A document management system, whether iManage, NetDocuments or a similar platform, is meant to be the firm's single source of truth. Over time, many become something closer to a digital attic. Duplicate folders, inconsistent names, abandoned workspaces and permissions nobody remembers granting accumulate quietly.
Messiness is more than an annoyance. Documents that cannot be found cost billable time. Permissions that are too broad expose client information to people who should not see it. And untidy records make it harder to respond to a client request, a conflict check or a litigation hold.
Why Hygiene Is a Security Issue
Document management permissions are a core confidentiality control. Model Rule 1.6(c) discusses reasonable efforts to prevent unauthorized access to client information, and ABA Formal Opinion 477R discusses weighing sensitivity and risk. Over-permissioned workspaces and stale accounts are precisely the kinds of weaknesses that undermine those efforts. They also magnify the damage if one user's account is compromised.
Start With Naming Conventions
Consistent naming makes everything else easier. Agree on a standard and document it on one page. Elements commonly included:
- Client and matter numbers in a fixed format.
- Document type, such as pleading, correspondence, memo or contract.
- Date format, ideally year first so files sort naturally.
- Version or status indicators, such as draft or final.
Avoid personal naming habits, special characters and vague names such as "new document" or "final final."
Structure Workspaces Predictably
Use the same folder template for each matter type. A litigation matter might have standard subfolders for pleadings, discovery, correspondence and research. Predictable structure means anyone can find what they need, and it makes permissions easier to apply consistently.
Permissions: Principle of Least Privilege
Set defaults by role and matter
Grant access to those working on the matter, not the entire firm by default. For sensitive matters, use restricted workspaces. Ethical walls and conflict screens should be enforced technically, not just recorded in a memo.
Review access regularly
Matter teams change. Run a quarterly review of who has access to sensitive workspaces, remove people who have rotated off and confirm that screens are still in place.
Handle departures promptly
Disable accounts the day someone leaves and reassign ownership of their documents. Review externally shared links tied to their account.
Clean Up Safely
Reduce clutter
Identify duplicate documents, empty folders and abandoned workspaces. Archive closed matters according to your records policy, and do not delete anything without confirming retention obligations and any litigation holds. Check your state's rules and your engagement letters.
Manage email filing
Email is often the messiest part. Encourage filing of relevant messages into the matter workspace, and consider tools that make filing quick, since people file when it is easy.
Fix orphaned files
Documents saved on desktops, personal OneDrive folders or unmanaged drives sit outside your controls. Periodically scan for these and bring them under management.
Sharing and Collaboration
Define how external sharing works. Prefer secure links with sign-in and expiry over email attachments for sensitive documents. Review who can create external links and audit them periodically.
Measure and Maintain
Pick a few simple measures:
- Number of workspaces without a named owner.
- Count of users with access to restricted matters.
- Active accounts belonging to departed staff, which should be zero.
- Documents saved outside the system.
- Open external sharing links older than a set period.
Review them quarterly and assign someone to fix the issues.
Train People
Hygiene fails when habits do. A short guide for new hires, a refresher each year and a visible owner for the system help maintain standards.
Plan for Change
If you are considering migrating platforms, cleaning up first reduces cost and risk. Do not move clutter to a new home.
Common Mistakes
- Granting firm-wide access for convenience.
- Leaving former employees' accounts active.
- Having no naming standard, or having one nobody follows.
- Deleting documents without checking retention duties.
- Ignoring documents stored outside the system.
How Counsel Cyber Helps
Counsel Cyber works with firms on iManage, NetDocuments and Microsoft 365 document environments, including permission reviews and cleanup plans. If you would like a permissions health check, we can provide a plain-language report.