Gatepost Review Stephen@GatepostReview.com

Know exactly what your AI tools can reach.

We list every AI tool connected to your firm's email, files and client systems, record what each one is allowed to do, and tell you which permissions to cut.

For accounting, tax and law firms in New York. Fixed scope, five working days, one written report.

Email Stephen
Stephen@GatepostReview.com

Now booking first reviews for early 2027.

Example findings for a fictional 12-person tax practice
Email drafting assistant
Partner's mailbox. Can send and delete, no review.
Drafts onlyHigh
Former contractor's access key
Practice software, full access. No owner since spring.
RemoveHigh
Tax research assistant
Every client folder, read and write. Needs read only.
Read onlyMedium
Document intake bot
Client portal uploads, read only. Named owner, logged.
AllowedFine

Every finding points to a setting we saw, with the change that fixes it.

Why firms ask for this now

Staff connect AI assistants to mailboxes, client folders and practice software in minutes. Few firms keep a list of what was connected, or what each tool is allowed to do.

Tax preparers

The FTC Safeguards Rule requires a written security program with access reviews and oversight of outside service providers. An AI tool with access to client data is one of those providers.

Any firm holding New Yorkers' data

New York's SHIELD Act requires reasonable safeguards, including assessing risks and vetting the service providers that handle private information.

Law firms

Client confidentiality extends to every tool that can read a matter file. A review shows which tools can, and whether a person approves what they send.

A review gives you evidence for your security program. It is not legal advice and does not certify that your firm is compliant with any law.

How the review runs

Five steps over about five working days. You see the scope in writing before anything starts.

  1. Agree the scope

    Day 1

    Which tools and accounts are in, and what the review will and won't cover, signed before we look at anything.

  2. Build the inventory

    Days 1 to 2

    Every AI tool and automation, including the ones staff added themselves, with who set it up and who owns it now.

  3. Map the access

    Days 2 to 3

    For each tool, every connection and permission: read or write, whose login it uses, and when its key last changed.

  4. Compare against the job

    Days 3 to 4

    Any access a tool's job doesn't need becomes a finding. So does a risky action with no person approving it, or no log.

  5. Rate and report

    Days 4 to 5

    Each finding rated High, Medium or Low with a one-line fix, then walked through with you on a call.

What you receive, and where the line is

You receive

  • An inventory of every AI tool in scope and what it can reach
  • Findings ranked by risk, each with the setting we saw and the fix
  • A list of anything we could not review, and why
  • A walkthrough call of up to an hour
  • A fixed fee, agreed in writing before we start

We never

  • Ask for your passwords. We use read-only access or a screen share.
  • Change, switch off or delete a setting. You decide every fix.
  • Copy keys, passwords or client records
  • Call the review a security guarantee. It records what we saw on the day.

Built for small professional firms

Accounting and tax firms

Roughly 5 to 50 staff, holding client tax records, payroll and financial data.

Law firms

Roughly 3 to 30 lawyers, holding matter files, client correspondence and privileged documents.

Fifteen minutes is enough to know if a review would help.

Gatepost Review is run by Stephen Pritchett. Write with a line about your firm and the tools you use. You'll get a reply within one working day.

Email Stephen
Stephen@GatepostReview.com