ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Joiners and Leavers: The Attorney Account Lifecycle for Firm IT

New hires need access quickly and departing attorneys need it removed just as fast. Use these checklists to keep both secure and consistent.

3 min readBy Counsel Cyber Team

People move through a law firm constantly: new associates, lateral partners, summer clerks, contract attorneys, paralegals and staff who leave for other jobs. Each transition is a security event. A new hire without proper setup creates risk when they improvise with personal tools. A departing employee whose access lingers creates a different kind of risk.

A written checklist, owned jointly by HR or administration and IT, makes both processes predictable. Below is a framework you can adapt. Items vary with your systems.

Why this matters for confidentiality

Rule 1.6(c) asks lawyers to make reasonable efforts to prevent unauthorized access to client information, and Rule 5.1 addresses supervisory responsibility. Leaving an ex-employee's accounts active, or letting a new hire pick their own file-sharing methods, runs against both. The documentation itself is also useful to show clients and insurers that you have a process.

Onboarding checklist

Before day one

  1. Receive written notice from HR with the start date, role, practice group and manager.
  2. Create the user account with a unique login, never a shared one.
  3. Assign licenses for email, Microsoft 365, practice management, document management, time and billing and phone.
  4. Place the user in the right security groups, with permissions based on role and matters, not copied from a colleague.
  5. Prepare the laptop with disk encryption, endpoint protection, current patches and standard software.
  6. Configure MFA enrollment so the user can complete it on day one.
  7. Prepare a welcome note with help desk contacts.

On day one

  1. Hand over equipment and confirm identity before issuing credentials.
  2. Walk the user through MFA setup and a password manager.
  3. Review the acceptable use policy, confidentiality expectations and AI policy. Collect a signed acknowledgment.
  4. Complete security awareness training.
  5. Show how to report suspicious emails and who to call for help.
  6. Confirm access to the right matters and no more.

First 30 days

  • Follow up on missing access and training.
  • Verify that the user is not using personal email or storage for client work.
  • Confirm the manager has reviewed the user's access.

Lateral attorneys need extra care

Laterals often bring files and contacts. Coordinate with ethics and conflicts counsel before importing client data, and keep clear records of what came from where. IT should not transfer matter files from a prior firm without authorization from the firm's responsible lawyer.

Offboarding checklist

Plan for both friendly departures and sudden ones. For urgent terminations, IT should be notified before the conversation happens, so access can be cut at the right moment.

Same day

  1. Disable the account and revoke active sessions and tokens in Microsoft 365 and every connected system.
  2. Reset passwords for shared resources the person knew, such as shared mailboxes or vendor portals.
  3. Remove MFA devices and any trusted device registrations.
  4. Retrieve laptops, phones, security keys, badges and other equipment. Remotely wipe or lock any personal device that holds firm data under your mobile device policy.
  5. Remove access to practice management, document management, billing and remote access.

Within a few days

  1. Convert the mailbox to a shared mailbox or set up forwarding and an out-of-office message, as the firm directs, and assign a supervising attorney to monitor it.
  2. Preserve the user's data in line with retention policy and any legal holds. Do not delete anything that might be subject to a hold.
  3. Transfer ownership of files, calendars and matters to a named person.
  4. Remove the user from phone systems, distribution lists and client portals.
  5. Review the account's connected applications and revoke them.

Within a month

  • Review logs for unusual downloads or forwarding before the departure.
  • Reclaim licenses.
  • Confirm a final checklist is signed by HR and IT.

Common pitfalls

  • Notification arrives late, or never, because HR and IT do not communicate.
  • Access is disabled, but shared passwords stay the same.
  • Contractors and temporary workers are not included in the process.
  • Departing attorneys take client files without a plan for notifying clients, which is an ethics question for your partners.
  • Old accounts remain "just in case."

Make it routine

Use a ticketing form so every start and exit triggers the same steps, and audit accounts quarterly against an HR roster. The review catches whatever slipped through.

Counsel Cyber manages onboarding and offboarding for law firm clients and can help build a checklist suited to your systems. Ask us for a template if you would like a starting point.