Sharing One Survey Login Across Clients Is a Liability
Running every client's employee survey from one account concentrates other companies' sensitive feedback in a place none of them control. What that costs, and what to do instead.
Most consultancies run every client's survey out of one account. It is not laziness; it is what the tools are shaped for. But it quietly makes your firm the custodian of several companies' most sensitive employee feedback, in a place none of them control, and that is a position worth looking at directly.
What you are actually holding
Open the account and look at what is in there. Harassment climate results for one client. Layoff aftermath for another. An upward review of a CEO who is still in post. Exit feedback naming a manager by pattern if not by name.
Now ask the questions your client's counsel would ask:
- If your firm is subpoenaed in an unrelated matter, what is discoverable?
- If an employee at Client A files a claim, and your account also holds Client B, what does disclosure look like?
- When a consultant leaves your firm, what did they still have access to on the way out?
- If your account is breached, how many companies do you have to notify, and who tells them?
None of these are exotic. They are the ordinary consequences of concentration, and the reason they rarely get raised is that nobody prices the arrangement until something happens.
The shared password makes it worse
The account is usually shared, too, because per-seat pricing punishes a firm of six for behaving properly. So there is one credential, it is in a password manager and probably a Slack message from 2024, and the access log cannot tell you which of your people opened which client's results.
"Who at your firm has seen our employee feedback?" is a fair question from a client. "Everyone with the password, and I cannot tell you who used it" is not a good answer.
An account per client is not the fix either
The obvious response is to have each client buy their own. Now the data is properly theirs, which is right, and you have added a procurement cycle to the front of every engagement, which is why it does not happen. Six-week project, three-week purchase. Most firms take the shared account instead, and honestly the incentives make that rational.
Separate the workspaces, keep one login
The structure that works is per-client isolation with per-firm access:
- A separate workspace per client, with its own key. Client A's results are not decryptable with Client B's key. There is no query that returns both.
- One login for you, with a membership in each. Your people are named individuals, not a shared password, and the client can see exactly which of them can open their workspace.
- The client owns theirs from day one. If that is only a promise, it is worth nothing at the moment it matters. Make it structural: we refuse to publish a survey in a client workspace until somebody at the client is an owner with their own key.
- One bill, on your side. The client should not have to buy anything for their data to be theirs.
What this does to the discovery question
It does not make your firm immune to a subpoena. Nothing does. What it changes is what a subpoena can reach.
If answers are encrypted in the respondent's browser and stored as ciphertext, then the survey vendor holding them cannot produce readable individual responses to anybody, and neither can you, because you never had them. What exists is an aggregate, decrypted in the browser of somebody the workspace gave a key to. The set of individual answers you could be compelled to hand over is empty, not because of a policy, but because it does not exist in a form anyone can read.
That is a materially different conversation with a client's general counsel than "we take security seriously".
The cheap version of doing this right
Move to a structure where each client's data is separate, the client owns it, and your access is a named membership you can end in one click. Then say so in your engagement letter, in one paragraph, because it is a genuine differentiator against every firm still running on a shared login.
FAQ
Is a folder per client good enough? No. Folders are organisation inside one account: same key, same access, same discovery scope. Separation has to be at the workspace and key level to change anything.
What if a client insists on owning the account? Then let them, but you have added procurement to the start of the engagement. A sponsored workspace they can take over later gets you both the same outcome without the delay.
How do I end a departing colleague's access? Remove their membership from each client workspace. That revokes access and deletes their stored copy of the key. It cannot reach a browser where they already unlocked it, which is true of every client-side encrypted system, so it is not a substitute for offboarding hygiene.
Does this cost more than one shared account? One licence covers five live client workspaces, so for most firms it is comparable, and it is considerably cheaper than a seat-priced tool bought per client.