ALLMSP Blog

Clio Permissions Guide for Law Firms: Roles, MFA, and Offboarding

A law-firm access blueprint for Clio roles, custom roles, groups, restricted matters, MFA administration, recurring reviews, and complete user offboarding.

Clio roles-permissions-mfa-offboarding support for a Georgia business

Clio contains client identities, privileged communications, matter strategy, deadlines, documents, time entries, bills, and trust information. The access question is therefore more precise than whether an employee can sign in: the firm must decide what each person can see, change, export, bill, report on, and administer, then prove that those boundaries survive promotions, transfers, leaves, and departures.

Clio Manage combines standard roles, plan-dependent custom roles, user groups, and matter-level permissions. Those layers interact. Every user needs at least one role, multiple roles resolve toward the most permissive access, matters are visible to all firm users by default, and some billing, accounts, or reporting rights can expose matter information even when the matter itself is restricted. A role name alone is not adequate evidence of least privilege.

A defensible access program starts with job-based design, tests sensitive matters from real user accounts, gives MFA recovery clear owners, and makes offboarding a coordinated legal-operations and IT event. The goal is reliable client service with fewer silent access paths, not a large spreadsheet of unchecked boxes.

Key decisions at a glance

  • Design a small role catalog from real job duties and remember that a user with multiple roles receives the most permissive combined access.
  • Use groups to simplify matter access, but test the actual matter view because billing, accounts, and reports permissions can reveal information through other routes.
  • Treat bulk matter-permission changes as replacements, not additions, and verify every retained user or group before applying the update.
  • Monitor MFA status and recovery ownership, including the special limitations around resetting the primary subscriber's MFA.
  • Offboarding must cover work reassignment, restricted and closed-matter exceptions, integration owners, licenses, groups, devices, sessions, and evidence.

Design Roles and Groups From Law-Firm Duties

Clio support workflow: Design Roles and Groups From Law-Firm Duties
Clio support workflow: Design Roles and Groups From Law-Firm Duties

Start with Clio's five standard roles—Administrator, Accounts, General Access, Billing, and Reports—as reference points, then map each permission to actual duties. Keep Administrator limited to people who must manage settings, users, roles, and firm-wide data. A title such as partner, paralegal, or bookkeeper is only a starting hypothesis; the approving manager should state which records and actions the person needs to perform and which high-impact actions should remain separated.

Where the firm's Clio plan supports custom roles, build narrowly named templates for recurring jobs instead of granting several broad system roles. Clio notes that standard-role templates carry their non-configurable permissions into a custom role, so review the inherited rights before using one as a shortcut. Also remember that multiple assigned roles combine at the most permissive level. Adding a small role can unexpectedly restore a capability that another role was intended to remove.

Use groups for stable cohorts that repeatedly share matter access or matter rates, such as a practice team or intake unit. Only administrators can create and modify groups. Document the group owner and membership rule, and do not treat archiving as cleanup: Clio states that an archived group remains on matters, calendar shares, and custom client rates until those objects are edited.

  • Record the business duty, approved data scope, and prohibited actions for each role.
  • Review non-configurable permissions before deriving a custom role from a system template.
  • Calculate effective access across every role assigned to the user, not role by role in isolation.
  • Give each group an owner, membership rule, review date, and retirement procedure.

Apply Matter Restrictions and Test the Hidden Access Edges

Clio support workflow: Apply Matter Restrictions and Test the Hidden Access Edges
Clio support workflow: Apply Matter Restrictions and Test the Hidden Access Edges

In Clio Manage, a matter is visible to everyone at the firm by default. For confidential, ethical-wall, executive, employment, or other restricted work, choose specific users or groups when creating or editing the matter. Clio currently allows up to 20 selected users and groups for that setting. Establish a matter-opening rule that tells staff when the default is unacceptable and who approves the access list.

A restricted-matter test must cover more than the Matters page. Clio warns that users without matter access may still see bills through Billing or Accounts permissions and may see matter details in reports through Reports permissions. Test search, reports, bills, exports, notifications, calendars, communications, and documents from the perspective of a permitted user and a deliberately excluded user. Save the test case and result with the approval record.

Handle bulk changes as high-risk operations. Clio's bulk permission update replaces the existing permission set; users who are not selected again lose access. Blocking a user overrides any access inherited through a group, but a later bulk block operation also requires existing blocked users to be selected again if the block should remain. Export the affected matter list, capture the before-state, use a two-person review, and retest representative matters afterward.

  • Define which matter types require specific users or groups instead of the Everyone default.
  • Test billing, accounts, reports, exports, notifications, calendars, and documents for access leakage.
  • Treat bulk updates as full replacements and preserve an approved before-and-after record.
  • Confirm that user blocks still override group access after any later permission maintenance.

Operate MFA and Offboard Users Without Orphaning Work

Clio support workflow: Operate MFA and Offboard Users Without Orphaning Work
Clio support workflow: Operate MFA and Offboard Users Without Orphaning Work

MFA is now part of Clio's normal account baseline; Clio says users who had not enabled it after it became mandatory in January 2026 are required to do so at their next login. Administrators and the primary subscriber can see MFA status for active users. An administrator can reset another user's MFA only after enabling MFA on the administrator's own account, and cannot reset MFA for the primary subscriber. Document who handles ordinary resets and when Clio Support must become involved.

Begin offboarding with ownership, not just deactivation. Inventory the user's open and pending matters, assigned tasks, calendar events, group memberships, private work, email and document integrations, billing responsibilities, exported data, and any connector that was authorized with the person's account. Clio can reassign matters, tasks, and calendar events, but its documented bulk reassignment does not cover work associated with closed matters, tasks or calendars not linked to a matter, attendee-only calendar events, or restricted matters set to Me.

Deactivate access at the agreed employment cutoff, verify that the user no longer appears as an active access path, and then address licensing separately. Clio explains that deactivation makes the license available but does not remove it from the subscription, so an unused license can continue to be billed. The primary subscriber has special ownership status and cannot be handled like an ordinary user; transfer ownership under Clio's process before a primary subscriber departs.

  • Monitor active-user MFA status and keep a documented, identity-verified reset procedure.
  • Reassign open work and manually inspect the categories that Clio cannot bulk reassign.
  • Replace departing-user credentials on email, document, accounting, and other integrations.
  • Deactivate the user, review the license count, and preserve completion evidence with timestamps.

Make Access Reviewable Instead of Merely Configured

Create a quarterly review packet that a managing partner and system owner can understand. Include active and invited users, roles, effective multi-role permissions, administrator and primary-subscriber assignments, groups, MFA status, restricted matters, blocked users, integration owners, recent departures, and exceptions awaiting approval. Add event-driven reviews after a role change, lateral hire, merger, practice-team move, extended leave, or suspected account compromise.

ALLMSP can maintain the technical access matrix, coordinate Microsoft or Google identity changes, verify managed devices and browser sessions, test role and matter boundaries, document MFA recovery, and execute the IT portion of joiner-mover-leaver procedures. The firm's designated legal authority should approve ethical-wall membership and the scope of confidential matters, while finance validates billing and trust access.

Use the review to fix design debt rather than simply renew every row. Retire one-off roles, remove stale group members, inspect archived groups still attached to matters or calendars, reduce unnecessary Administrator assignments, replace integration owners who changed jobs, and sample actual user experiences. A signed exception should identify the risk owner, reason, compensating control, and expiration date.

  • Review access quarterly and after employment, practice, ownership, or security events.
  • Show effective permissions after role combinations, not only the names of assigned roles.
  • Separate legal approval, financial approval, and technical implementation responsibilities.
  • Time-limit exceptions and verify remediation from a real user account before closure.

Frequently Asked Questions

What standard roles are available in Clio Manage?

Clio documents five standard roles: Administrator, Accounts, General Access, Billing, and Reports. Each has built-in capabilities, and some permissions are non-configurable. Assign from job duties and review the documented permission details before treating any role as a harmless label.

What happens when a Clio user has more than one role?

The user receives permissions from the most permissive assigned role. Review the combined effective access whenever a role is added or changed, because a narrow role does not cancel a broader capability granted elsewhere.

Are custom roles available to every Clio Manage account?

Clio states that custom roles are available on select plans. Confirm the firm's subscription before designing around them. When using a standard role as a template, account for the non-configurable permissions that carry into the custom role.

How do Clio groups differ from roles?

Roles control what a user can do across Clio, while groups can simplify access to particular matters and the assignment of some rates. A person can be in a group and still receive broader capabilities through roles, so the two controls must be reviewed together.

Are new Clio matters restricted by default?

No. Clio Manage matters are visible to all firm users by default. Staff must choose specific users or groups when the matter needs restricted access, and the firm should make that decision part of matter opening rather than a later cleanup.

Can someone without matter access still see information about it?

Potentially. Clio warns that Billing or Accounts permissions may expose bills and Reports permissions may expose matter details even when the user lacks direct matter access. Test those paths when implementing confidential-matter controls.

What is risky about bulk matter-permission updates in Clio?

A bulk update replaces the existing access list. Anyone not selected again can lose access, and bulk blocking requires retained blocked users to be selected again. Capture the current state, obtain a second review, and test after applying the change.

Who can see and reset Clio MFA status?

Administrators and the primary subscriber can see MFA status for active users. An administrator with MFA enabled can reset another user's MFA, but cannot reset the primary subscriber's MFA; recovery for that account may require Clio Support.

Does deactivating a Clio user remove the subscription license?

No. Clio says the license becomes available for another user but remains on the account and may continue to be billed until it is removed. Review license quantity after access and work reassignment are complete.

What should a Clio offboarding checklist cover?

Cover the cutoff time, matters, tasks, calendars, restricted and closed-matter exceptions, groups, roles, MFA, integrations, devices, sessions, data exports, license disposition, and evidence. Include a special ownership plan if the departing person is the primary subscriber or connector owner.

Facebook
LinkedIn
WhatsApp
X
Email
Print
Threads
Reddit

Related Articles