ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Clio Permissions and Security Settings Every Firm Should Review

Practice management platforms hold your most sensitive data. Review these user role, sharing, authentication and audit settings in Clio or any similar system.

4 min readBy Counsel Cyber Team

Practice management software is where a firm's matters, contacts, billing records, trust accounting and client communications meet. That concentration makes it convenient and also makes it a high-value target. Most firms configure the platform during onboarding and rarely look at it again, so permissions drift as people join, change roles and leave.

This post uses Clio as an example because many small and mid-size firms run it, but the same review applies to MyCase, PracticePanther, Smokeball or any comparable platform. Menu names differ, so use this as a checklist of questions rather than a click-by-click guide.

Start with who has access

Export or view your user list and compare it with current staff. Look for:

  • Former employees, interns and temporary workers who still have active accounts.
  • Contractors or outside bookkeepers with broader access than their work requires.
  • Shared logins, such as a "frontdesk" account, that hide who did what.
  • Accounts for people who changed roles and kept permissions from the old job.

Remove or disable anything unexplained. Do this quarterly, and tie it to your offboarding checklist so departures trigger removal the same day.

Apply least privilege to user roles

Most platforms offer role-based permissions. A paralegal rarely needs the ability to export every contact, change billing rates or edit trust accounting. An administrator rarely needs to be an administrator all day.

Roles to examine

  1. Administrator or owner. Limit to the smallest number of people possible, and give each their own named account. Use a separate account for administrative tasks if the platform allows it.
  2. Billing and trust accounting. Restrict who can create payments, adjust ledgers or approve disbursements. Separating the person who enters from the person who approves is a basic internal control.
  3. Matter-level access. If you handle sensitive matters, such as high-profile clients or conflicts that require ethical walls, use the platform's matter restrictions instead of relying on people to stay out.
  4. Exports and reports. Bulk export is useful and risky. Limit who can run broad exports of contacts and matters.

Turn on strong authentication

Require multi-factor authentication for every user, not as an option. If your platform supports single sign-on through Microsoft 365, consider using it so that account disablement in one place cuts off access everywhere. Make sure the recovery method for MFA is not an email account that is itself unprotected.

Review the client portal and sharing

Client portals are a safer alternative to emailing documents, but only when configured thoughtfully.

  • Confirm clients must authenticate to view shared documents, and that links do not remain open indefinitely.
  • Review which documents are currently shared and whether any are no longer needed.
  • Check notification settings so that emails sent to clients do not include sensitive content in the message body.
  • Make sure staff know when to use the portal instead of a regular attachment.

Look at integrations and connected apps

Over time, firms connect accounting tools, e-signature services, calendars, email add-ins and automation platforms. Each connection can read or write data. Review the list of authorized apps, remove those you do not recognize or use, and check what each one can access. Ask for the same MFA and security expectations from integration vendors that you expect from your main platform.

Check the audit trail

Find out what activity logs your platform provides and how long it keeps them. Logs help answer practical questions: who changed this trust ledger entry, who exported this contact list, who logged in from an unusual location. Decide who reviews them and how often. If logs are only retained for a short time, document that limitation and consider whether it matches your needs.

Data retention and exit planning

Ask what happens to your data if you leave the vendor. Test whether you can export matters, documents and billing history in a usable format. Confirm how deleted data is handled and what the vendor's backup arrangements are, since SaaS vendors typically protect their own infrastructure but may not restore a single file you deleted by mistake. Many firms choose to keep an independent backup of cloud data as a result.

Document your settings

Write a one-page summary of the roles, authentication settings and integrations you approved, with a date. When staff change or a carrier asks about access controls, you will have an answer ready. This also supports the supervision duties in Model Rules 5.1 and 5.3, which concern how lawyers oversee people and nonlawyer assistance.

A simple quarterly routine

  1. Compare the user list with HR records.
  2. Review admin and billing roles.
  3. Remove unused integrations.
  4. Spot check shared portal documents.
  5. Record the date and findings.

How we can help

Counsel Cyber manages practice-management environments for law firms and can audit permissions, authentication and integrations in an afternoon. If it has been a while since anyone looked, ask us for a configuration review.