Cybersecurity

    Ethical Walls for Law Firms: What Actually Enforces Them

    Written by Mauro GonzalezClio Certified Consultant10+ Years in Legal TechnologyLast updated:

    An ethical wall is only real if a system refuses the access. A policy that says a screened lawyer will not open a matter is a statement of intent, and intent is not what a client's outside counsel guidelines are asking about. Big Mode Consulting configures screening across document management, email, and collaboration tools, and the place these fail is almost never the document system. It is the seam between systems, where a wall in one place does not follow the matter into another.

    Mauro Gonzalez12 min readAugust 2026

    What a wall has to cover

    A screen is only as good as its weakest surface, and firms routinely secure one surface thoroughly while leaving three others open. Work through all of them before telling a client the wall is up.

    The document management system

    The surface everyone secures first, and usually the one that is genuinely correct. Native matter level security in a legal DMS is designed for exactly this, so it tends to hold.

    Email, including the archive nobody is looking at

    The mailbox, distribution lists, shared mailboxes, and any journaling or archive copy. A screened person does not have to search for anything to end up with matter content in their inbox. Someone hits reply all.

    The matter record in practice management

    Notes, calendar entries, task assignments, contact records. Even where the documents are locked, the matter record often narrates what the documents contain.

    Collaboration tools

    Teams channels, shared drives, chat threads, and the file sharing links that were created for a client and never expired. Screening these is a separate configuration from screening the DMS, and it is regularly skipped.

    Time and billing, the one people forget

    Narrative time entries describe the substance of the work in detail, and a screened timekeeper browsing matter lists or running a report can read a great deal of it. Prebills circulate widely inside a firm. This is the surface that surprises people during an audit.

    Why walls fail at the seams

    A barrier configured in the document management system does not propagate to email unless somebody deliberately extended it there. Two systems, two permission models, two admin consoles, two sets of assumptions about what a group means. The configuration is correct on the day it is made and starts drifting the following month, when a team changes, a system is upgraded, or someone creates a channel for a matter that already had a screen on it.

    The failure is rarely a breach. Nobody reads the file. What happens is subtler and harder to answer for: a screened person had a path to the material and the firm cannot demonstrate they never took it. Ask a partner to prove a negative six months after the fact and watch what happens.

    Head to head detail on how specific document platforms handle this sits in our comparisons of NetDocuments and iManage and iManage and SharePoint.

    Permissions are not screening

    Matter level permissions answer one question. Who can open this record. Useful, necessary, and not the same thing as a screen, because screening in the ethics sense carries three further requirements that a permission setting on its own does not satisfy: the access has to be actively denied rather than merely unpublished, the denial has to hold in every system where the matter has a footprint, and the whole arrangement has to leave a record somebody can read later.

    Model Rule 1.0(k) supplies the definition, describing screening as isolating a person from participation through timely measures reasonably adequate to protect the information. Note the words timely and reasonably adequate. Both are judged after the fact, by someone who was not in the room when the decision was made.

    Model Rule 1.10 governs when a conflict is imputed across a firm and when a screen is the mechanism that lets the firm keep the matter after a lateral hire arrives. Model Rule 1.18 covers the prospective client who told you enough to create a duty and then went elsewhere. Both rules assume the screen is real.

    What different systems can actually do

    Think in classes of product rather than feature checklists, because feature lists change with every release and the class characteristics do not.

    Dedicated legal document management

    Built around the matter as the unit of security, so restricting a matter to a defined group is a native operation rather than an assembly job. This class is where most firms already have a defensible barrier, and the NetDocuments and iManage comparison covers how the two leading options differ.

    General collaboration platforms

    A platform such as SharePoint can be configured to approximate matter level restriction using its general permission model. It was not designed for legal screening, so the result depends heavily on how it was built and how disciplined the firm stays afterward. More configuration risk. More ongoing maintenance. Our iManage versus SharePoint comparison goes into the tradeoff.

    Practice management platforms

    Typically offer matter level permissions rather than screening with the audit and attestation layer a compliance reviewer expects. Fine for a small number of screens. Thinner once a firm has to evidence them at scale.

    Enterprise risk and governance products

    This category exists specifically to enforce barriers across several systems at once and to report on them centrally. Firms end up here when they run multiple systems and carry an obligation to prove compliance rather than assert it. See the Clio versus Intapp comparison for how that category compares to a practice management approach.

    Proving it, which is the part that gets skipped

    Admin reporting and audit trails do not exist for internal comfort. They exist because somebody outside the firm will eventually ask, and the asking tends to arrive at an inconvenient moment. A client working through a security questionnaire before expanding a relationship. An insurer at renewal. Opposing counsel drafting a disqualification motion who would very much like the answer to be no.

    A screen you cannot evidence is functionally a screen you did not have.

    Evidence means access logs covering both successful and denied attempts, a dated attestation recording that the screen was applied and by whom, a report listing the people excluded and the matters they were excluded from, and enough retention that the report still exists when the question arrives two years later. Getting this out of one system is straightforward. Getting a single coherent answer out of four is the work.

    The plumbing underneath

    • Single sign on with SAML, so identity lives in one directory instead of being re-created per system with slightly different membership each time.
    • Role based access, so a screen is applied to a group rather than reapplied person by person and forgotten on the sixth system.
    • Directory groups that are actually maintained when someone moves practice groups, changes assistants, or comes off secondment. Stale group membership is the single most common way a correctly built wall quietly stops working.
    • Admin reporting that a compliance reviewer can read without asking IT to run a query.

    When a lateral hire arrives

    This is the trigger event for most firms, and the sequence matters more than the tooling.

    1. 1Identify the conflict before the start date. Screening applied after someone already has a laptop and a login is the version that is hard to defend.
    2. 2Apply the screen before system access is granted, not as a cleanup task in the first week.
    3. 3Document the date the screen was applied and who applied it.
    4. 4Give whatever notice the rules and the client's guidelines require.
    5. 5Check every surface listed above, not only the document system.
    6. 6Put the screen on the calendar for review, because the firm will change systems before the matter closes.

    How this gets licensed

    Screening capability is frequently packaged as an add on module or reserved for a higher tier rather than included in a base license, and governance products that enforce barriers across systems are usually licensed separately from the systems they govern. Ask where the capability sits in the vendor's packaging before you ask what it costs, because the answer to the second question depends entirely on the first.

    What actually surprises firms is not the license line. It is the configuration work, the directory cleanup that turns out to be a prerequisite, and the ongoing maintenance of group membership that nobody scoped because it does not look like a project. Budget for the second year, not only the first. More on the wider security posture this fits into sits in our cybersecurity basics for law firms guide and our security services.

    Can you prove the screen held?

    We configure and audit screening across document management, email, and collaboration tools, and we will tell you where your current setup has a seam.

    Frequently Asked Questions

    An ethical wall, also called an information barrier or a screen, is a set of controls that keeps a specific lawyer or staff member away from a specific matter. Model Rule 1.0(k) defines screening as the isolation of a person from participation in a matter through timely measures reasonably adequate to protect information that person is obligated to protect. The working definition inside a firm is narrower. A system has to refuse the access, and someone has to be able to show later that it did.

    Matter level permissions control who can open a record. That is one ingredient. A screen in the ethics sense also requires that the denial hold everywhere the matter lives rather than in one system, that it be applied at the right moment rather than after work has already started, and that it produce a record. A firm can have permissions on every matter and still have no defensible screen.

    SharePoint can be configured to restrict access at a site, library, or item level, and firms do build screening on top of it. It was not designed as a legal screening product, so the barrier is assembled from general purpose permission features rather than a native matter security model. That means more configuration up front, more places for the configuration to drift, and more work to produce the reporting an outside party will ask for. Firms with several screened matters and a compliance obligation generally find the maintenance load is the deciding factor rather than whether it is technically possible.

    Yes. Email carries the same client confidences as the document system and usually more of the informal reasoning. A screen that stops at the document management system leaves the mailbox, distribution lists, any journaling or archive copy, and forwarded threads outside the barrier. Email is also where a screened person is most likely to receive matter content passively, without ever going looking for it.

    With records rather than recollection. Access logs showing attempts and denials, an attestation that the screen was applied and the date it was applied, the list of who was excluded from what, and an admin report a non technical reviewer can read. Firms are usually asked for this by a client running a security questionnaire, an insurer at renewal, or opposing counsel in a disqualification fight. Build the evidence path when you build the wall.

    A lateral hire who worked on a matter adverse to one of yours is the common trigger, which is the situation Model Rule 1.10 addresses when it sets out when a firm can keep a matter despite an imputed conflict. Model Rule 1.18 covers duties owed to a prospective client who shared information and then did not retain you. Adverse or related matters run inside the same firm are another. So is a client that simply requires screening in its outside counsel guidelines, whether or not the rules would compel it.

    A named person, and not the person who happens to be free that week. Ownership means someone reviews group membership when people change teams, confirms the screen is still applied when a system is upgraded or replaced, and can produce the report on request without a project. Screens fail quietly, so the owner matters more than the initial configuration.

    About the Author

    Mauro Gonzalez is the founder of Big Mode Consulting with over a decade of experience in legal technology and enterprise IT. As a Clio Certified Consultant and Filevine implementation specialist, he has helped 50+ law firms modernize their technology stacks. He specializes in case management implementation, managed IT services, and ABA-compliant cybersecurity solutions.