First page of Microsoft's 100,000-partner directory, sorted by responsiveness All 6 Microsoft Solutions Partner designations Microsoft Solutions Partner since 2006 1,100+ organizations under management
Home/Blog/How Law Firms Should Structure SharePoint for Co…

How Law Firms Should Structure SharePoint for Compliance

2026-06-16·IT PartnerNewMicrosoft 365SharePointSecurityCompliance

Most law firms do not have a SharePoint problem; they have a matter-governance problem that SharePoint exposes. Client files spread across Teams, OneDrive, legacy file shares, and over-permissioned SharePoint sites create predictable risks: improper access, stale guest accounts, weak audit evidence, and inconsistent retention.

Start with the compliance model, not the folder tree

Rebuilding the old file server in SharePoint as Client > Matter > Pleadings > Discovery > Correspondence is familiar, but it does not solve permissioning, external sharing, retention, sensitivity labeling, audit, or eDiscovery.

Start with one question: what is the unit of confidentiality? For most firms, it is the matter. A litigation matter, M&A transaction, employment investigation, estate file, or regulatory response may need different access, retention, external collaboration, and hold requirements even when the client is the same.

A compliance-ready SharePoint model should define these objects:

  • Client: the business relationship and billing or reporting entity.
  • Matter: the primary security, collaboration, and retention boundary.
  • Practice group: the operating owner and template driver.
  • Role: partner, associate, paralegal, legal assistant, records, conflicts, finance, external counsel, client contact, expert, vendor.
  • Data class: client confidential, attorney-client privileged, attorney work product, public filing, highly restricted, administrative.

If the current structure cannot show who has access to Matter 2024-0187, whether access comes from a group or a direct grant, which guests were invited, what sharing links exist, and what retention applies, the structure is not compliance-ready.

Use matter-centric sites when confidentiality matters

For legal work, the strongest SharePoint pattern is usually one SharePoint site per matter, or one Microsoft Teams team per matter with its connected SharePoint site. This creates a clean boundary for owners, members, guests, sharing settings, retention scope, sensitivity labels for the container, audit review, and eDiscovery holds.

A single large document library with client or matter folders is easy to create and hard to govern. Folder-level permissions can work for limited exceptions, but at legal scale they become brittle: inheritance breaks, direct grants multiply, owners lose visibility, and access reviews become unreliable.

A practical pattern is:

  • Hub site for each practice group, department, or region.
  • Matter site for each active matter, created from a standard template.
  • Standard libraries for working documents, pleadings or filings, correspondence, discovery, closing sets, or administrative material as applicable.
  • Private channel, shared channel, or separate restricted site for highly sensitive workstreams, selected deliberately because private and shared channels create separate SharePoint sites with their own membership.
  • Closed-matter state that reduces access and starts the retention process.
  • Separate records, knowledge, or precedent libraries for approved forms and final work product that should not live inside active matter workspaces.

The operating model matters as much as the site model. A 200-attorney firm may open hundreds or thousands of matters per year. Manual site creation will not stay consistent. Provision matter sites from the intake or matter-opening workflow. The workflow should create the site or team, apply the template, assign owners and groups, apply default metadata, apply container sensitivity where used, set sharing defaults, and record the responsible attorney. If provisioning takes too long, users will create unmanaged Teams, ad hoc SharePoint sites, or OneDrive workarounds.

Design permissions around groups, not individual exceptions

Direct user permissions are difficult to review and easy to forget. In law firms, they often start with urgent requests: add an associate, share a folder with a consultant, invite an expert, or give finance read access. Months later, no one can explain why the access still exists.

Use role-based groups for each matter. Depending on the design, these may be Microsoft 365 groups, Microsoft Entra ID security groups, or SharePoint groups that contain Entra ID groups. Keep the model simple:

  • Matter Owners: responsible attorneys and delegated matter administrators.
  • Matter Members: internal legal team.
  • Matter Read-Only: records, conflicts, finance, or other approved internal roles.
  • External Collaborators: client contacts, co-counsel, experts, vendors, or consultants.

Do not give guests broad access to the full matter site unless the engagement requires it. Use a dedicated external-collaboration library, channel, or site with separate permissions when guests only need a subset of documents. Set an owner, purpose, and review date for each external collaboration space.

Use access reviews for sensitive matters and at matter close. In Microsoft Entra ID Governance, access reviews can support group and guest review processes when the tenant is licensed and configured for them. Where automated access reviews are not available, maintain a documented manual review: owner, date, membership reviewed, exceptions approved, and removals completed.

Make metadata do compliance work

Folders help lawyers navigate a file, but folders alone do not give reliable retention, eDiscovery, reporting, or policy targeting. Use metadata to make matter identity and risk visible to SharePoint, Microsoft Purview, search, and reporting.

At the site or library level, capture matter defaults such as client number, matter number, practice group, responsible attorney, jurisdiction, open date, close date, confidentiality level, retention category, and client-specific restrictions. At the document level, use only fields that materially change from document to document, such as document type, privilege status, draft/final status, and record status.

Do not require lawyers to complete excessive metadata on every save. A better model is default metadata from the matter site plus a short controlled list for fields that users can realistically maintain.

Example: documents in the matter site inherit Client ID, Matter ID, Practice Group, and Responsible Attorney. Users select Document Type from a controlled list such as Pleading, Contract, Correspondence, Discovery, Research, Board Material, Closing Deliverable, or Administrative. Privilege can default to Not Assessed and be updated through metadata, a sensitivity label, or a review workflow when needed.

This improves compliance because retention and eDiscovery usually fail when the firm cannot reliably identify which documents belong to a matter, which are final records, which involve external parties, and which are subject to client-specific terms.

Apply retention and sensitivity controls deliberately

Legal compliance is not one retention rule. A seven-year default may be appropriate for some closed client files, but not for all. Minor clients, trusts and estates, tax, real estate, patent prosecution, government matters, litigation holds, regulatory requirements, and outside counsel guidelines may require different treatment.

A mature SharePoint model supports three states:

  1. Active matter: assigned team can collaborate; documents are editable; external sharing follows matter policy.
  2. Closed matter: access is reduced; content is read-only or tightly controlled; the retention trigger is recorded.
  3. Disposition or archive: content is reviewed, preserved, exported, deleted, or retained according to firm policy, legal hold, and client terms.

Use Microsoft Purview retention policies and retention labels based on the control needed. Site-level retention policies can cover a whole matter site. Retention labels can be applied to libraries, folders, document sets, or individual items, and can support records management scenarios when configured. For matter-close retention, consider event-based retention or a close-date-driven process where available and appropriate.

Use sensitivity labels in two different ways. Container labels for Microsoft Teams, Microsoft 365 groups, and SharePoint sites can help control privacy, external sharing, guest access, and unmanaged-device behavior. File sensitivity labels can apply encryption, content markings, and usage restrictions to documents and emails.

Keep the label set understandable. A legal label set might include General Business, Client Confidential, Privileged, Highly Restricted, and External Collaboration Allowed. Avoid encryption settings that break search, co-authoring, eDiscovery, or document workflows unless the risk justifies the friction. The goal is proportional control, not maximum restriction on every file.

Treat external sharing as a governed workflow

Many SharePoint incidents in law firms involve misdirected links, guests who remain active after a matter ends, inherited permissions, oversharing from synced content, or compromised external accounts. External sharing should be designed as a controlled workflow, not a personal preference.

Use these controls where they fit the firm’s risk model and licensing:

  • Disable Anyone links firmwide unless a documented exception is approved.
  • Use Specific people links for client, expert, vendor, and co-counsel sharing.
  • Set default link permissions to view-only unless editing is required.
  • Limit the default link expiration period and require shorter expiration for high-risk matters.
  • Require multifactor authentication for guests through Microsoft Entra External ID and Conditional Access where available.
  • Set guest access expiration or scheduled guest reviews for temporary experts, consultants, and co-counsel.
  • Use SharePoint and OneDrive unmanaged-device controls, Conditional Access, or Microsoft Defender for Cloud Apps session controls to block or limit downloads for highly restricted content where appropriate.
  • Review sharing events, guest invitations, and anonymous link creation in the Microsoft Purview audit log for sensitive matters.
  • Separate client-facing collaboration spaces from internal strategy, privilege analysis, and attorney work product.

If a client requires broad collaboration access, document it as a client-specific requirement and configure that matter accordingly. Do not let one client’s workflow become the tenant-wide default.

SharePoint design decision Recommended legal-firm pattern Compliance reason Common failure pattern
Unit of structure Matter-centric SharePoint site or Teams-connected site Makes permissions, sharing, retention, audit, and eDiscovery matter-specific One large library with client and matter folders
Site relationship Practice-group hub sites with matter sites associated to the hub Supports navigation and governance without inheriting permissions from a single container Department sites used as shared dumping grounds
Permissions Role-based groups with limited owners and minimal direct grants Easier access reviews and cleaner audit evidence Individual permissions scattered across folders and files
Restricted workstreams Private channel, shared channel, or separate restricted site selected intentionally Creates a separate membership boundary for sensitive subsets of work Sensitive documents stored in the main matter library with broken inheritance
External sharing Specific people links, controlled guest access, expiration or review, separate external collaboration area Reduces accidental disclosure, stale guest access, and overbroad client or vendor access Anyone links, unmanaged guests, no expiration, full-site guest access by default
Metadata Matter defaults plus limited document-level fields Supports search, retention, eDiscovery, reporting, and policy targeting Deep folders with no reliable matter metadata
Retention Active, closed, and disposition states tied to matter close and matter type Aligns lifecycle with firm policy, legal holds, and client obligations Same retention rule for every file regardless of matter type
Sensitivity labels Container labels for sites and teams; file labels for documents that need marking or encryption Protects privileged and restricted content without confusing site controls with file controls Too many labels, unclear labels, or encryption that disrupts legal workflows
Provisioning Automated from intake or matter-opening workflow Applies templates, groups, metadata, labels, and sharing defaults consistently Manual IT tickets and ad hoc Teams or SharePoint sites
Access review Quarterly or risk-based review for sensitive matters; documented review at matter close Produces evidence that confidentiality is actively managed No review until a breach, audit, or client questionnaire

Key takeaways

  • For law firms, the matter is usually the right security, collaboration, and retention boundary in SharePoint.
  • Folder-level permissions can handle limited exceptions, but they become a compliance liability when used as the primary design.
  • External sharing should use governed links, guest controls, expiration or review, and audit visibility.
  • Metadata, retention labels, and sensitivity labels should be simple, matter-aware, and enforceable.
  • A compliant SharePoint design depends on provisioning, ownership, and access review processes as much as site structure.

If you are unsure whether your Microsoft 365 tenant can support this model, start with a security and configuration review before redesigning the information architecture. IT Partner can help assess baseline controls, Microsoft Secure Score gaps, sharing settings, guest access, labels, and remediation priorities through our Microsoft 365 Security Baseline and Secure Score Remediation service.

Questions this article didn’t answer?

Thirty minutes with Mike — our CEO, not a sales rep. Bring the hard version of the question.