How Law Firms Are Rethinking Document Sharing
Legal work involves sending privileged material to people outside the firm. Here is how firms are handling client documents without portals nobody logs into.
Legal practice has an awkward requirement: the most confidential documents must routinely be sent to people outside the firm, who have no interest in learning the firm’s systems. Opposing counsel, clients, expert witnesses, and courts all need access, and none of them will tolerate an onboarding flow.
Why client portals underperform
Most firms bought a portal. Most portals are underused, for a reason that has nothing to do with the software: a client receiving three documents a year will not remember a password, and will email to ask for the file directly. The lawyer, wanting to be responsive, attaches it.
The portal did not fail technically. It failed because it put the cost of security on the person with the least reason to accept it.
What firms are moving toward
The pattern that sticks is per-document links with controls attached, rather than a destination clients must visit.
- Access expires on a matter-appropriate timeline — often when the engagement closes.
- Sensitive material requires email verification, so each view is tied to a verified address.
- Every open is recorded, giving a defensible answer to "when did they receive it?"
- Access can be revoked immediately when a matter concludes or a relationship changes.
- The recipient clicks a link and reads the document. That is the entire experience.
The audit trail is the part clients notice
Delivery disputes are common and expensive. A record showing a document was opened on a specific date, by someone who verified a specific email address, resolves arguments that otherwise turn into affidavits.
It is worth checking how long that record survives in whatever tool you use. Some systems delete access history when a link expires, which removes the evidence at precisely the moment it becomes relevant.
A reasonable default policy
Firms that make this work tend to converge on something like: routine correspondence goes by email; anything privileged or client-confidential goes as a link with an expiry; anything that would be damaging if misdirected also requires email verification; and access is reviewed when a matter closes.
The value is not in any single control. It is that the sender keeps the ability to change their mind after sending — which email has never offered.
Keep reading
- Why Email Attachments Are a Security Risk
Email was never designed to carry confidential files. Here is what actually happens to an attachment after you hit send, and what to use instead.
- Best Practices for Sharing Sensitive Files in 2026
A practical checklist for sending confidential documents: expiry, view limits, verification, audit trails, and the mistakes that undo all of them.