ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX · Serving TX, AR, LA, OK & KS
(737) 325-2520

Document Management for Law Firms: Folder Structure and Permissions

A practical guide to organizing law firm documents with sensible folder structure, naming, matter-level permissions and retention that survives staff turnover.

3 min readBy Counsel Cyber Team

Ask five lawyers where a document lives and you may get five answers. Some save to the desktop, others to a shared drive, a few to an email draft folder and one to a USB stick. When that is how a firm works, finding files is slow, permissions are inconsistent, and a security incident becomes much harder to scope. The tool matters less than the structure you impose on it.

Whether your firm uses a dedicated system such as NetDocuments or iManage, a practice-management platform, or SharePoint and OneDrive, the same principles apply.

Start With One Source of Truth

Decide where final and working client documents live, and say so in policy. Everything else is a convenience copy. Without that decision, no structure will hold. Publish a short rule such as: "Client work product is saved in the document management system, not on local drives or personal accounts."

Organize Around the Matter

Law firms think in clients and matters, so structure should reflect that.

Suggested hierarchy

  1. Client
  2. Matter
  3. Standard subfolders within each matter

Standard subfolders

Use a consistent template, adapted to the practice area. A litigation template might include:

  • Correspondence
  • Pleadings
  • Discovery
  • Research
  • Client documents
  • Billing and administrative
  • Drafts

A transactional or estate-planning template will differ, but the principle is the same: identical structure across matters so anyone can find things.

Automate where possible

Create templates so new matters get the right folders and permissions automatically, rather than relying on people to build them by hand.

Naming Conventions

Simple rules reduce chaos:

  • Start with the date in a sortable format, such as year-month-day
  • Follow with a short, descriptive title
  • Mark versions clearly, and prefer version history to filenames like "final_v3_REAL"
  • Avoid special characters and very long names
  • Never put sensitive details like Social Security numbers in filenames

Permissions

Security begins with who can open what.

  1. Default to the matter team. Grant access to the people working on the matter, not the whole firm.
  2. Use groups, not individuals. Assign permissions to role-based groups so access can be changed in one place.
  3. Restrict sensitive matters. Provide ethical walls and restricted folders for conflicts, HR, financial records and high-profile clients.
  4. Separate administrative access. The ability to change permissions should belong to a small, named group.
  5. Review regularly. Check access quarterly for departed staff, role changes and finished matters.
  6. Log access. Turn on audit logging so you can answer who opened or downloaded what.

Broad "everyone can see everything" settings are convenient until a departing employee, a compromised account or a conflict problem shows why they are risky.

External Sharing

Clients and co-counsel need to receive documents. Use secure sharing links with expiration dates and passwords or authentication rather than attaching sensitive files to ordinary email. Review active external shares periodically and disable open links. ABA Formal Opinion 477R discusses securing client communications and suggests considering more secure methods when the sensitivity warrants.

Email Filing

Email contains much of the matter record. Use integrations that let users file messages and attachments to the matter with one click, and teach staff to do so consistently. An unfiled email is a missing document.

Retention and Closing Matters

  • Define a retention schedule by matter type, consistent with your state's rules and client agreements.
  • Close matters formally, archive them and revoke unneeded access.
  • Delete data when the retention period ends, subject to any legal holds.
  • Make sure backups and archives follow the same logic, so deleted data does not live forever elsewhere.

Migration Tips

When cleaning up an existing mess:

  1. Inventory the sources, such as shared drives, desktops and cloud accounts.
  2. Decide what to migrate, archive and delete.
  3. Pilot with one practice group.
  4. Train users before cutover and again after.
  5. Lock down the old locations to read-only to stop drift.

Where We Fit

Counsel Cyber helps firms design folder templates, set matter-level permissions and migrate documents into well-governed systems. If your document environment feels messy, we can start with an assessment of where files live and who can reach them.