ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

A Quarterly Access Review for Your Practice Management System

Stale user accounts and over-broad permissions in Clio and similar platforms are a quiet risk. Use this quarterly checklist to tighten who can see what.

3 min readBy Counsel Cyber Team

A practice management platform holds nearly everything about a matter: client contact details, billing records, notes, calendars and documents. Over time, the list of people who can reach that information tends to grow in ways nobody planned. Interns finish, associates leave, and a paralegal who moved to a new team keeps old privileges.

A short, regular access review keeps this under control. The checklist below applies to Clio, MyCase, PracticePanther and similar tools, and the same ideas carry over to document management systems. Menu names differ by product, so adapt as needed.

Why quarterly

Annual reviews are easy to skip and let too much drift accumulate. Monthly reviews feel like a burden. Quarterly is a workable rhythm for most small and mid-size firms. Put it on the calendar with a named owner, usually the firm administrator or office manager, with IT assisting.

Step 1: Export the user list

Pull a complete list of users, their roles, their last sign-in dates and whether MFA is enabled where the product reports it. If the platform does not show this, ask your vendor or IT provider how to get it.

Compare it against an HR roster of current staff, contractors and attorneys. Every account should match a real, current person.

Step 2: Remove or disable what should not be there

  • Departed employees, interns and temporary staff.
  • Contractors whose projects have ended.
  • Duplicate or shared accounts, such as "frontdesk" logins that several people use, which make it impossible to know who did what.
  • Accounts with no sign-in for a long stretch, such as 90 days. Confirm with a manager before disabling, but do not leave them idle.

Disabling is usually safer than deleting, because it preserves history and attribution.

Step 3: Check roles against jobs

Look at permission levels, not just who has an account.

  • Who can see billing and trust accounting information? It should be a small group tied to actual duties.
  • Who can export data in bulk? This is a high-risk permission that few people need.
  • Who has administrator rights? Keep that to as few people as practical, and make sure those accounts have MFA.
  • Do contract staff or part-timers see matters they do not work on?

The principle is least privilege: grant what the role requires and nothing more.

Step 4: Review matter-level restrictions

Some matters need extra protection, such as high-profile clients, internal firm matters, or situations where an ethical wall is in place. Check that:

  • Restricted matters are visible only to the intended team.
  • Conflict screens in place for lateral hires or other situations still match current staffing.
  • Matters that have closed are archived with appropriate access.

Step 5: Look at integrations and API connections

Third-party apps connected to the platform can hold persistent access to client data. Review the list of connected apps and ask:

  • Is each integration still used?
  • Who authorized it, and what data does it reach?
  • Does the vendor behind it meet your security expectations?

Remove anything unused. Treat new connections as requests that need approval, rather than something any user can add on their own.

Step 6: Confirm sign-in security

Verify that MFA is required for every user, that single sign-on is used if the product supports it, and that password rules are sensible. If you can limit logins by location or device, consider it.

Step 7: Record what you did

Keep a dated note of who performed the review, what changed and what is outstanding. This record is useful when a client questionnaire or insurance application asks how often you review access.

Build removal into offboarding

The best review is the one that finds nothing, because offboarding already removed access the day someone left. Make practice management removal a line item on your offboarding checklist, owned by HR or administration and checked by IT.

Getting help

Counsel Cyber supports law firms using Clio, NetDocuments, iManage and Microsoft 365, and we can assist with an access review or set one up as a recurring service. If you would like a template for the checklist above, we will share it.