Practice management platforms such as Clio support a wide range of connected apps: calendars, e-signature, accounting, intake forms, document automation, payment processing and AI assistants. Each one can save time. Each one is also a new route to client data, run by a company your firm may know very little about.
Connecting an app is often a matter of a few clicks and a permission screen. That ease makes it important to have a simple vetting process, so convenience does not outrun judgment.
What Happens When You Connect an App
When a user authorizes an integration, they typically grant the app permission to read and sometimes change data in the platform. Depending on the settings, that may include contacts, matters, documents, calendar entries, billing records and notes. The app then holds access until someone revokes it, even if the user who connected it has forgotten about it.
Because these apps hold privileges on your behalf, they fall within the scope of reasonable safeguards discussed in Model Rule 1.6(c) and, when provided by outside vendors, supervisory duties like those in Rule 5.3. Confirm local expectations with your state bar.
A Practical Vetting Process
Step 1: Define the business need
Ask why the app is wanted, who will use it and what problem it solves. If an existing, approved tool does the same job, use it.
Step 2: Review what data it can access
Look at the permissions the app requests. Does a scheduling tool need access to billing records? Does a document tool need all matters, or only some? Prefer apps that request the least access necessary.
Step 3: Ask the vendor security questions
Request written answers to these:
- Where is our data stored and for how long?
- Is data encrypted in transit and at rest?
- Is our data used to train AI models or shared with third parties?
- What independent security assessments exist?
- How do you handle breach notification?
- How can we delete our data and revoke access?
- Which subcontractors process our data?
Step 4: Review the terms
Read the privacy policy and agreement for data ownership, confidentiality, liability and what happens at termination. Have someone with legal training look at anything unusual.
Step 5: Check the company
Consider how long the vendor has existed, who owns it, how it is funded and whether it has had security incidents. Small startups can be excellent, but ask what happens to your data if the company closes or is acquired.
Step 6: Pilot with limited scope
Try the app with a small group or with test data first. Confirm it behaves as described and does not create unexpected sharing.
Step 7: Approve and record
Add it to a list of approved integrations, noting the owner, the purpose, the data it accesses and the review date.
Controlling Integrations Technically
- Restrict who can connect apps. Limit authorization to administrators where the platform allows.
- Use single sign-on and multi-factor authentication for the platform itself, so a stolen password cannot approve new apps.
- Review connected apps quarterly and remove unused ones.
- Watch for dormant access. An integration unused for months should be revoked.
- Document owners. Every app should have a named person responsible for it.
Red Flags
- An app requesting broad permissions for a narrow function.
- No clear privacy policy or security documentation.
- Inability to explain how data is deleted.
- Pressure to connect immediately without review.
- Apps that ask for your login credentials directly instead of using standard authorization.
Special Considerations for AI Features
AI assistants and summarizers are among the fastest-growing integration categories. They may send client text to outside model providers. ABA Formal Opinion 512 discusses confidentiality and informed consent in connection with generative AI tools. Ask any AI vendor exactly where content goes and whether it is retained or used for training.
Offboarding and Exit Plans
When you remove an integration, revoke its access in the platform, confirm the vendor deleted your data, and keep a record. Likewise, when an employee who authorized an app leaves, review the apps connected under their account.
How Counsel Cyber Helps
Counsel Cyber helps firms review their practice-management settings, audit connected apps and build lightweight approval processes. If you are not sure which apps are connected to your platform right now, we can help you find out.