Buying NetDocuments, iManage, SharePoint or another document management system does not by itself fix a firm's file problems. If lawyers save drafts called "final_v2_REAL" to their desktops, email attachments never reach the matter workspace and every folder has its own structure, the new system becomes an expensive version of the old chaos.
Good hygiene is a set of simple, agreed habits. They improve productivity, reduce risk and make security easier, because you cannot protect what you cannot find or classify. Here are the standards worth setting.
Why hygiene is also a security issue
Confidentiality depends on knowing where client information is. Files saved on local drives, personal cloud accounts or random shared folders escape backup, retention and access controls. Poor structure also leads to over-sharing, because administrators grant broad access when they cannot tell what is in a folder. When the firm responds to a legal hold, a client request or a breach investigation, scattered files multiply the work.
Standard 1: A consistent workspace structure
Define one template for matter workspaces, with a short list of standard subfolders appropriate to your practice. A litigation matter might include pleadings, discovery, correspondence, research and work product. A transactional matter might include drafts, executed documents, diligence and correspondence. Adjust for your practice, but make every matter in a group look the same, so anyone can find things.
Avoid deep nesting. Metadata and search in modern systems can reduce the need for many folder levels.
Standard 2: Naming conventions
Pick a convention and write it down. A common pattern includes the document type, a short description and the date, with a version indicator when needed. For example, a letter might be named with the date first so files sort chronologically.
Good conventions:
- Are short and consistent.
- Avoid special characters and spaces that cause problems with some systems.
- Use dates in a sortable format.
- Indicate status, such as draft or executed, in a standard way.
- Do not include confidential details such as full client names or sensitive facts in filenames where they might appear in logs or notifications.
If your system provides version history, use it instead of embedding "v2" and "v3" in names.
Standard 3: Email filing
Email is often where critical client communication lives, and it is the most commonly lost. Set an expectation that substantive emails and attachments are filed to the matter workspace, using the system's Outlook integration. Make it easy: one-click filing, rules for common cases and a reminder in onboarding.
Standard 4: Permissions by matter and role
Apply least privilege.
- Give access by matter team, not by blanket firm-wide permissions.
- Use groups rather than individual grants, so changes are easier to manage and audit.
- Create ethical walls and restricted matters for situations that require them, such as conflicts, lateral hires or sensitive internal matters.
- Limit who can delete, export in bulk or change permissions.
- Review access quarterly and when people change roles or leave.
Standard 5: External sharing
Define how documents are shared with clients and third parties.
- Use secure sharing links with expiration dates and passwords where appropriate, or a client portal, rather than unprotected email attachments for sensitive files.
- Avoid anonymous links to confidential material.
- Review active external shares regularly and remove stale ones.
- Disable personal file-sharing services for firm work.
Standard 6: Classification and retention
Tag documents by sensitivity, and apply retention rules consistent with your records policy and applicable state requirements, which you should confirm with your state bar. Close matters promptly, archive them and apply the retention schedule so that old files do not linger forever. Preserve anything under a legal hold.
Standard 7: Cleanup and migration
If you are moving from a file server, clean before you move. Remove duplicates and obsolete material, decide how to treat orphaned files and map old folders to the new structure. Moving unmanaged clutter into a new system carries the clutter forward.
Standard 8: Training and accountability
Train every new hire on the standards on day one, and provide a one-page quick reference. Appoint practice group champions who answer questions and notice drift. Run periodic spot checks and report findings without blame. Measure adoption: how many documents are being filed into matters versus saved elsewhere, and how many emails are being filed.
A short audit you can run this month
- Pick five active matters and see whether the structure matches the template.
- Search for files with generic names like "document1" or "final final."
- Review who has access to the most sensitive matters.
- Check for anonymous sharing links.
- Look for local folders or personal drives with client files.
Findings tell you where to focus.
Where we help
Counsel Cyber supports firms using NetDocuments, iManage, SharePoint and Microsoft 365, including cleanup, permissions review and migration planning. If you want help establishing standards or auditing your current system, we are glad to start with a short assessment.