Most client confidentiality breaches in messaging apps don’t come from a dramatic failure. They come from a Slack Connect channel nobody remembered was still open, a Teams guest invite that never got revoked, or a WhatsApp message sent from someone’s personal phone because it was faster than logging into anything official.
This is different from a general shadow IT problem. Shadow IT is about unauthorised tools showing up on the network at all. This piece is about the specific messaging habits that put client-confidential work at risk, even inside tools your agency has already sanctioned and pays for.
Client files and conversations leak most often through everyday habits, not obvious mistakes
The risk in Slack, Teams, and WhatsApp rarely comes from someone doing something clearly wrong. It comes from ordinary collaboration habits that were never designed with client confidentiality in mind.
Slack Connect and Teams guest access quietly outlive the projects they were set up for
Slack Connect channels and Teams guest access both make external collaboration genuinely easy, which is exactly why they tend to accumulate. A channel set up for a three-month project often stays open a year later, with the client’s guest account still able to see everything posted in it, long after anyone’s actively checking who has access to what.
Unmanaged file forwarding moves client work outside any system that tracks it
Forwarding a file from a Slack thread to a personal email, or from a Teams chat to WhatsApp, takes one tap and leaves no record in either system that it happened. Once a client file leaves the platform it was shared through, there’s no audit trail and no way to revoke access if something goes wrong later.
The real risk with WhatsApp is the personal device it’s running on, not the app itself
WhatsApp’s encryption is genuinely strong. That’s not where the risk sits for an agency.
Personal devices have no admin visibility and no backup an agency controls
When client conversations happen on WhatsApp through a personal phone, the agency has no visibility into what was said, no backup if the device is lost, and no way to remove access when someone leaves the business. The conversation and everything in it simply lives on a device the agency doesn’t manage and never will.
There’s no clean way to separate client work from personal use on the same thread
Even with the best intentions, a WhatsApp conversation with a client tends to blur into the same thread as personal messages, on the same phone, backed up (if at all) to whichever personal account is signed in. There’s no dedicated professional space for that conversation to live in.
Grounded in what Dr Logic sees across client-facing agencies, the businesses managing this well aren’t the ones with the strictest policy. They’re the ones that made the sanctioned tool genuinely easier to use than the workaround, so nobody has a reason to reach for WhatsApp in the first place.
If client confidentiality across Slack, Teams, or WhatsApp is a live concern for your agency, our Cyber Security team can help review where the actual gaps sit.
Good enough governance for a small agency does not mean heavy-handed lockdown
A 70 to 150 person agency doesn’t need enterprise-grade data loss prevention tooling to close most of this gap. It needs a small number of specific habits applied consistently.
What “good enough” looks like in practice:
- A regular audit of Slack Connect channels and Teams guest accounts, closing anything tied to a finished project
- A clear default for where client conversations happen, with WhatsApp positioned as a fallback rather than the norm
- An NDA and confidentiality obligation that names which tools are acceptable for client communication, not just a general confidentiality clause
- A simple offboarding step that revokes guest and external access the same day someone’s role ends, not weeks later
None of this requires banning tools your team already relies on. It requires making the sanctioned option the obviously easier one, and closing external access on a schedule rather than only when someone happens to remember.
What this means for your agency
Client confidentiality risk in messaging tools is rarely about a single bad decision. It’s about small habits, an open Slack Connect channel, a guest account nobody revoked, a quick WhatsApp forward, accumulating quietly until one of them matters. Good enough governance means making the right habit the easy one, not adding friction everywhere at once.
Related articles
- Shadow IT: How to Detect and Manage Unauthorised Apps
- Securing Microsoft 365 and Google Workspace for Hybrid Teams in 2026
FAQs
Is WhatsApp safe to use for client communication?
The encryption itself is strong, but the risk for an agency isn’t encryption. It’s that conversations on a personal device have no admin visibility, no agency-controlled backup, and no way to revoke access when someone leaves. That’s a governance gap, not a security flaw in the app.
What's the risk with Slack Connect or Teams guest access for external clients?
Both make external collaboration easy, which means access tends to outlive the project it was set up for. A channel or guest account left open after a project ends gives a client, or anyone with access to their account, ongoing visibility into conversations they no longer have a reason to see.
How is this different from a general shadow IT policy?
Shadow IT is about detecting and managing unauthorised tools showing up on the network at all. This is about specific habits inside tools your agency has already sanctioned and pays for, where the risk comes from how they’re used rather than whether they’re approved.
Do we need to ban WhatsApp entirely to protect client confidentiality?
No. Outright bans tend to push conversations further out of sight rather than eliminating them. Making the sanctioned tool genuinely the easier option, and treating WhatsApp as a fallback rather than the default, closes most of the gap without a heavy-handed policy.



















































