ContractorsOffboardingLifecycle

Revoking Contractor Access at a Legal Tech Startup: Case Files, Client Portals, and Matter Systems

How legal tech startups and law firms should revoke contractor access to Clio, Filevine, Relativity, and client portals — before a departing contractor walks away with privileged data.

8 min read

Revoking Contractor Access at a Legal Tech Startup: Case Files, Client Portals, and Matter Systems

When a contractor leaves a legal tech startup or law firm, the access risk is different from every other industry. It's not just a Figma seat or a Slack channel — it's case files, client portals, and matter systems that carry attorney-client privilege. A departing paralegal contractor who still has Clio access three weeks later isn't just a security gap; it may be an ethics violation. Here's how to do it right.

Why Legal Tech Access Revocation Is a Different Problem

At most startups, offboarding a contractor is an operational inconvenience — revoke Slack, remove Figma, update the password manager. At a legal tech startup or law firm, it's a professional obligation.

Three things make it different:

Attorney-client privilege survives on local machines. A contractor who downloaded case documents or client communications to their personal laptop retains copies even after their Clio or Filevine access is removed. The access revocation step fixes the ongoing access problem; it doesn't recover what's already been downloaded. Your offboarding process needs to address both.

Bar rules govern data access timelines. Most state bars have technology competence obligations (Model Rule 1.1, comment 8 in the US; similar provisions in other jurisdictions) that extend to third-party contractors handling client data. An attorney who lets a departed contractor retain client-portal access for weeks is exposing the firm to disciplinary action, not just a data breach.

Matter system audit trails matter legally. When a contractor accesses a case file on their last week, that access is logged in your matter system. If that case later goes to litigation or audit, the log entry can be discoverable. Running a clean, timestamped access revocation — and documenting it — is part of your defensible record.

The stakes are higher. The process needs to match.

Case Management Systems: Clio, MyCase, and Filevine

Case management systems are the core data layer. They hold matter records, client contact information, billing data, and document history. Contractor access to these platforms needs to be addressed first.

Clio (Manage and Grow): Go to Settings → Users → locate the contractor's user account → Deactivate. Deactivating removes login access but preserves their work history in the audit log. Do not delete the user — deleted users create orphaned records. Before deactivating, reassign any open tasks and matter responsibilities to an active team member. Check whether the contractor had a Clio Grow (client intake) account separately; the two product lines have different user management panels.

MyCase: Navigate to Settings → Users and Permissions → find the contractor → set their status to Inactive. MyCase does not support granular permission scoping at the per-matter level on most plans, so deactivation is the only reliable revocation step. Verify that any shared document folders the contractor created still have at least one active admin who can manage them.

Filevine: Filevine uses team-based access rather than individual permissions. Go to Admin → Team Management → remove the contractor from all project teams they belong to. Then go to User Management and deactivate their account. Note: Filevine's project history retains all actions taken by the contractor — this is the audit trail you want. Export a user-activity report for the contractor before deactivating if you need a snapshot for compliance documentation.

All case management systems: After deactivating, verify that any API tokens or integrations the contractor set up under their account are also revoked. Case management platforms often allow third-party app connections (e-signature tools, billing integrations) that remain active even after the user is deactivated.

Document Review Platforms and Matter Systems

If your legal tech startup handles eDiscovery, litigation support, or large-scale document review, you likely have contractor access to platforms like Relativity, Everlaw, or Logikcull — and these carry a higher risk than general case management tools, because document review contractors often work with large volumes of privileged material over compressed timelines.

Relativity (RelativityOne): Relativity uses workspace-level access. An admin needs to navigate to the relevant workspace → Workspace Details → Users → remove the contractor from the workspace. Do this for every workspace they had access to — contractors working across multiple matters may have access to several. If the contractor was using a Relativity Processing account for ingesting data, revoke that separately under the Processing Users section.

Everlaw: In Everlaw, go to Organization Settings → Users → locate the contractor and remove them from all case rooms they have access to. Everlaw sends an email confirmation when case room access is removed. Keep that confirmation as part of your offboarding record. Everlaw's audit log (available per case room) will show all document views and exports by that user — pull that log as part of your contractor exit documentation.

iManage and NetDocuments: If your firm uses iManage Work or NetDocuments for document management, contractor access typically flows through Active Directory or LDAP groups. Disabling the contractor's directory account should cascade to these platforms, but verify by checking their user status in the document management admin panel directly. iManage in particular has a history of session tokens persisting beyond account deactivation in older configurations — confirm with your IT contact or iManage admin.

Download exposure: For any document review engagement, ask the contractor directly (in writing) whether they downloaded any case documents to local storage. This creates a record of the question and any disclosure, which matters if the issue surfaces later. Most contractors don't download deliberately — but document review work sometimes involves local processing tools that cache files.

Client Portals and Secure Communication Tools

Client portals are where legal tech firms expose the most sensitive data to people outside the organization — and where contractor access is most easily overlooked during offboarding.

Built-in case management portals (Clio for Clients, MyCase Client Portal): These are usually controlled by the underlying user account in the case management system. Deactivating the contractor's main account (covered above) typically cuts off their ability to manage client portal communications, but it does not revoke access that clients themselves have. Check whether the contractor had individual clients linked to their Clio or MyCase profile who now need to be reassigned to an active staff member.

SharePoint and Box for shared client documents: If your firm uses SharePoint or Box for client file sharing, the contractor's access to shared links and folders may survive their departure — especially if they were shared using direct links rather than user-account permissions. Audit their shared links in Box Admin Console (Content → find user → Shared Links) or SharePoint Admin Center (Sharing → External content) and revoke or expire outstanding shares.

Encrypted email and secure messaging: Check whether the contractor was using a firm-provisioned encrypted email alias (Google Workspace or Microsoft 365 alias) for client communications. Disable those aliases and set up email forwarding to an active staff member so client replies don't go to a dead inbox. If the contractor used a personal email for any client communications (which should have been prohibited in their contract), document what you know and flag it with the supervising attorney.

E-signature platforms (DocuSign, Adobe Sign): If the contractor managed any pending signature workflows, reassign those envelopes to an active sender account before deactivating the contractor's access. A pending DocuSign envelope tied to a deactivated sender account will stop working for the recipient.

The Legal Tech Contractor Exit Checklist

Run this in order on the contractor's last working day, or before if you have advance notice of departure.

  1. Export the contractor's user activity log from your case management system before making any changes. This creates a timestamped record of what they accessed.
  2. Reassign open matters and tasks in Clio / MyCase / Filevine to an active staff member. Don't leave orphaned matter assignments.
  3. Deactivate the case management account (Clio, MyCase, Filevine — whichever applies). Deactivate; don't delete.
  4. Remove from all document review workspaces (Relativity, Everlaw, Logikcull). Download workspace access logs per matter.
  5. Remove from document management groups in iManage or NetDocuments. Verify session tokens are cleared.
  6. Revoke client portal management access and reassign orphaned client relationships.
  7. Audit shared links in SharePoint / Box. Expire or delete the contractor's outstanding shares.
  8. Disable firm email aliases and set forwarding to an active staff member.
  9. Reassign pending e-signature envelopes in DocuSign / Adobe Sign.
  10. Revoke API tokens and third-party app connections tied to the contractor's account.
  11. Send a written confirmation request asking whether the contractor retains any downloaded client materials, and retain their response.
  12. Document completion — record dates and person responsible for each step, and file it with the matter or HR record.

For general playbooks on structuring this kind of systematic access revocation, the contractor access revocation checklist for agencies and the access revocation policy template give a foundation you can adapt for legal-specific requirements.

The question of what access the contractor may have accumulated that you don't know about — shadow access through personal accounts or OAuth connections — is covered in freelancer access discovery after departure.

Frequently Asked Questions

Does deactivating a Clio user immediately cut their access? Yes — deactivating a Clio user prevents them from logging in to Clio Manage and Clio Grow immediately. If they have an active session open in a browser, that session will expire (Clio uses short-lived sessions). For safety, change the firm's Clio account password for any shared admin accounts at the same time.

What happens to matters the contractor owned in Filevine after deactivation? In Filevine, deactivating a user removes them from all project teams but preserves their contributions in the matter history. Matters they created or were assigned to remain fully accessible to active staff. You will need to manually reassign matter ownership if the contractor was listed as the primary contact for specific projects.

Does removing a contractor from a Relativity workspace delete their work? No. Relativity preserves all coding decisions, annotations, and review history when a reviewer is removed from a workspace. Their work is retained and attributed to their user account in the audit log — which is exactly what you want for the record. Removing them simply prevents future access.

What if the contractor had access through a shared login we all used? This is the shared-account problem. If your case management system access was shared on a single credential, you cannot selectively revoke one person's access — you need to change the password and redistribute it to current staff only. This is also the point where it becomes urgent to move to individual user accounts. Every person in a Clio or Filevine account should have their own login, full stop. Shared credentials make contractor offboarding nearly impossible to do cleanly and create an unauditable access record.

What Optserv Does Here

Optserv tracks the full contractor lifecycle — from access provisioning at start to a structured offboarding checklist when the engagement ends. When a contractor wraps up, the platform surfaces which tools they had access to and walks through revocation in order, so nothing gets missed in the handoff. See how it works for agencies and service firms →

Sources

  • American Bar Association Model Rules of Professional Conduct, Rule 1.1 Comment 8 (technology competence)
  • Clio support documentation: Deactivating users in Clio Manage
  • Relativity documentation: Managing users and workspace access
  • Everlaw help center: Removing users from case rooms and accessing audit logs

By the Optserv Team

Run your entire team from one place.

Optserv handles hiring, onboarding, access management, and offboarding, built for startups that want to operate like grown-ups without the enterprise overhead.

Try Optserv free