Law firm access governance

Multi-Office Law Firm Permissions and Governance Guide

Design permissions and governance for a multi-office law firm, including global identity, office and practice scopes, matter roles, ethical walls, external users, joiner-mover-leaver controls, privileged administration, recertification, audit, emergency access, RACI, and testing.

Direct answer

A multi-office law firm should separate global identity from access scope, then combine office, practice, matter, and user roles with least-privilege defaults. Define ethical walls, cross-office collaboration, approved local exceptions, external-user limits, joiner-mover-leaver controls, privileged administration, emergency access, recertification, and audit evidence as one governed model. Test permitted and denied paths with representative matters, document every exception, and have qualified professionals confirm the rules for each applicable jurisdiction.

Definitions

Global identity

The authoritative person record used to recognize one individual across offices, practices, systems, and assignments without creating separate identities that can drift apart.

Access scope

The boundary that limits what a user can discover, view, edit, share, export, administer, or report on, such as an office, practice, matter, record type, or external workspace.

Matter role

A named responsibility on a matter, such as matter lead, working team member, reviewer, billing contact, client liaison, or read-only stakeholder, with defined actions and data visibility.

Ethical wall

A documented restriction intended to prevent unauthorized people from accessing protected matter information when conflicts, confidentiality, independence, or firm policy requires separation.

Local exception

A time-bound and approved departure from the default permission model for a particular office, practice, matter, user, role, or regulatory requirement.

External user

A person outside the firm, such as a client contact, co-counsel, expert, auditor, or service provider, who receives a deliberately limited access path to defined records or actions.

Joiner-mover-leaver control

The lifecycle process that provisions, changes, reviews, suspends, and removes access when a person joins, changes role or office, takes leave, or leaves the firm.

Privileged administrator

A user with elevated authority to change identities, roles, policies, integrations, audit settings, or other controls that can affect many records or users.

Access recertification

A documented periodic review in which accountable owners confirm that current access remains necessary, appropriate, and supported by the underlying role or assignment.

Emergency access

A controlled, exceptional access path used for an urgent operational, security, client-protection, or continuity need, with approval, time limits, logging, and retrospective review.

RACI

A responsibility model that identifies who is responsible, accountable, consulted, and informed for an access decision, control, review, exception, or incident.

Practical workflow

  1. Establish one global identity record

    Choose the authoritative identity source and stable person identifier. Link office, practice, employment status, professional role, manager, location, and system accounts to that identity. Prevent duplicate local accounts from becoming an alternate route around suspension, recertification, or ethical-wall controls.

  2. Define the permission hierarchy

    Separate firm-wide capabilities from office, practice, matter, record, and action scopes. Document which roles may discover, view, edit, share, export, delete, approve, report, or administer each class of record. Start from deny-by-default or minimum necessary access and make inheritance visible.

  3. Map office, practice, and matter roles

    Define the difference between an office role, practice-group role, and matter role. A person may belong to one office, support another, and work on matters led by a third. Test how conflicting memberships resolve, which scope wins, and whether a role grants visibility without granting edit or export rights.

  4. Separate global identity from matter confidentiality

    Keep person identity and employment facts globally authoritative while applying matter-specific confidentiality, client, party, and ethical-wall restrictions at the matter or record layer. Verify that global search, directory displays, notifications, reports, APIs, and exports do not reveal protected matter content.

  5. Design ethical walls and conflict restrictions

    Define the trigger, protected population, excluded population, restricted records, notification behavior, approval authority, review date, and evidence for each wall. Test discovery, search, previews, downloads, shared links, email filing, reports, integrations, administrator access, and changes to the matter team or wall status.

  6. Enable controlled cross-office collaboration

    Create an approved collaboration pattern for matters spanning offices or practices. Identify the matter owner, participating teams, permitted data, client or engagement limits, reporting scope, and end date. Make collaboration explicit rather than relying on broad firm-wide visibility or copied documents.

  7. Govern local exceptions

    Allow local rules only where a documented business, professional, regulatory, client, or contractual reason exists. Require an accountable approver, affected scope, compensating control, start and expiry dates, review owner, and evidence. Preserve the default policy and original role so exceptions can be removed cleanly.

  8. Control external-user access

    Give clients, co-counsel, experts, auditors, and service providers separate external identities and matter-scoped permissions. Require identity proofing or an approved invitation process, explicit content selection, authentication, expiry, revocation, download and sharing controls, notification review, and a test that one external user cannot pivot into another matter.

  9. Run joiner, mover, and leaver workflows

    Connect HR or identity events to provisioning, approval, role changes, office transfers, leave, suspension, and departure. Recalculate inherited and direct grants when a person moves, preserve matter handoff evidence, disable sessions and tokens when required, and confirm that former users cannot retain access through shared links, delegated accounts, or integrations.

  10. Protect privileged administration

    Separate day-to-day work from policy and platform administration. Use individual administrator identities, strong authentication, just-in-time or time-bound elevation where practical, separation of duties, approval for high-impact changes, restricted support access, immutable or protected logs, and regular review of administrative actions.

  11. Define emergency access

    Specify the events that justify emergency access, who can approve it, which minimum scope is available, how long it lasts, what the user must record, and how the access is reviewed afterward. Test a real emergency path and a denied request, including notification, evidence capture, expiry, and investigation of any use outside the approved reason.

  12. Recertify access and review audit evidence

    Set review cadences for firm, office, practice, matter, external, and privileged access. Send managers, matter owners, records or risk owners, and system owners the grants they must confirm. Record decisions, removals, exceptions, non-responses, evidence, and follow-up. Review access changes, denied attempts, exports, privilege elevation, and emergency use for anomalies.

  13. Assign governance RACI and change control

    Name the accountable owner for identity, role design, ethical walls, local exceptions, matter access, external users, privileged administration, audit, incident response, and recertification. Require change requests to identify impact, affected jurisdictions, testing evidence, approvers, communication, rollback, and the date for post-change review.

  14. Test the complete permission model

    Use an authorization matrix and representative accounts to test allowed, denied, inherited, direct, exceptional, expired, suspended, and emergency paths. Cover office and practice changes, ethical walls, cross-office matters, external users, administrator actions, search and notifications, APIs and exports, audit records, and recovery after a failed change.

Comparison

Control areaOver-broad patternGoverned design
IdentityEach office creates separate accounts with inconsistent status and ownership.One authoritative global identity is linked to approved system accounts, assignments, and lifecycle events.
Role scopeFirm, office, practice, and matter access are mixed into a single broad role.Roles are separated by scope and action, with visible inheritance and minimum necessary defaults.
Ethical wallsA hidden folder convention is treated as proof that a conflict restriction works.The wall has a trigger, excluded users, protected records, approval, expiry or review, tested deny paths, and audit evidence.
Cross-office workAll offices receive default visibility so teams can collaborate informally.Approved collaboration grants only the matter data, actions, participants, and duration needed for the work.
Local exceptionsLocal administrators change access without preserving the reason or expiry.Exceptions are attributable, approved, time-bound, compensating-controlled, and included in recertification.
External usersA client or co-counsel account mirrors an internal team role.External identities use separate, matter-scoped permissions with expiry, revocation, and sharing controls.
AdministrationShared administrator credentials can change policy without individual attribution.Privileged work uses named identities, strong authentication, separation of duties, elevation controls, and protected audit logs.
ReviewAccess is granted once and removed only after someone reports a problem.Joiner-mover-leaver events, scheduled recertification, audit review, and exception expiry drive continuous correction.

Limitations and exceptions

  • The ABA Model Rules are model rules, not a universal code that automatically applies to every lawyer or firm. State, federal, tribal, national, provincial, and professional-body rules may differ or impose additional duties.
  • SRA standards and guidance apply in the context of solicitors and firms regulated by the SRA in England and Wales. They should not be treated as a substitute for the rules of another jurisdiction.
  • An access-control configuration does not decide whether a conflict exists, whether an ethical wall is sufficient, whether privilege applies, or whether a disclosure is permitted. Qualified professionals must make those decisions.
  • A global identity model must account for local employment, licensing, data-protection, labor, client, court, and records requirements. Central administration does not remove local accountability.
  • Role-based access is only one layer of control. Shared links, search indexes, notifications, exports, integrations, backups, support access, devices, and copied files can create alternate disclosure paths.
  • Emergency access can protect continuity but can also bypass ordinary separation. It requires a narrow scope, explicit reason, attributable approval, short duration, protected logs, and retrospective review.
  • Recertification confirms a decision at a point in time; it does not prove that every rule, integration, inherited grant, or downstream copy enforced the decision continuously.
  • NIST frameworks and control catalogs are adaptable security references, not legal standards or a security certification. The firm must choose controls proportionate to its risks and obligations.
  • This guide is an access-governance framework and case-management evaluation aid, not legal advice, a professional-responsibility opinion, or a guarantee that a particular software configuration will satisfy a jurisdiction.

Primary sources

ABA Model Rule 1.6: Confidentiality of InformationABA model rule addressing information relating to a client representation and the circumstances in which disclosure is or is not permitted.ABA Model Rule 1.10: Imputation of Conflicts of InterestABA model rule providing a reference for conflicts imputed among lawyers associated in a firm and for screening and notice considerations.ABA Model Rule 5.1: Responsibilities of a Partner or Supervisory LawyerABA model rule relevant to managerial and supervisory measures that give reasonable assurance of professional-conduct compliance.ABA Model Rule 1.1, Comment [8]: Maintaining CompetenceABA commentary identifying the benefits and risks associated with relevant technology as part of maintaining competence.ABA Formal Opinion 477R: Securing Communication of Protected Client InformationABA ethics guidance on reasonable efforts to prevent inadvertent or unauthorized access when protected client information is communicated electronically.NIST Cybersecurity Framework 2.0NIST framework for managing and communicating cybersecurity risk through outcomes that can be adapted to organizations of different sizes and maturities.NIST SP 800-53 Rev. 5, Security and Privacy ControlsNIST control catalog covering access control, least privilege, identification and authentication, audit and accountability, incident response, and assessment.SRA: Confidentiality of Client InformationSRA guidance on the continuing duty to protect client information and the need to consider confidentiality when handling information and access.SRA Code of Conduct for FirmsSRA standards for firms regulated by it, including business controls and the culture and environment for competent and ethical legal services.

Methodology

Start with the firm operating model and the decisions that access must support: who may work on a matter, who may supervise or approve, who may collaborate across offices, who may act externally, who may administer the system, and what evidence is needed after an access event. Build a permission matrix with rows for identity, role, office, practice, matter, record type, action, external status, lifecycle state, and exception state. Distinguish direct grants from inherited grants, and distinguish global identity attributes from matter-specific confidentiality. Define default roles, ethical-wall rules, collaboration patterns, local exceptions, emergency access, privileged operations, joiner-mover-leaver triggers, recertification cadence, audit events, and RACI ownership before configuring software. For each rule, record the source policy, jurisdiction or client constraint, approver, expiry or review date, compensating control, and expected evidence. Test ordinary, denied, inherited, changed, expired, suspended, external, emergency, and administrator paths using representative offices, practices, matter types, parties, documents, reports, notifications, APIs, and exports. Review false allows and false denies separately, reconcile the permission matrix to actual grants, sample audit logs, and require sign-off from legal, information security, operations, records, and accountable matter owners. Pilot high-risk workflows first, monitor exceptions and failed lifecycle events after launch, and update the model when the firm, system, clients, professional rules, or jurisdictions change. This is an organization-designed governance method, not a universal legal rule or certification test.

Contact

Map your law firm permissions and matter governance

Reach out and learn more about our offerings and how CaseDocker can help you

Built for legal operations teams

Share your use case and we will connect you with the right team for product guidance, pricing, and rollout planning.

Clear next steps

Expect a response from our team with the most relevant next step for your inquiry.

Get in Touch

Get in Touch

We usually reply quickly

FAQs

Use one authoritative identity for each person and attach office, practice, employment, professional role, manager, and system-account attributes to it. Keep matter access separate from the identity record. When someone changes office or role, recalculate direct and inherited permissions from the new assignment, preserve the handoff evidence, and disable obsolete sessions, tokens, invitations, and delegated access.

Usually no. Office and practice membership can support default routing, directory visibility, or limited reporting, but matter access should still depend on an approved matter role, client or confidentiality restrictions, and any ethical wall. If a firm intentionally grants broader visibility, document the reason, permitted actions, risks, review owner, and test evidence rather than treating it as an invisible default.

Use named test accounts on both sides of a representative wall. Verify allowed users can perform the required work while excluded users cannot discover, search, preview, open, download, share, receive notifications about, report on, or reach the protected content through an API or integration. Change the matter team, wall status, and administrator context, then review the audit evidence, expiry behavior, and approved exception path.

Record the reason, affected jurisdiction, office, practice, matter, user, records, actions, approver, start date, expiry or review date, compensating control, owner, and evidence. Preserve the default grant and the original role so the exception can be removed without guessing. Review recurring exceptions as a signal that the baseline role, matter model, or policy may need redesign.

Give each external person a separate identity and a narrow matter-scoped role. Require an approved invitation or identity-verification process, strong authentication where appropriate, explicit document or action selection, expiration, revocation, download and sharing controls, and review of notifications and search. Test the same email address or person across multiple matters to confirm that one engagement does not expose another.

It should cover initial provisioning, manager and role approval, office or practice changes, temporary leave, suspension, departure, token and session revocation, shared links, delegated access, external invitations, matter reassignment, privileged roles, and integrations. Test both the identity event and the resulting effective permissions. Record exceptions when an account must remain available for handoff, preservation, investigation, or continuity.

Use individual administrator identities, strong authentication, least privilege, separation of duties, approval or just-in-time elevation for high-impact changes, and protected logs that capture who changed what and why. Keep support access separate from matter work, restrict access to protected content, review administrator activity, and ensure no shared credential or undocumented service account can bypass the firm policy.

Set the cadence by risk and change frequency. Privileged, external, ethical-wall, and high-sensitivity matter access may need more frequent review than stable low-risk roles. At minimum, trigger review after joiner-mover-leaver events, matter closure, role or office changes, incidents, and policy changes. Every review should record the owner, grants considered, decision, removals, exceptions, non-responses, evidence, and follow-up date.

Related CaseDocker capabilities

Case management and matter workspaces

Connect matters, people, documents, tasks, dates, and activity so access decisions can be evaluated in the context of daily case-management work.

Explore

Legal workflow playbooks

Structure intake, approvals, escalations, recurring controls, and exception handling around permission and governance workflows.

Explore

Legal case management information

Review the broader case-management operating model when mapping roles, matter records, collaboration, reporting, and adoption requirements.

Explore

Turn this guide into an operating plan

Share your current legal workflow and CaseDocker can map the right modules, integrations, controls, and rollout sequence.

Book a walkthrough