ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX · Serving TX, AR, LA, OK & KS
(737) 325-2520

Clio and NetDocuments Access Reviews: A Quarterly Checklist

Practice-management permissions drift as staff come and go. Use this quarterly checklist to review user access in your case and document systems before it bites.

4 min readBy Counsel Cyber Team

Most law firms spend real effort choosing a practice-management platform and almost none on keeping its permissions tidy afterward. Over a few years, the user list in your case management and document systems becomes a record of every hire, departure, temp, intern and shortcut. Nobody planned it that way, but the result is the same: people can see matters they have no reason to touch.

A quarterly access review fixes this without much cost. It takes a few hours, needs no special tooling, and it is the kind of control that clients and cyber-insurance underwriters increasingly ask about. The steps below apply whether you run Clio, NetDocuments, iManage, or a mix of tools alongside Microsoft 365.

Why access drift matters

Model Rule 1.6(c) asks lawyers to make reasonable efforts to prevent unauthorized access to client information, and Model Rules 5.1 and 5.3 address supervision of lawyers and nonlawyer staff. Confirm the specifics with your state bar, but the practical point is clear: if a former employee's account still works, or a paralegal can open every matter in the firm, that is hard to call reasonable.

Drift also raises the cost of any incident. If one account is compromised, the attacker inherits whatever that account could reach. Tighter permissions mean a smaller blast radius.

Before you start

Pick a named owner, usually the firm administrator or office manager, and a second reviewer, ideally a partner. The person who grants access should not be the only one who checks it.

Gather three lists:

  • Current HR roster, including contractors, temps and outside co-counsel with access
  • Active user list from each platform
  • Active user list from Microsoft 365 or your identity provider

The checklist

1. Match users to people

Compare each platform's user list against the HR roster. Flag any account that does not map to a current person. Shared logins such as "frontdesk" or "scanner" deserve special attention, because they cannot be tied to an individual and usually bypass multifactor authentication.

2. Remove or suspend departed users

Disable accounts for anyone who has left. Do not simply delete them, because matter history and audit logs often depend on the user record. Check API tokens and connected apps tied to those users as well.

3. Review roles and administrators

List everyone with administrator rights. Most firms need very few. Ask of each: does this person need admin rights to do their job today? Move day-to-day users to standard roles.

4. Check matter-level access

Look at how matters and workspaces are shared. Common problems include:

  • Firm-wide visibility on matters that should be restricted, such as HR, firm finances, or sensitive client work
  • Ethical walls that were set up once and never revisited after staff changes
  • Former conflicts-screened attorneys who were later given access by mistake

5. Audit third-party connections

Practice-management tools connect to email, calendars, billing, e-signature and AI assistants. Review each connected app, confirm someone still uses it, and revoke the ones nobody can explain.

6. Confirm MFA coverage

Verify that every account has multifactor authentication enforced, not just offered. Phishing-resistant methods such as security keys or passkeys are better than text messages where your platform supports them.

7. Sample the audit logs

Spot-check login and download activity. You are looking for odd hours, unfamiliar locations, and bulk exports. A few minutes of sampling often reveals more than a long policy document.

Document what you did

Write a one-page record: date, reviewer names, accounts removed, roles changed, exceptions accepted and why. Keep it with your security policies. When a client sends a security questionnaire or an insurer asks how you manage access, you will have a dated answer rather than a verbal assurance.

Make it routine

Tie the review to events as well as the calendar. Departures should trigger same-day deprovisioning through a short offboarding checklist, and new hires should get access based on a defined role template rather than copying a colleague's permissions. Copying a colleague is the main way drift starts.

Also decide in advance who approves exceptions. If a partner wants an associate to see a restricted matter, that request should be written down and reviewed at the next quarterly check, not left in place indefinitely.

Common mistakes

  • Treating the review as an IT task only, when the matter owners are the ones who know who should see what
  • Skipping contractors and outside counsel because they are not on the payroll
  • Fixing the findings but never recording them
  • Waiting for an annual review, by which point dozens of changes have piled up

Where we can help

Counsel Cyber helps firms run these reviews across Clio, NetDocuments, iManage and Microsoft 365, and can turn the findings into a short report you can share with clients or insurers. If you would like a second set of eyes on your current permissions, we are glad to start with a no-pressure security review.