What is Ethical Wall?

Governance & Control
Definition

The boundary that keeps one client's information out of another's work. Professions name it differently, matter wall in law and information barrier in accounting and advisory firms. In an AI system it has to filter access before retrieval, because an instruction in a prompt cannot enforce confidentiality.

Why It Matters

Confidentiality in a professional firm is an access problem before it is a conduct problem. A wall exists so that the people working an engagement see what that engagement requires, and nothing else. When a firm puts its document estate into a shared index and points an agent at it, the wall has to be rebuilt in a place the agent cannot argue with.

The failure mode is quiet. Nothing looks wrong: the answers are fluent, the sources are real, and one of them belongs to a different client. Nobody notices until an answer cites a document that should never have been retrievable.

How It Works

The filter runs before retrieval, at the query, so the model never receives a document the requesting user is not entitled to see. That is the difference between confidentiality as a property of the system and confidentiality as an instruction the model is asked to respect.

Three inputs decide the filter: the engagement, the user’s role on it, and the purpose of the request. A per-instance workload identity carries those into the retrieval call so the boundary travels with the request, and scoped credentials keep it bounded by environment and lifetime. What the run touched then belongs in the decision record, which turns “the agent was scoped” into evidence a firm can produce.

Where It Breaks

Post-hoc filtering is the common half-measure. Redacting the output after generation means the model already reasoned over the material, and the trace recorded it. The bound has to sit upstream of the model to be a control.

The second break is the shared index. A single vector store holding every engagement’s documents pools the firm’s information, and similarity search does not know about client boundaries. Per-engagement separation, or a filter enforced at query time, is what keeps the pool from becoming a leak.

The third is the service account. Integrations are usually built with one credential that can read broadly, because that is the fastest path to a working pilot, and the agent inherits it. The wall then exists in the diagram rather than in the system.

The fourth is conflict screening. A wall that keeps engagements separate also has to let the firm answer whether two of them are related, which is a different query with a different access rule. Treating the two as one problem produces either a leak or an unusable screening tool.

How Flytebit Handles It

Access is filtered by engagement, role, and purpose at retrieval rather than at output, and the run records the documents it touched. Screening runs as a separate, deliberately scoped path so that answering a conflict question does not require opening the wall. The industry application is on our Professional Services page, and the control design is our AI governance and risk work.

More info

On flytebit.com

Reviewed by Jayaveer Bhupalam, Founder & CTO Last updated September 28, 2026