Skip to main content
LexLogik LogoLexLogik

Insights for law firms

Access control in the shared workspace for matter documents

By Clemens Jonathan Schmid and Jonas Maximilian Regul

Shared folders need roles - or too many people see sensitive PDFs.

Shared workspaces speed handoffs between partner, associate and support. Without access control they also speed mis-access: the trainee opens the divorce matter next door, the IT contractor sees matter content in a support case, a former colleague keeps a link.

In the firm, access control is less a feature comparison than a roles question. Who may read, who edit, who approve, who delete - and for how long?

Roles that hold in practice

Separate at least: read access for people on the matter, edit access for the document chain, admin rights for a few people, and time-limited guests (instructed counsel, experts) with clear end dates. “Everyone in the firm can access the share” is convenient and risky.

Matter-based spaces beat theme-based mega-folders once parallel matters and conflicts sit in play. When someone leaves the matter, revoking access must be a standard step - like returning the key card.

Shared links and shadow access

An “anyone with the link” share bypasses carefully maintained groups. For matter PDFs that is rarely defensible. Prefer named accounts, expiry dates and, where possible, watermarked or traceable downloads. Chat attachments in private channels create shadow copies outside control.

LexLogik and similar processing tools should sit inside the same access logic as the DMS: no lasting deposit of sensitive files in personal cloud “just for a moment”.

Office managers and partners share the duty

Technical settings often sit with office management; the substantive call “who may see this matter” remains counsel’s responsibility. Keep a short matrix per matter type: who has default access, who decides exceptions, how cover is arranged.

Review orphaned shares and guest access quarterly. The list grows longer than expected - especially after large cases with many external parties.

What audits and client questions need

Clients increasingly ask who can access their materials. An honest, brief answer requires that you know. Document the model (not every click): matter spaces, roles, revocation on exit, ban on uncontrolled links.

External and temporary parties

Instructed counsel, experts and matter-related suppliers often need time-limited read access. Set expiry dates and actively remind before renewal. “Leave the link in case something else comes” is the most common path to orphaned visibility. Record who was opened into which space - useful for client questions and conflicts checks.

The same logic applies to scan and OCR intermediate steps: permission to upload a file need not mean lasting sight of the whole matter space. Separate processing rights from matter rights where the tool allows.

Access control costs a little friction day to day. Missing access protection costs trust and, in earnest, far more. Teams that make roles and revocation routine barely notice the friction - and avoid the emergency action after an incident.

Guest access and external counsel

External counsel get time-limited rights only to named matter folders, never the whole workspace. Office management revokes access the day after the agreed end - automatically or by checklist. Open guest rights are an audit classic.

Access control in a shared workspace works when cover staff can operate without full rights and guest accounts do not stay “temporary forever”. Fewer open rights mean fewer matters exposed in an incident.

10 days free

Try LexLogik in your practice

All features unlocked. No credit card. No automatic subscription.