Please enjoy this blog post co-authored by Chris Hockey, Senior Manager, Information Governance, Gibson, Dunn & Crutcher LLP and Tara Saylor, Senior Manager, Collaboration Services, Bryan Cave Leighton Paisner LLP.
As software moved to the cloud over the past decade, it introduced new opportunities for collaboration. Instead of a single copy of a file stored on a firm’s own hardware, a cloud-hosted document can be accessed and edited by multiple users simultaneously. Clients and lawyers have embraced this technology for its speed and ease of use, and vendors continue to offer new solutions to fit their workflows.
From an IT perspective, this collaboration introduces new risks, but the demand is driven by client expectations as much as by technical capabilities, making it hard to ignore. This convenience doesn’t remove a law firm’s security and regulatory obligations, and blanket blocks become less practical. Those client expectations are increasingly specific: sophisticated access controls that permit real-time editing while preventing a file from being copied, downloaded, or printed, and an assumption that firms will work inside the client’s own preferred tools and security environments.
This post offers an overview of the collaboration environments available today and their use cases, but the harder work sits around them: matching the tool to the task, designing intake and review processes that add security rather than delay, and balancing escalating client requirements and regulatory obligations against the business need to keep the work moving.
Current software categories
Broadly, there are three categories of collaboration software on the market today.
Full-featured deal rooms and extranets:
● Overview: A full, bespoke offering built for the client — workflows, trackers, custom security for individual elements within the site. This may include multiple parties with different interests in a matter. Examples include HighQ and SharePoint sites.
● Strengths: They offer high levels of customization and control for complex work, and because they are often purpose-built for the industry, they are likely to meet or surpass regulatory and compliance obligations.
● Weaknesses: Flexibility comes with complexity and overhead, both technical and financial.
● Considerations: Because of the complexity and overhead, full-featured deal rooms may not be a good option for one-time file transfers or large volumes of files.
Shared workspaces:
● Overview: These are the spaces where work gets done. It may involve coauthoring documents, back-and-forth conversations, trackers and project planners. Microsoft Teams is an example of this kind of workspace, but DMS systems are now offering real-time co-authoring functionality.
● Strengths: Purpose-built for collaboration and convenience. The workspace often sits inside the firm's own environment, so there is little new to stand up.
● Weaknesses: That same strength is the defining risk. A shared workspace usually means guest access into the firm's own tenant, categorically different from handing an external party a separate, walled-off tool. A guest in a standalone deal room can reach only what is inside that room; a guest inside the firm's environment can reach whatever the tenant's access model allows — a far larger and less obvious surface. The operative question is not "Can we add this guest?" but "What can this guest actually reach once they are in, and from where?"
● Considerations: Guest access must be scoped deliberately: least-privilege access to the specific workspace rather than the tenant, defined guest-account provisioning and offboarding, and auditability of what a guest touched. And "from where?" is not a throwaway: a guest in a restricted or sanctioned jurisdiction turns the access decision into a regulatory one, not just an IT one (see the section on colliding demands). Governing the information itself, though, is not a new problem. If the firm's records-management policy and retention schedule are sound, a shared workspace governs like any other firm system. The work is organizing the space so it can be governed, not writing new rules for every matter.
Special-purpose collaboration:
● Overview: These are frequently purpose-built cloud tools that expand to include collaboration instead of platforms built for collaboration. Examples include the new deal room functionality in tools such as Legora and Harvey or emerging tools like Datasite.
● Strengths: These tools provide collaborative access to innovative tools like legal-specific AI or best-in-class tools.
● Weaknesses: Because external access is an emerging feature in a fast-changing category, it may not have all the same offerings as traditional deal rooms.
● Considerations: These tools are powerful and capable, but the fast-moving nature requires focus to manage.
Where client and regulatory demands collide with business need
This is where the hard tradeoffs live. The business need is constant: serve the client and keep the work moving quickly. Client and regulatory demands do not always cooperate with that need, and the collaboration environment is where the conflict gets resolved, whether anyone decides it deliberately.
Two patterns appear repeatedly.
Client protection demands are escalating. Clients increasingly require that documents cannot be copied, downloaded, printed, or screenshotted. Rights management and encryption at that level have become a baseline expectation rather than a premium feature. That expectation can rule out the fast, convenient option: if the environment the attorney wants to use cannot enforce the control, the client requirement wins and the business need to move quickly yields to it.
Access can carry regulatory weight the tool will not surface on its own. Making documents available to users in certain jurisdictions raises guest-into-tenant permission questions and sits on top of sanctions and cross-border transfer obligations. The business need to bring a client or co-counsel into the work is legitimate; so is the constraint. The platform will happily grant access. It will not tell you access is the problem.
The takeaway: environment choice is not a convenience decision. It is where client requirements and regulatory obligations get resolved together, and it is far cheaper to resolve them before work product lands in a shared space than after.
Building for speed and security
Law firms need security in collaboration. Clients are demanding speed. The two are not opposed if you design for both. The point of everything below is to strip the avoidable friction around a request so only the necessary security review remains. It is about cutting the steps that surround the review, not the review itself.
- Document software requirements: Work with Security and Compliance teams to identify and document the minimum and preferred requirements for collaboration software. Consider things like multi-factor authentication for guest accounts, how guest accounts will be managed, archiving and retention requirements, and security expectations. Developing this guide will make it easier and faster to evaluate new tools.
- Review your processes: Look hard for steps that add time without adding security. The common one is the unnecessary middleman: routing a request or a data move through a team that has no more access or authority than the person already making it. "We have always done it this way" is not a control. Keep the review that protects the firm and cut the handoffs that only protect the habit. Pair this with training and documentation so requests reach the right team the first time.
- Develop intake forms: Gather information in a single document to prevent back-and-forth at the time of the request.
- Evaluate integrations for long-term clients: Many firms have long-standing relationships with clients that could allow for more flexible governance and access. There may be opportunities to set up behind-the-scenes infrastructure before it’s requested or permit closer integrations between systems. For example, add their domains to allow lists as part of the tool set up instead of waiting for the request.
- Match the software to its strengths: As outlined above, tools offer a variety of strengths and shortcomings. Don’t require the complexity of a full deal room for a simple file transfer, and conversely, don’t expect a special-purpose tool to provide all the same features as a traditional deal room.
Know the tradeoffs
Seamless external collaboration is now the expectation, not the exception. The security and regulatory obligations that come with it are not negotiable. The way through is not finding one perfect platform. It is knowing your environment, matching each to the work in front of you, and engineering out the avoidable friction before it forms.
Matching the tool to the job is the daily discipline. The durable competence is understanding what each environment does and does not do, because the tools will keep changing and the best option this year may not be the best one next year. Deeper down, none of this is really about the tools. It is about whether the information governance underneath them is sound, and the collaboration question is just where that shows up first. Govern to that understanding and speed and security stop pulling against each other.
#Collaboration#Just-in-Time#100Level#InformationGovernanceorCompliance#EnterpriseCollaborationSoftware