Vibe coding for CIOs in professional services.
At a law, accounting or consulting firm the CIO reports to partners who own the business and build what they like. The document system enforces ethical walls between client matters. A partner's homemade tool that reads from it does not, and an engagement letter promises the client their data never left the firm's approved vendors.
What is true about software in professional services before you write a prompt.
Agencies, consultancies, law firms and accounting practices sell time and expertise, and most of their software is a compromise: the practice management system, the time tracker, the client portal that nobody likes. Executives at these firms are building their own: a client dashboard, a proposal generator, an intake workflow, a utilisation report. Every one holds client confidential information.
Client confidentiality is the business
A tool that lets one client see another's project, or exposes a document to the wrong staff member, ends a relationship and possibly a licence. Access control per client is the first thing to build and the first thing to check.
The engagement letter has terms about data
Clients often specify where their data may be stored and who may process it. A tool on a personal hosting account in the wrong region breaches contracts the firm signed.
Billing must reconcile
Time, rates, expenses and invoices have to agree with the accounting system. A utilisation tool or a billing dashboard that drifts from the books causes arguments with clients and auditors.
Professional rules apply to software
Legal privilege, accounting standards and industry codes constrain how records are kept and who may access them. The tool has to fit those rules, not the other way round.
What a CIO in professional services builds first.
01Ethical walls that follow the documents
A template that checks the document management system's matter permissions before showing a file, so a partner's tool cannot show a walled matter to someone the wall excludes. iManage and NetDocuments expose this. Most homemade tools ignore it.
02The approved vendor list, per engagement
A register of which hosting, database and AI providers are approved for client data, in which regions, mapped to the engagement terms that reference them. A partner's tool is checked against it before it holds a client file.
03Matter-scoped access, not firm-wide
A login for partner-built tools that inherits a user's matters from the practice management system. Staff see the clients they work for, and nothing else, without each tool inventing its own permission list.
CIOs in every industry tend to build the same four things. The CIO page has that list.
A client's documents go to an unapproved AI provider
A partner builds a due diligence summariser that sends client contracts to an AI API the firm has never reviewed. The engagement letter for that client lists approved processors and this is not one. A client audit asks where their documents went. The firm must disclose, may lose the engagement, and in a law firm may have a privilege question the partners cannot answer.
The pattern underneath is the one every CIO hits: every department app is connected to a real system with a real key, hosted on someone's personal account, with no offboarding. When they leave, the app stays, and so does the access.
What a safe build in professional services usually runs on.
Builds run on a standard web stack with Postgres, private document storage, single sign-on for staff and a scoped client login, and integrations with the practice management, time and accounting systems through read-only keys where possible. Client-facing pages are separated from internal ones from the start.
What changes for a CIO in professional services.
A CTO in your corner helps you build the rules as software: a template with single sign-on, secret storage, logging and hosting already correct, so the departmental builder starts safe. And a CTO in chat for the moments when someone's tool touches something it should not. You keep the speed the business has discovered. You get the control back.
What CIOs in professional services ask.
A CTO who has read professional services apps before yours.
Thirty minutes, free, no card. What you built, what is going on with it, whether we can help.
In your corner.