Law firm access governance
Multi-Office Law Firm Permissions and Governance Guide
Design permissions and governance for a multi-office law firm, including global identity, office and practice scopes, matter roles, ethical walls, external users, joiner-mover-leaver controls, privileged administration, recertification, audit, emergency access, RACI, and testing.
Direct answer
A multi-office law firm should separate global identity from access scope, then combine office, practice, matter, and user roles with least-privilege defaults. Define ethical walls, cross-office collaboration, approved local exceptions, external-user limits, joiner-mover-leaver controls, privileged administration, emergency access, recertification, and audit evidence as one governed model. Test permitted and denied paths with representative matters, document every exception, and have qualified professionals confirm the rules for each applicable jurisdiction.
Definitions
Global identity
The authoritative person record used to recognize one individual across offices, practices, systems, and assignments without creating separate identities that can drift apart.
Access scope
The boundary that limits what a user can discover, view, edit, share, export, administer, or report on, such as an office, practice, matter, record type, or external workspace.
Matter role
A named responsibility on a matter, such as matter lead, working team member, reviewer, billing contact, client liaison, or read-only stakeholder, with defined actions and data visibility.
Ethical wall
A documented restriction intended to prevent unauthorized people from accessing protected matter information when conflicts, confidentiality, independence, or firm policy requires separation.
Local exception
A time-bound and approved departure from the default permission model for a particular office, practice, matter, user, role, or regulatory requirement.
External user
A person outside the firm, such as a client contact, co-counsel, expert, auditor, or service provider, who receives a deliberately limited access path to defined records or actions.
Joiner-mover-leaver control
The lifecycle process that provisions, changes, reviews, suspends, and removes access when a person joins, changes role or office, takes leave, or leaves the firm.
Privileged administrator
A user with elevated authority to change identities, roles, policies, integrations, audit settings, or other controls that can affect many records or users.
Access recertification
A documented periodic review in which accountable owners confirm that current access remains necessary, appropriate, and supported by the underlying role or assignment.
Emergency access
A controlled, exceptional access path used for an urgent operational, security, client-protection, or continuity need, with approval, time limits, logging, and retrospective review.
RACI
A responsibility model that identifies who is responsible, accountable, consulted, and informed for an access decision, control, review, exception, or incident.
Practical workflow
Establish one global identity record
Choose the authoritative identity source and stable person identifier. Link office, practice, employment status, professional role, manager, location, and system accounts to that identity. Prevent duplicate local accounts from becoming an alternate route around suspension, recertification, or ethical-wall controls.
Define the permission hierarchy
Separate firm-wide capabilities from office, practice, matter, record, and action scopes. Document which roles may discover, view, edit, share, export, delete, approve, report, or administer each class of record. Start from deny-by-default or minimum necessary access and make inheritance visible.
Map office, practice, and matter roles
Define the difference between an office role, practice-group role, and matter role. A person may belong to one office, support another, and work on matters led by a third. Test how conflicting memberships resolve, which scope wins, and whether a role grants visibility without granting edit or export rights.
Separate global identity from matter confidentiality
Keep person identity and employment facts globally authoritative while applying matter-specific confidentiality, client, party, and ethical-wall restrictions at the matter or record layer. Verify that global search, directory displays, notifications, reports, APIs, and exports do not reveal protected matter content.
Design ethical walls and conflict restrictions
Define the trigger, protected population, excluded population, restricted records, notification behavior, approval authority, review date, and evidence for each wall. Test discovery, search, previews, downloads, shared links, email filing, reports, integrations, administrator access, and changes to the matter team or wall status.
Enable controlled cross-office collaboration
Create an approved collaboration pattern for matters spanning offices or practices. Identify the matter owner, participating teams, permitted data, client or engagement limits, reporting scope, and end date. Make collaboration explicit rather than relying on broad firm-wide visibility or copied documents.
Govern local exceptions
Allow local rules only where a documented business, professional, regulatory, client, or contractual reason exists. Require an accountable approver, affected scope, compensating control, start and expiry dates, review owner, and evidence. Preserve the default policy and original role so exceptions can be removed cleanly.
Control external-user access
Give clients, co-counsel, experts, auditors, and service providers separate external identities and matter-scoped permissions. Require identity proofing or an approved invitation process, explicit content selection, authentication, expiry, revocation, download and sharing controls, notification review, and a test that one external user cannot pivot into another matter.
Run joiner, mover, and leaver workflows
Connect HR or identity events to provisioning, approval, role changes, office transfers, leave, suspension, and departure. Recalculate inherited and direct grants when a person moves, preserve matter handoff evidence, disable sessions and tokens when required, and confirm that former users cannot retain access through shared links, delegated accounts, or integrations.
Protect privileged administration
Separate day-to-day work from policy and platform administration. Use individual administrator identities, strong authentication, just-in-time or time-bound elevation where practical, separation of duties, approval for high-impact changes, restricted support access, immutable or protected logs, and regular review of administrative actions.
Define emergency access
Specify the events that justify emergency access, who can approve it, which minimum scope is available, how long it lasts, what the user must record, and how the access is reviewed afterward. Test a real emergency path and a denied request, including notification, evidence capture, expiry, and investigation of any use outside the approved reason.
Recertify access and review audit evidence
Set review cadences for firm, office, practice, matter, external, and privileged access. Send managers, matter owners, records or risk owners, and system owners the grants they must confirm. Record decisions, removals, exceptions, non-responses, evidence, and follow-up. Review access changes, denied attempts, exports, privilege elevation, and emergency use for anomalies.
Assign governance RACI and change control
Name the accountable owner for identity, role design, ethical walls, local exceptions, matter access, external users, privileged administration, audit, incident response, and recertification. Require change requests to identify impact, affected jurisdictions, testing evidence, approvers, communication, rollback, and the date for post-change review.
Test the complete permission model
Use an authorization matrix and representative accounts to test allowed, denied, inherited, direct, exceptional, expired, suspended, and emergency paths. Cover office and practice changes, ethical walls, cross-office matters, external users, administrator actions, search and notifications, APIs and exports, audit records, and recovery after a failed change.
Comparison
| Control area | Over-broad pattern | Governed design |
|---|---|---|
| Identity | Each office creates separate accounts with inconsistent status and ownership. | One authoritative global identity is linked to approved system accounts, assignments, and lifecycle events. |
| Role scope | Firm, office, practice, and matter access are mixed into a single broad role. | Roles are separated by scope and action, with visible inheritance and minimum necessary defaults. |
| Ethical walls | A hidden folder convention is treated as proof that a conflict restriction works. | The wall has a trigger, excluded users, protected records, approval, expiry or review, tested deny paths, and audit evidence. |
| Cross-office work | All offices receive default visibility so teams can collaborate informally. | Approved collaboration grants only the matter data, actions, participants, and duration needed for the work. |
| Local exceptions | Local administrators change access without preserving the reason or expiry. | Exceptions are attributable, approved, time-bound, compensating-controlled, and included in recertification. |
| External users | A client or co-counsel account mirrors an internal team role. | External identities use separate, matter-scoped permissions with expiry, revocation, and sharing controls. |
| Administration | Shared administrator credentials can change policy without individual attribution. | Privileged work uses named identities, strong authentication, separation of duties, elevation controls, and protected audit logs. |
| Review | Access is granted once and removed only after someone reports a problem. | Joiner-mover-leaver events, scheduled recertification, audit review, and exception expiry drive continuous correction. |
Limitations and exceptions
- The ABA Model Rules are model rules, not a universal code that automatically applies to every lawyer or firm. State, federal, tribal, national, provincial, and professional-body rules may differ or impose additional duties.
- SRA standards and guidance apply in the context of solicitors and firms regulated by the SRA in England and Wales. They should not be treated as a substitute for the rules of another jurisdiction.
- An access-control configuration does not decide whether a conflict exists, whether an ethical wall is sufficient, whether privilege applies, or whether a disclosure is permitted. Qualified professionals must make those decisions.
- A global identity model must account for local employment, licensing, data-protection, labor, client, court, and records requirements. Central administration does not remove local accountability.
- Role-based access is only one layer of control. Shared links, search indexes, notifications, exports, integrations, backups, support access, devices, and copied files can create alternate disclosure paths.
- Emergency access can protect continuity but can also bypass ordinary separation. It requires a narrow scope, explicit reason, attributable approval, short duration, protected logs, and retrospective review.
- Recertification confirms a decision at a point in time; it does not prove that every rule, integration, inherited grant, or downstream copy enforced the decision continuously.
- NIST frameworks and control catalogs are adaptable security references, not legal standards or a security certification. The firm must choose controls proportionate to its risks and obligations.
- This guide is an access-governance framework and case-management evaluation aid, not legal advice, a professional-responsibility opinion, or a guarantee that a particular software configuration will satisfy a jurisdiction.
Primary sources
Methodology
Start with the firm operating model and the decisions that access must support: who may work on a matter, who may supervise or approve, who may collaborate across offices, who may act externally, who may administer the system, and what evidence is needed after an access event. Build a permission matrix with rows for identity, role, office, practice, matter, record type, action, external status, lifecycle state, and exception state. Distinguish direct grants from inherited grants, and distinguish global identity attributes from matter-specific confidentiality. Define default roles, ethical-wall rules, collaboration patterns, local exceptions, emergency access, privileged operations, joiner-mover-leaver triggers, recertification cadence, audit events, and RACI ownership before configuring software. For each rule, record the source policy, jurisdiction or client constraint, approver, expiry or review date, compensating control, and expected evidence. Test ordinary, denied, inherited, changed, expired, suspended, external, emergency, and administrator paths using representative offices, practices, matter types, parties, documents, reports, notifications, APIs, and exports. Review false allows and false denies separately, reconcile the permission matrix to actual grants, sample audit logs, and require sign-off from legal, information security, operations, records, and accountable matter owners. Pilot high-risk workflows first, monitor exceptions and failed lifecycle events after launch, and update the model when the firm, system, clients, professional rules, or jurisdictions change. This is an organization-designed governance method, not a universal legal rule or certification test.
Map your law firm permissions and matter governance
Reach out and learn more about our offerings and how CaseDocker can help you
Built for legal operations teams
Share your use case and we will connect you with the right team for product guidance, pricing, and rollout planning.
Clear next steps
Expect a response from our team with the most relevant next step for your inquiry.
Get in Touch
Get in Touch
FAQs
Related CaseDocker capabilities
Case management and matter workspaces
Connect matters, people, documents, tasks, dates, and activity so access decisions can be evaluated in the context of daily case-management work.
ExploreLegal workflow playbooks
Structure intake, approvals, escalations, recurring controls, and exception handling around permission and governance workflows.
ExploreLegal case management information
Review the broader case-management operating model when mapping roles, matter records, collaboration, reporting, and adoption requirements.
ExploreTurn this guide into an operating plan
Share your current legal workflow and CaseDocker can map the right modules, integrations, controls, and rollout sequence.
