An ethical wall is only real if a system refuses the access. A policy that says a screened lawyer will not open a matter is a statement of intent, and intent is not what a client's outside counsel guidelines are asking about. Big Mode Consulting configures screening across document management, email, and collaboration tools, and the place these fail is almost never the document system. It is the seam between systems, where a wall in one place does not follow the matter into another.
A screen is only as good as its weakest surface, and firms routinely secure one surface thoroughly while leaving three others open. Work through all of them before telling a client the wall is up.
The surface everyone secures first, and usually the one that is genuinely correct. Native matter level security in a legal DMS is designed for exactly this, so it tends to hold.
The mailbox, distribution lists, shared mailboxes, and any journaling or archive copy. A screened person does not have to search for anything to end up with matter content in their inbox. Someone hits reply all.
Notes, calendar entries, task assignments, contact records. Even where the documents are locked, the matter record often narrates what the documents contain.
Teams channels, shared drives, chat threads, and the file sharing links that were created for a client and never expired. Screening these is a separate configuration from screening the DMS, and it is regularly skipped.
Narrative time entries describe the substance of the work in detail, and a screened timekeeper browsing matter lists or running a report can read a great deal of it. Prebills circulate widely inside a firm. This is the surface that surprises people during an audit.
A barrier configured in the document management system does not propagate to email unless somebody deliberately extended it there. Two systems, two permission models, two admin consoles, two sets of assumptions about what a group means. The configuration is correct on the day it is made and starts drifting the following month, when a team changes, a system is upgraded, or someone creates a channel for a matter that already had a screen on it.
The failure is rarely a breach. Nobody reads the file. What happens is subtler and harder to answer for: a screened person had a path to the material and the firm cannot demonstrate they never took it. Ask a partner to prove a negative six months after the fact and watch what happens.
Head to head detail on how specific document platforms handle this sits in our comparisons of NetDocuments and iManage and iManage and SharePoint.
Matter level permissions answer one question. Who can open this record. Useful, necessary, and not the same thing as a screen, because screening in the ethics sense carries three further requirements that a permission setting on its own does not satisfy: the access has to be actively denied rather than merely unpublished, the denial has to hold in every system where the matter has a footprint, and the whole arrangement has to leave a record somebody can read later.
Model Rule 1.0(k) supplies the definition, describing screening as isolating a person from participation through timely measures reasonably adequate to protect the information. Note the words timely and reasonably adequate. Both are judged after the fact, by someone who was not in the room when the decision was made.
Model Rule 1.10 governs when a conflict is imputed across a firm and when a screen is the mechanism that lets the firm keep the matter after a lateral hire arrives. Model Rule 1.18 covers the prospective client who told you enough to create a duty and then went elsewhere. Both rules assume the screen is real.
Think in classes of product rather than feature checklists, because feature lists change with every release and the class characteristics do not.
Built around the matter as the unit of security, so restricting a matter to a defined group is a native operation rather than an assembly job. This class is where most firms already have a defensible barrier, and the NetDocuments and iManage comparison covers how the two leading options differ.
A platform such as SharePoint can be configured to approximate matter level restriction using its general permission model. It was not designed for legal screening, so the result depends heavily on how it was built and how disciplined the firm stays afterward. More configuration risk. More ongoing maintenance. Our iManage versus SharePoint comparison goes into the tradeoff.
Typically offer matter level permissions rather than screening with the audit and attestation layer a compliance reviewer expects. Fine for a small number of screens. Thinner once a firm has to evidence them at scale.
This category exists specifically to enforce barriers across several systems at once and to report on them centrally. Firms end up here when they run multiple systems and carry an obligation to prove compliance rather than assert it. See the Clio versus Intapp comparison for how that category compares to a practice management approach.
Admin reporting and audit trails do not exist for internal comfort. They exist because somebody outside the firm will eventually ask, and the asking tends to arrive at an inconvenient moment. A client working through a security questionnaire before expanding a relationship. An insurer at renewal. Opposing counsel drafting a disqualification motion who would very much like the answer to be no.
A screen you cannot evidence is functionally a screen you did not have.
Evidence means access logs covering both successful and denied attempts, a dated attestation recording that the screen was applied and by whom, a report listing the people excluded and the matters they were excluded from, and enough retention that the report still exists when the question arrives two years later. Getting this out of one system is straightforward. Getting a single coherent answer out of four is the work.
This is the trigger event for most firms, and the sequence matters more than the tooling.
Screening capability is frequently packaged as an add on module or reserved for a higher tier rather than included in a base license, and governance products that enforce barriers across systems are usually licensed separately from the systems they govern. Ask where the capability sits in the vendor's packaging before you ask what it costs, because the answer to the second question depends entirely on the first.
What actually surprises firms is not the license line. It is the configuration work, the directory cleanup that turns out to be a prerequisite, and the ongoing maintenance of group membership that nobody scoped because it does not look like a project. Budget for the second year, not only the first. More on the wider security posture this fits into sits in our cybersecurity basics for law firms guide and our security services.
We configure and audit screening across document management, email, and collaboration tools, and we will tell you where your current setup has a seam.
Mauro Gonzalez is the founder of Big Mode Consulting with over a decade of experience in legal technology and enterprise IT. As a Clio Certified Consultant and Filevine implementation specialist, he has helped 50+ law firms modernize their technology stacks. He specializes in case management implementation, managed IT services, and ABA-compliant cybersecurity solutions.