improvised one.
Mistakes that undo a carve-out#
Carve-outs usually fail through shortcuts rather than bad rules. The most common is sorting by folder name: an engagement folder labeled internal can still hold a client's data extract, and a folder named after a client can hold the firm's blank templates.
A second mistake is treating email and chat as out of scope. Proposal threads, Teams channels and Slack workspaces often carry the richest reasoning about how an engagement was scoped, and also the most client detail. Decide on them explicitly instead of letting them drift into an index.
The third is sorting once and never again. New engagements keep adding mixed records, so the rules need an owner and a point in the engagement closeout checklist where records are tagged before the team disperses.
Illustrative: an operations consultancy sorts its SharePoint#
Illustrative: a fictional operations consultancy keeps engagement folders in SharePoint, proposals in its CRM and time and staffing data in Deltek. The managing partner wants an internal AI assistant that answers questions from past work without exposing clients.
The firm sorts by record type rather than by folder. Blank templates and training decks go straight to firm-owned, and final deliverables are excluded. Project reviews, proposals and staffing plans are prepared: names replaced, figures turned into ratios, locations broadened. Two clients whose MSAs define work product broadly are excluded entirely.
Only firm-owned and prepared records are indexed for the assistant. The same decision log later answers a buyer's questions when the firm considers licensing a package of prepared project reviews.
How SourceX applies the buckets#
SourceX applies the same logic during the Rights and Preparation steps of the SourceX five-step transaction: Supply, Rights, Preparation, Approval and Delivery. Client-owned material is excluded by default, mixed records are prepared to remove personal and confidential details, and the firm approves the result before anything moves.
The SourceX Evidence Packet carries the decision log forward as provenance, licensing rights, permitted use, the privacy record and release authorization. Each included record family can then be traced to the clause and approval behind it.
Frequently asked questions
Is replacing the client name enough to make a record safe?
Rarely. Clients can be identified from industry, region, size, an unusual problem or a distinctive figure. Preparation should generalize these details too, and someone familiar with the client should read the prepared record to confirm it no longer points to them.
Do timesheets count as client-confidential material?
The hours themselves usually do not, but time narratives often do, because they describe what was done for whom and sometimes why. Strip client names, matter descriptions and sensitive phrases from narratives before treating timesheets as firm-owned operational records. Rate and billing details for a specific client can also be confidential.
What if the client contract has no confidentiality clause?
Confidentiality duties can still arise from NDAs signed at the proposal stage, from professional obligations or from how information was shared. Treat silence as a reason to check further, not as permission. Many firms apply their standard confidentiality rules to every client regardless of contract wording.
Should we tell clients that we keep and reuse firm knowledge?
Most firms already say so in their MSAs through background IP and license-back clauses. Making this explicit in new agreements, and explaining how prepared records are used, reduces surprises. Clients generally accept reuse of methods; what they want protected is their own information.
Do we have to sort every historical folder?
No. Start with the record families you actually plan to use, such as project reviews from a particular practice or a run of recent years. Sorting by record type lets you cover large volumes quickly, and folders you never plan to use can stay untouched.
Sources
- The Use group of the Data & Trust Alliance Data Provenance Standards includes elements for confidentiality classification, consent documentation location, privacy-enhancing technologies applied, allowed and excluded processing and storage geographies, license to use, intended data use, and copyright, patent and trademark status. Source
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.