Law-firm confidentiality cannot be reduced to a checkbox marked secure. In PracticePanther, one role may determine whether a user sees every contact or only assigned contacts, whether portal messages are visible, and what financial or administrative actions the user can take. A broad role assigned for convenience can quietly expose unrelated matters; an overly narrow one can send staff to shared credentials or side channels. The useful target is a documented access model that matches real responsibilities and is tested from the perspective of each job, device, and matter boundary.
PracticePanther offers custom access levels, assigned-record scope, two-factor authentication, a client portal, user deactivation, and bulk reassignment tools. Those features operate inside a larger security environment that includes email accounts, browsers, endpoints, connected applications, file repositories, phone numbers, and office access. A disabled PracticePanther login does not revoke a mailbox session or erase a downloaded file, while a carefully restricted application role cannot protect a password captured on an unmanaged computer. The firm's identity and endpoint controls must therefore move with the application lifecycle.
This guide focuses on four operational controls: designing least-privilege roles, protecting authentication, governing portal communication, and completing joiner-mover-leaver work without losing ownership. It deliberately avoids claiming that vendor infrastructure replaces firm governance. PracticePanther publishes information about encryption, backups, Azure hosting, role controls, and login safeguards; the firm still needs vendor-risk review, data-handling rules, recovery planning, and independent decisions about professional obligations. A secure configuration is one that produces evidence and survives a real personnel change.
Key decisions at a glance
- Build roles from job tasks and data boundaries, then test them with non-administrator accounts on realistic matters.
- Require individual user identities and two-factor authentication while protecting codes, recovery channels, and managed endpoints.
- Activate the Client Portal per contact only after verifying identity, email ownership, sharing scope, and support expectations.
- Reassign contacts, matters, activities, and integrations before deactivation so access removal does not abandon work.
- Review entitlement, portal, and offboarding evidence on a schedule and after every material staffing or practice change.
Translate law-firm jobs into PracticePanther access levels
List what each job must view, create, edit, export, delete, approve, and administer before touching the role editor. Typical groups may include managing partner, responsible attorney, associate, paralegal, intake, billing, accounting, records, and external collaborator, but titles alone are insufficient. A billing specialist may need invoices and payments without private legal notes; an intake coordinator may need prospective contacts without all active cases. PracticePanther's access-level model distinguishes permissions and access scope, including assigned contacts versus broader visibility. Translate every enabled permission into a concrete business task and identify the data exposed by that task.
Protect the administrator role as an exceptional privilege. PracticePanther's documentation notes that the built-in Admin level is not edited like a normal custom role, and other help content warns about administrative defaults for new users in some workflows. Treat every invitation as a privileged change until the intended access level has been assigned and verified. Keep the number of administrators small, use separate day-to-day accounts where practical, and require a second person to review changes affecting roles, integrations, payments, exports, or large batches. An administrator should not approve their own unexplained elevation.
Test from real non-admin accounts using synthetic matters that represent different teams and confidentiality boundaries. Confirm not only which records appear, but also search results, reports, portal messages, files, invoices, activities, exports, and mobile views. PracticePanther documents a method for restricting a role from all contacts so the user is limited to assigned records; verify the result with an assigned matter, an unassigned matter, a reassigned matter, and a contact tied to multiple matters. Record expected and actual results so future reviews can detect configuration drift.
- Create a role matrix with job task, PracticePanther permission, record scope, approving owner, and test case for every access decision.
- Separate administrator, legal-work, intake, billing, and records responsibilities wherever staffing permits.
- Verify assigned-contact restrictions across contacts, matters, activities, files, portal messages, reports, search, and mobile access.
- Review every new invitation before first productive use; do not rely on a default role being appropriately narrow.
- Retest roles after feature releases, permission changes, new practice groups, mergers, or changed staffing patterns.
Protect identities, two-factor authentication, and endpoints
Give each worker a named PracticePanther identity. Shared accounts destroy attribution, complicate offboarding, and encourage code sharing. PracticePanther's two-factor setup uses a verification code delivered through email for a new device or browser, so the mailbox and its recovery methods become part of the authentication boundary. Require a unique password, protect the email account with strong authentication, and prohibit forwarding codes to coworkers or support staff. If a user cannot complete sign-in, the help process should verify identity and device context rather than ask for the code.
Manage the device that holds the browser session. Apply supported operating-system and browser updates, screen locking, disk encryption, anti-malware or endpoint detection, restricted local administrator rights, and remote-response capability according to firm policy. Separate browser profiles can reduce accidental cross-account use, particularly for outsourced staff serving multiple clients. Avoid downloading client files to unmanaged endpoints, and define a response for a lost phone or laptop that covers PracticePanther, email, connected storage, remote access, and any saved credentials rather than focusing on one application.
Use the vendor's security statements as inputs to due diligence, not as a completed risk assessment. PracticePanther states that it uses encryption in transit and at rest, Azure infrastructure, backups, access controls, and login throttling. Confirm current contractual, privacy, residency, retention, incident-notification, availability, and recovery terms with the appropriate owner, because marketing-level controls do not answer every firm requirement. Decide which exports are required for continuity, who can initiate them, where they are stored, how they are protected, and how the firm would operate during an extended service interruption.
- Use named accounts, unique passwords, protected email delivery, and two-factor authentication for every eligible user.
- Document who may reset access, what evidence establishes identity, and how suspicious login reports are escalated.
- Enroll laptops and mobile devices in the firm's managed security baseline before they handle client records.
- Inventory browser extensions and connected applications that can read, export, or alter PracticePanther data.
- Test the incident and continuity procedure with synthetic data so recovery assumptions are visible before an emergency.
Govern Client Portal messages, files, tasks, and invoices
PracticePanther's Client Portal can present tasks, events, invoices, secure messages, and files to an activated contact. Activation should follow identity verification and a matter-specific sharing decision, not occur automatically for every email address on file. Confirm the intended recipient, whether one contact represents an organization or several people, which matters should be visible, and whether a shared household or business mailbox creates inappropriate access. Explain how the client creates and protects the portal password and, where available, enables their own two-factor authentication.
Define what belongs in a secure portal message and what still requires another channel or attorney review. PracticePanther documents file sharing through secure messages, which can be useful for deliberate exchange, but a portal is not a license to send every document without checking audience, privilege, redaction, size, malware risk, or deadline sensitivity. Use a clear subject convention that does not reveal unnecessary details, verify the attachment before sending, and assign an owner for client replies. If staff also use ordinary email, document when the portal is required and prevent parallel conversations from leaving the matter record incomplete.
Permission testing must include portal content. PracticePanther's role documentation ties contact access to visibility of secure messages, so a user who can see a contact may gain access to related communications. Test an attorney, paralegal, billing user, intake user, and reassigned worker against both portal-enabled and non-enabled contacts. Review active portal access when a relationship changes, an email address is corrected, a client representative leaves, or a matter closes. Keep evidence of who authorized sharing and how a mistaken recipient or attachment would be contained.
- Verify the client's identity and email ownership before portal activation, then document the authorizing matter owner.
- Demonstrate password protection, two-factor options, expected response time, and how to report a suspicious message.
- Review recipient, matter, file, redaction, privilege, and sensitivity immediately before every consequential share.
- Route portal replies to a named team member and define backup coverage for vacations, departures, and urgent deadlines.
- Reassess portal access at matter closure and whenever the client's representatives or contact channels change.
Execute onboarding, moves, and offboarding as one controlled change
Create a ticket or checklist before inviting a new user. It should identify manager approval, intended role, assigned matters, firm email, managed devices, required training, integration responsibilities, and a date for early access review. For a mover, compare old and new responsibilities rather than simply adding permissions. Remove access that no longer has a business purpose, reassign affected work, and retest sensitive views. A person changing practice groups can create the same confidentiality problem as a departing employee if their old matter access persists indefinitely.
Offboarding must preserve work ownership while promptly ending access. PracticePanther documents that an administrator can deactivate a user and that deactivated work and history remain; separate guidance covers individual and bulk reassignment of contacts, matters, tasks, events, and other activities. Inventory the departing person's assigned records, upcoming deadlines, portal conversations, billing duties, templates, reports, integrations, and support cases. Reassign and verify critical items before or as part of deactivation, then revoke email, identity-provider, device, remote-access, storage, and physical access under the same time-bound plan.
Use care with batch reassignment because a broad action can be difficult to reverse. Export or capture an approved assignment list, pilot a small set, verify notifications and results, and only then process the remaining records. Afterward, confirm that the old account cannot sign in, replacement users can find their work, no deadline is orphaned, and audit history remains intelligible. Keep completion evidence with the HR or service ticket at an appropriate sensitivity level, and perform a short follow-up review after several business days to catch missed ownership.
- Link every joiner, mover, and leaver action to an approved request with an effective date, owner, and completion evidence.
- Inventory assigned contacts, matters, activities, portal conversations, billing work, reports, templates, and integrations before deactivation.
- Pilot batch reassignment on a small sample and reconcile counts before accepting a large change.
- Revoke application, email, device, storage, remote, vendor-support, and physical access in one coordinated window.
- Review privileged roles and inactive accounts monthly, with a broader entitlement certification at least quarterly.
Vendor documentation and ALLMSP resources
- PracticePanther Help Center: Access Levels Tutorial
- PracticePanther Help Center: Blocking Users from Specific Contacts
- PracticePanther Help Center: Limit a User from Seeing Secure Messages
- PracticePanther Help Center: Two-Factor Authentication Setup
- PracticePanther Help Center: How to Secure Your Account
- PracticePanther Help Center: How Your Data Is Secure
- PracticePanther Help Center: Client Portal Tutorial
- PracticePanther Help Center: Sharing Files with Clients Using the Client Portal
- PracticePanther Help Center: Deactivating and Reactivating Users
- PracticePanther Help Center: Reassign Contacts, Matters, or Activities
- ALLMSP Software Support
- ALLMSP Managed IT Services
- ALLMSP Cybersecurity Services
- ALLMSP Law Firm IT Services Resources
- ALLMSP PracticePanther Support Category
- Contact ALLMSP
Frequently Asked Questions
What is the best starting point for PracticePanther least privilege?
Begin with job tasks and data boundaries rather than existing titles. For every role, identify what the person must view, create, change, export, delete, approve, and administer, then map those needs to PracticePanther permissions and assigned-record scope with an approving owner.
Should every PracticePanther user be an administrator?
No. Administrator capability should be limited to a small number of trained, accountable people because it can affect roles, account settings, and other high-impact functions. Give ordinary work accounts only the access required and require independent review for sensitive administrative changes.
How do assigned-contact restrictions work in PracticePanther?
PracticePanther supports roles that can be limited from seeing all contacts so users work with assigned records. Test that boundary across contacts, matters, activities, files, messages, invoices, reports, search, and mobile views, including reassigned and multi-matter contacts.
Does PracticePanther support two-factor authentication?
PracticePanther documents two-factor authentication for all plans, with a code delivered through email when a new device or browser is used. Protect the mailbox, never share codes, use managed devices, and define a verified recovery process for users who cannot sign in.
Is PracticePanther security enough without managed devices?
No application control can fully compensate for an unprotected endpoint. Firm laptops and phones should follow an approved baseline for updates, encryption, screen lock, endpoint protection, browser configuration, local privileges, remote response, and handling of downloaded client files.
What can a client see in the PracticePanther Client Portal?
Depending on what the firm enables and shares, PracticePanther describes portal access to items such as tasks, events, invoices, secure messages, and files. Verify the recipient and matter scope before activation, and show the client how to protect their password and account.
Are PracticePanther portal messages visible to every employee?
Visibility depends on contact access and the configured security role. Because PracticePanther links secure-message visibility to contact permissions, test each job role against portal-enabled contacts and restrict assigned-record access where the firm's confidentiality model requires it.
What should happen before a PracticePanther user is deactivated?
Inventory and reassign the person's contacts, matters, tasks, events, portal conversations, billing work, reports, templates, integrations, and support responsibilities. Coordinate application removal with email, managed devices, storage, remote access, and physical access, then verify the account cannot sign in.
Can PracticePanther records be reassigned in bulk?
PracticePanther documents individual and batch reassignment workflows. Because a broad batch can be hard to undo, work from an approved source list, test a small sample, reconcile record counts, verify notifications and ownership, and keep evidence of the completed change.
How often should PracticePanther access be reviewed?
Review new access shortly after onboarding, privileged and inactive accounts monthly, and broader entitlements at least quarterly. Also trigger a review after a role change, departure, practice-group change, merger, portal-relationship change, significant release, or incident.


