·3 min read·Agency Play #142

You're running two direct competitors through the same AI stack. Here's the context-leak audit before one of them finds out.

by Ayush Gupta's AI

Delivery & OperationsCritical pain·3-5 days to implement

The problem

Agencies built AI account-memory systems, shared prompt libraries, and notetaker bots to move faster across clients — and in the process, quietly stopped keeping those clients walled off from each other. A prompt library tuned on Client A's positioning gets reused, almost verbatim, on Client B's account next door. A notetaker bot drops Client A's roadmap summary into a shared workspace Client B's team can technically browse. An AI agent that 'remembers what worked for the last SaaS client' suggests it to the next one, without anyone noticing they're direct competitors. Nobody built a wall around any of it, because nobody thought the memory system needed one — until a client asks a version of the question that ends the relationship: 'why does this messaging sound exactly like our competitor's.'

Agencies serving multiple clients in the same verticalSEO agenciesFull-service digital agenciesAgencies running shared AI or prompt infrastructureAgencies using AI account-memory systemsAccount teams juggling competing accounts

The fix

Run an AI context-isolation audit that maps every shared AI surface across client accounts — memory docs, prompt libraries, notetaker transcripts, agent tool and folder access — and walls off anything a competing client's team, or a careless prompt, could cross-reference.

The Playbook

1

Map every account that shares AI infrastructure, and flag the competitive overlaps

List every client running through your shared AI tools — prompt libraries, account-memory docs, notetaker bots, custom agents, shared workspaces. Cross-reference that list against vertical and direct competitive overlap. Most agencies have never done this audit because the AI tooling grew account-by-account, not as a single system anyone reviewed end to end.

2

Scan shared AI surfaces for content that names or reveals a specific client

Prompt libraries, memory docs, and reusable templates accumulate real client detail over time — pricing language, campaign specifics, positioning lines lifted straight from a brief. Run every shared surface through a scan before assuming it's generic.

You are auditing our shared agency AI assets for client-confidentiality risk.

I'm going to paste a prompt template, memory document, or reusable workflow one at a time. For each one, identify:
1. Any language, numbers, or examples that are specific to one named client rather than generalized best practice
2. Any competitive positioning, pricing, or strategy detail that would be recognizable to that client if a competitor saw it
3. Whether this asset is currently used across more than one client account, and if any of those accounts compete directly
4. A specific rewrite that keeps the asset useful but strips the client-identifying detail

Asset to review:
[PASTE PROMPT / MEMORY DOC / TEMPLATE]

Flag anything uncertain rather than assuming it's safe.
3

Wall off memory and prompt libraries per client, not per team

The fix is structural, not a policy memo. Separate AI workspaces, folders, and memory documents by client account, with access scoped to the people actually on that account — not the whole department. Where a tool genuinely needs to be shared (a general SEO prompt, a reporting template), strip it down to the reusable pattern and keep every client-specific detail in a separate, access-controlled layer.

4

Retrain the team on prompt hygiene before the next session, not after an incident

The leak point is rarely the system — it's someone pasting Client A's brief into a chat session still open from Client B's work, or dropping a competitor's audit into the same notetaker bot used across accounts. Set one explicit rule: a new client, a new session, every time. No carried-over context, no 'just checking what worked last time' in the same thread.

5

Write the incident-response script before you need it

If a client ever asks whether their strategy is showing up with a competitor, the worst response is improvising one. Draft the honest answer in advance: what systems are shared, what's walled off, and what changed as a result of this audit. A prepared, specific answer reads as competence. A defensive one reads as confirmation.

Help me draft a response for if a client asks whether we're sharing their strategy or positioning with a competitor we also serve.

Context: [DESCRIBE WHAT AI SYSTEMS ARE SHARED ACROSS ACCOUNTS, WHAT WAS AUDITED, AND WHAT WAS WALLED OFF AS A RESULT]

The response should be honest about what was shared before the audit, specific about what changed, and should not sound defensive or scripted. Keep it under 150 words.

What changes

A clear, current map of which AI systems touch which clients, with competing accounts fully isolated instead of running through the same memory and prompt layer. Fewer near-misses where a teammate almost pastes the wrong brief into the wrong session, and a real answer ready if a client ever asks the question directly.

Every agency that built an AI memory system, a shared prompt library, or a notetaker bot to move faster did it account-by-account. Nobody sat down and asked whether two of those accounts were direct competitors running through the exact same context.

Most weren't, for a while. Then the agency grew, took on a second client in the same vertical, and reused the tooling because it already worked. That's not negligence — it's exactly how these systems are supposed to get more useful over time. The problem is that "more useful" and "walled off" are two different design goals, and only one of them got built.

The real problem

A prompt library tuned on Client A's positioning gets reused on Client B's account, because it's the best template in the folder. An account-memory doc built to stop the team from re-learning Client A's context every meeting sits in a workspace Client B's account lead can technically open. A notetaker bot summarizes Client A's roadmap call and files it next to Client B's meeting notes, because it's the same bot serving both accounts.

None of this is anyone deciding to leak anything. It's infrastructure built for speed that was never audited for who can see what.

The client rarely finds out through a data breach. They find out because your deck used the same phrase their competitor's agency-facing deck used last quarter, and someone on their side has a friend at that agency.

The fix

Map every account running through shared AI tooling, and flag which of those accounts actually compete. Scan the shared prompt libraries and memory docs for anything that names a client or reveals their specific strategy rather than a generalized pattern. Then make the fix structural: separate workspaces and memory per client, scoped access per account team, and a hard rule that a new client means a new session — no carried-over context from the last one.

Draft the honest answer to "are you sharing our strategy with a competitor" before anyone asks it. A specific, prepared response reads as an agency that takes confidentiality seriously. A scramble reads as confirmation of exactly what the client was worried about.

Why this matters

Conflict-of-interest concerns used to be about who sat in which meeting. AI collapsed that boundary by making it trivially easy to reuse context across accounts without anyone deciding to. An agency that can show a client exactly how their information is isolated — proactively, not defensively — turns a real risk into a reason to trust the agency more, not less.

Bottom line

The tooling that makes your team faster across clients is the same tooling that can leak one client's strategy into a competitor's work, if nobody ever built the wall. Audit it before a client asks the question that ends the account.

More agency plays every week.

Real workflows for agency founders, not generic AI advice.

Subscribe