Every law firm hires, promotes and loses people. Each of those events changes who should have access to what, and each is a chance for something to slip. A new associate waits three days for the right permissions. A departed paralegal still receives firm email on her phone six months later. A summer clerk's account is never disabled. These are not exotic failures. They are the everyday ways confidential information ends up in places it should not be.
A consistent checklist, owned by one person and triggered by HR or the managing partner, solves most of it. Below are practical lists you can adapt.
Why this matters for a law firm
Client confidentiality is the core obligation. Model Rule 1.6(c) speaks of reasonable efforts to prevent unauthorized access to client information. Prompt removal of departed users' access and appropriate limits for new users are among the most basic reasonable efforts a firm can show. Confirm the specifics with your state bar.
Onboarding checklist
Before day one
- Receive written notice from HR or the hiring partner with name, role, start date, supervising attorney and any practice groups.
- Create the user account with a unique login. Never share accounts or reuse a prior employee's.
- Assign licenses for Microsoft 365 and other core tools.
- Apply role-based access: only the matters, folders and groups the person needs. Resist copying another user's permissions wholesale.
- Order and configure the laptop with encryption, endpoint protection and management software.
- Prepare phone and desk setup if applicable.
On day one
- Require the person to set up multi-factor authentication before accessing anything else.
- Walk through the acceptable use policy and obtain a signed acknowledgment.
- Assign security awareness training and give a short in-person overview of how to report suspicious emails.
- Introduce the help desk process and contact details.
- Show how to access practice management and document systems, and how to save work in approved locations only.
Within the first month
- Confirm training completion.
- Ask the supervising attorney to verify that access matches the role.
- Revisit any temporary access granted to get started.
Offboarding checklist
Offboarding should begin before the last day when possible, and for involuntary departures it must be coordinated in advance so access is removed at the moment of notice.
At notice
- HR or the managing partner notifies IT in writing of the departing person and the effective date and time.
- Decide who will receive the person's mail, calendar and files. Never leave this undecided.
On the last day
- Disable the user account and revoke active sessions.
- Reset passwords for any shared accounts the person knew.
- Remove access from practice management, document management, e-filing, research tools and vendor portals.
- Remove the person from distribution lists, Teams channels and shared mailboxes.
- Recover laptop, phone, keys, badges and tokens. Wipe or reimage devices after confirming what must be preserved.
- Remove firm email and data from any personal phone, using managed device controls where available.
- Set automatic replies or forwarding for a defined, limited time.
After departure
- Preserve the mailbox and files as required by your retention policy or any legal hold. Do not delete immediately.
- Reassign matters and review pending deadlines.
- Confirm all accounts are closed by running a check against a master list of systems.
- Record the date and the person who completed each step.
Changes of role
Promotions, practice group moves and leaves of absence are access events too. Review permissions on each change rather than letting them accumulate. This is where "permission creep" develops.
Contractors, interns and temporary staff
Give them accounts with expiration dates set at creation. Short-term staff are among the most frequently forgotten users.
Audit the process
Once a quarter, compare the active user list against the current staff roster. Anything unaccounted for should be investigated. Also review the last three departures and check how quickly each step was completed.
Automate where you can
Identity tools can tie accounts to HR records, so that a role change triggers permission changes automatically. Even without automation, a ticket template with each step as a checkbox makes the process repeatable.
How Counsel Cyber can help
Counsel Cyber handles onboarding and offboarding for managed IT clients using documented checklists and quarterly access reviews. If you would like help building a version for your firm, we are glad to assist.