Most law firms spend real effort choosing a practice-management platform and almost none on keeping its permissions tidy afterward. Over a few years, the user list in your case management and document systems becomes a record of every hire, departure, temp, intern and shortcut. Nobody planned it that way, but the result is the same: people can see matters they have no reason to touch.
A quarterly access review fixes this without much cost. It takes a few hours, needs no special tooling, and it is the kind of control that clients and cyber-insurance underwriters increasingly ask about. The steps below apply whether you run Clio, NetDocuments, iManage, or a mix of tools alongside Microsoft 365.
Why access drift matters
Model Rule 1.6(c) asks lawyers to make reasonable efforts to prevent unauthorized access to client information, and Model Rules 5.1 and 5.3 address supervision of lawyers and nonlawyer staff. Confirm the specifics with your state bar, but the practical point is clear: if a former employee's account still works, or a paralegal can open every matter in the firm, that is hard to call reasonable.
Drift also raises the cost of any incident. If one account is compromised, the attacker inherits whatever that account could reach. Tighter permissions mean a smaller blast radius.
Before you start
Pick a named owner, usually the firm administrator or office manager, and a second reviewer, ideally a partner. The person who grants access should not be the only one who checks it.
Gather three lists:
- Current HR roster, including contractors, temps and outside co-counsel with access
- Active user list from each platform
- Active user list from Microsoft 365 or your identity provider
The checklist
1. Match users to people
Compare each platform's user list against the HR roster. Flag any account that does not map to a current person. Shared logins such as "frontdesk" or "scanner" deserve special attention, because they cannot be tied to an individual and usually bypass multifactor authentication.
2. Remove or suspend departed users
Disable accounts for anyone who has left. Do not simply delete them, because matter history and audit logs often depend on the user record. Check API tokens and connected apps tied to those users as well.
3. Review roles and administrators
List everyone with administrator rights. Most firms need very few. Ask of each: does this person need admin rights to do their job today? Move day-to-day users to standard roles.
4. Check matter-level access
Look at how matters and workspaces are shared. Common problems include:
- Firm-wide visibility on matters that should be restricted, such as HR, firm finances, or sensitive client work
- Ethical walls that were set up once and never revisited after staff changes
- Former conflicts-screened attorneys who were later given access by mistake
5. Audit third-party connections
Practice-management tools connect to email, calendars, billing, e-signature and AI assistants. Review each connected app, confirm someone still uses it, and revoke the ones nobody can explain.
6. Confirm MFA coverage
Verify that every account has multifactor authentication enforced, not just offered. Phishing-resistant methods such as security keys or passkeys are better than text messages where your platform supports them.
7. Sample the audit logs
Spot-check login and download activity. You are looking for odd hours, unfamiliar locations, and bulk exports. A few minutes of sampling often reveals more than a long policy document.
Document what you did
Write a one-page record: date, reviewer names, accounts removed, roles changed, exceptions accepted and why. Keep it with your security policies. When a client sends a security questionnaire or an insurer asks how you manage access, you will have a dated answer rather than a verbal assurance.
Make it routine
Tie the review to events as well as the calendar. Departures should trigger same-day deprovisioning through a short offboarding checklist, and new hires should get access based on a defined role template rather than copying a colleague's permissions. Copying a colleague is the main way drift starts.
Also decide in advance who approves exceptions. If a partner wants an associate to see a restricted matter, that request should be written down and reviewed at the next quarterly check, not left in place indefinitely.
Common mistakes
- Treating the review as an IT task only, when the matter owners are the ones who know who should see what
- Skipping contractors and outside counsel because they are not on the payroll
- Fixing the findings but never recording them
- Waiting for an annual review, by which point dozens of changes have piled up
Where we can help
Counsel Cyber helps firms run these reviews across Clio, NetDocuments, iManage and Microsoft 365, and can turn the findings into a short report you can share with clients or insurers. If you would like a second set of eyes on your current permissions, we are glad to start with a no-pressure security review.