Controls
Every firm has an answer to who can see a given household. The question is whether the answer is a record or an assurance.
An examiner asks whether a particular advisor could have accessed a particular household during a particular window. Or an advisor leaves for a competitor and the firm needs to establish what they could see on their last day. Or a client asks, plainly, who at your firm can look at this.
Every firm has an answer to this. The question is whether the answer is a record or an assurance.
A great deal of software in this category enforces access on the screen. The menu item does not appear. The row is filtered out of the table. The button is greyed. To the person using it, the restriction is complete and obvious.
Underneath, the request that populated that screen may have asked for everything and been trimmed on arrival. The data left the server. It was removed from view.
This is not usually anyone's decision. It is what happens when a product grows feature by feature over a decade: access control gets added to each new screen as the screen is built, by whoever built it, and after enough screens there is no single place where the rule lives — there are ninety places, and they are ninety chances to have implemented it slightly differently.
It does not matter on the day everything works. It matters at the edges, and the edges are ordinary:
Each of those is a normal Tuesday, not a breach scenario. And each one is where a rule enforced ninety separate times finds the one place it was not.
Scope belongs to the request, not the screen.
Every read carries the identity of whoever asked, and the restriction is applied where the data is assembled rather than where it is displayed. A request that is not entitled to a household does not get a filtered answer. It never had those rows to filter.
The practical consequence is that there is no unscoped path to find. Removing the screen does not remove the control, because the screen was never the control. Reports, exports and the interfaces other systems use all inherit the same restriction, because they all go through the same door.
The other half of doing this properly is that it has to be usable, or the firm will route around it.
An advisor's access is the union of what they hold directly and what their firm membership grants them. Move offices, pick up a book, get added to a team, and the access follows from those facts rather than from somebody remembering to update a list. Firm administrators see down their own tree and not sideways into anyone else's.
Nobody maintains a spreadsheet of exceptions, because the spreadsheet of exceptions is how these systems actually fail. It is never wrong on the day it is written.
Every real platform has a level of access that spans the firm, because support, operations and reconciliation cannot function without it. Any vendor claiming otherwise is describing a product that could not be operated.
The honest version is not to pretend it does not exist. It is to make it a named, narrow, logged capability rather than an ambient property of being an employee — and to be able to produce the log.
Ask where scoping happens. Not whether roles exist — roles always exist. Where the restriction is applied.
If the answer describes a screen, a menu, or a permission toggle in an administration panel, ask the follow-up: what happens when the same request is made without the screen? Through an export, a scheduled report, or the interface a connected system uses?
A good answer is short and structural. A long answer, in this particular area, is itself the finding.
We are not going to publish how entitlements are represented, resolved or enforced, and we would be suspicious of any vendor that did.
What is worth saying in public is the standard, because it is the standard you should apply to us as readily as to anyone else: the control lives with the data, it is provable after the fact, and the firm-wide view is a door with a log on it rather than a hallway everyone walks through.
Questions this did not answer? Ask them directly — that is what the twenty minutes is for.
Book 20 minutes with Kyle