Every law firm has a story about a former employee whose account still worked months after they left, or a new associate who spent three days without a working laptop. Both come from the same cause: no repeatable process. Hiring and departures touch HR, IT, the managing partner, and the practice-management system, and when no one owns the checklist, things get missed.
A written onboarding and offboarding process is one of the cheapest security improvements a firm can make. It also supports supervision duties under ABA Model Rules 5.1 and 5.3 and answers questions that insurers and clients ask about access control.
Who owns it
Assign a single owner, typically the firm administrator or HR lead, who triggers the checklist and confirms completion. IT executes the technical steps. A department head or supervising attorney confirms what access the person needs.
Onboarding checklist
Before day one
- Receive the hire notice with start date, role, practice group, and supervisor, at least a week ahead.
- Create the user account with a unique identity. Avoid shared logins.
- Assign licenses and apps based on a role template, not by copying the last person's access.
- Set up multifactor authentication and enroll the user's device or hardware key on day one.
- Prepare a laptop with disk encryption, endpoint protection, and standard software already installed.
- Add the user to the correct groups for matters, shared mailboxes, and distribution lists.
Day one
- Walk through acceptable use, confidentiality, and the firm's AI and remote-work policies
- Collect a signed acknowledgment of the policies
- Assign security awareness training to be completed in the first week
- Demonstrate how to report a suspicious email or lost device
- Check that password manager and MFA work
First 30 days
- Review access with the supervisor: too little, too much?
- Confirm training completion
- Ask for feedback on what slowed them down
Offboarding checklist
Departures are higher risk, particularly when they are not friendly. Plan the timing with HR and a partner so access ends at the right moment, not hours later.
At the moment of departure
- Disable the account and revoke active sessions, tokens, and app passwords.
- Reset the password and remove MFA methods the person controls.
- Block mobile access, and remote wipe firm data on personal devices if policy allows.
- Collect laptops, phones, hardware keys, badges, and other equipment.
- Remove access to practice management, document management, billing, and any third-party portals, not just email.
Within a few days
- Convert the mailbox to a shared mailbox or set forwarding to a supervisor for a defined period, rather than deleting it
- Transfer ownership of files, shared folders, and calendar items
- Update shared passwords the person knew, and rotate keys or API credentials they managed
- Review recent download and sharing activity for anything unusual
- Reassign matters and notify clients where appropriate
Within 30 to 90 days
- Archive data according to your retention policy, then delete the license
- Wipe and reissue returned devices
- Audit that no accounts remain active, including those in vendor systems
Common misses
- Cloud tools with separate logins, such as e-filing portals, research subscriptions, and e-signature services
- Shared mailbox permissions and calendar delegations
- Personal cloud storage or personal email used for firm work
- Mobile devices syncing firm data after departure
- Third-party apps connected to the user's account
- Contractors and temporary staff, who are often left out of the process
Make it easier with a systems list
Keep a living list of every application that holds firm data and who administers it. At offboarding, walk through the list line by line. This list also helps with client questionnaires and insurance applications.
Use roles, not copies
Build role templates, such as attorney, paralegal, receptionist, and billing, with defined access. It reduces over-permissioning and makes onboarding faster.
Review quarterly
Compare the list of active accounts against current HR records. Look for accounts with no sign-in for 60 days, and shared accounts that no one can explain. Quarterly checks catch what the checklist missed.
Work with us
Counsel Cyber helps law firms turn these checklists into ticket templates and automations so the steps happen every time. If your firm's process currently lives in one person's head, we would be glad to help you document and test it.