ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Ethical Walls in Practice Management Tools: Permissions in Practice

How law firms can implement confidentiality screens in practice management and document systems: design, technical controls, testing and ongoing review.

3 min readBy Counsel Cyber Team

When a firm needs to screen a lawyer or staff member from a matter, the instruction is usually simple: they must not have access to this file. Turning that instruction into reality across email, documents, practice management, billing, chat and shared drives is less simple. A screen that exists only as a memo is not much of a screen.

This post looks at how firms can implement an ethical wall, sometimes called a confidentiality screen, using technical controls in practice management and document systems. It does not address when a screen is required or effective. Those are legal questions under the conflict rules of your state, so consult your ethics counsel and state bar.

Start with the decision, not the tool

Before IT touches anything, the responsible attorneys should document:

  1. Who is screened, by name, and from which client or matter.
  2. The reason and effective date.
  3. Who is allowed to work on the matter.
  4. Who is responsible for oversight, usually the general counsel, conflicts partner or managing partner.
  5. Any notice requirements to clients or affected persons, determined by counsel.

IT's role is to execute and verify the technical side under that direction.

Map every place the information lives

Matters leave traces in many systems. Build a checklist:

  • Practice management: matter records, contacts, notes, tasks, calendar entries, communications logs and billing entries.
  • Document management: workspaces, folders, search results and recent items.
  • Email: mailboxes, shared mailboxes, distribution lists and calendars.
  • File shares and cloud storage: SharePoint, Teams, OneDrive and legacy file servers.
  • Accounting and billing systems: time entries, invoices and reports.
  • Chat and collaboration: channels, direct messages and shared files.
  • Reports and dashboards: analytics that display matter names or amounts.
  • Backups and archives: who can restore or search them.
  • Paper files and physical areas, which are outside IT but belong on the checklist.

Implement technical restrictions

Practice management and document systems

Most mature platforms let you restrict a matter or workspace to a named group of users. Typical steps:

  1. Mark the matter as restricted or confidential, using the platform's feature.
  2. Replace broad firm-wide permissions with an explicit list of allowed users or groups.
  3. Add an explicit deny for screened individuals where the system supports it.
  4. Check that restrictions apply to related items such as documents, notes, tasks and bills.

Microsoft 365 locations

Restrict the associated SharePoint site or Teams channel to a limited group, and disable inheritance from broader groups. Review shared mailboxes and calendars connected to the matter. Where your licensing supports it, use sensitivity labels and information barriers to separate groups, since those features are designed for such separation.

Search and reporting

Confirm that restricted matters do not appear in search results, auto-complete lists, dashboards or recently opened items for screened users. If AI search or summarizing features are enabled, test them as well.

Administrator access

IT administrators can often see everything. Limit this to what is necessary, require named administrator accounts and review logs of administrative access to restricted matters. Include IT staff and outside providers in any confidentiality obligations, consistent with the supervision duties under Rule 5.3.

Test the screen

A configuration is not verified until someone tries to break it.

  1. Log in as, or simulate, a screened user.
  2. Search for the client name, matter number and sample document titles.
  3. Browse folders, calendars, shared drives and chat.
  4. Try accessing via links, recent files or email attachments.
  5. Document the test results with date and tester, and keep them with the matter's screening records.

Monitor and maintain

  • Audit logs: set alerts for access attempts by screened users.
  • Group changes: require approval and logging for any changes to the allowed group.
  • Periodic reviews: confirm quarterly that the permissions still match the authorized list.
  • Departures and transfers: adjust access promptly when people change roles or leave.
  • Termination of the screen: when the screen ends, restore access deliberately, following written approval.

Common failure points

  • A screened paralegal who remains a member of a firm-wide email group that receives matter correspondence.
  • Matter documents saved to a personal folder or local drive.
  • Time entries visible in billing reports.
  • Old workspaces from a prior migration with legacy permissions.
  • Chat messages that include screened persons.
  • Backups that remain searchable by broad groups.

Culture and training

Technical controls work best with clear expectations. Remind everyone involved that discussions in hallways and forwarded emails count. Have screened personnel acknowledge the screen in writing, as directed by the responsible attorneys.

How we help

Counsel Cyber helps law firms implement and test confidentiality screens across practice management, document management and Microsoft 365. If your firm is preparing for a lateral hire or a conflict that will require a screen, we can build a checklist for your environment and verify the result with the responsible partner.