MatterLayer / Field note
Buyer evaluationEvaluating a PMS or legal-tech integration
A useful integration review begins with a bounded outcome and ends with a tested offboarding path. Between those points, the firm must map objects, permissions, data movement, provenance, failure behavior and ownership.
Define the outcome and object map
Write the operating question before discussing endpoints. Identify the matter cohort, user roles, decision and minimum information required. Then map the objects that support it: matters, contacts, users, custom fields, tasks, time, bills, documents or events may have different identifiers and access rules. Vendor documentation can show available platform structures and export or API capabilities, but configuration varies by customer and product plan. Test against the firm's own sandbox or controlled records. Document which system owns each field, how deleted or merged records behave and what happens when a custom field is absent. Avoid joining records on names when a stable identifier exists. The map should also show transformations. If the integration translates a status or derives an indicator, reviewers need to distinguish that interpretation from the source value and follow a link back to the canonical record.
Start read-only and test permissions
A read-only Pilot reduces the chance of unintended source changes, but it is not automatically low risk. The credential may still expose more matters or data than the workflow requires. Use least privilege, separate test and production credentials and identify who can approve or rotate them. Test representative roles, restricted matters, closed matters and negative cases. A person who cannot open a matter in the source should not gain access through the integrated view. If the source API cannot express the firm's permission model, that limitation is an architectural decision, not a detail to defer. Decide whether the connector polls, receives events or relies on exports, and show users when information is stale or incomplete. Log access and processing at a level that supports investigation without creating an unnecessary duplicate store of client data.
Assess supplier and privacy responsibilities
Record the provider, subprocessors, hosting and access locations, security evidence, incident terms, retention, deletion, portability and change-notification process. The ASD procurement guidance is directed to particular government and organisational contexts, but its treatment of supply-chain risk, shared responsibility, contractual safeguards and decommissioning offers useful questions. It does not certify a vendor for a private law firm. Where personal information is involved and the firm is subject to the Privacy Act, assess the proposed collection, use, disclosure and cross-border handling against the APPs and the particular purpose. Other confidentiality, privilege, client and professional considerations require their own analysis. The checklist should name who makes each decision and retain the evidence reviewed, rather than collapsing due diligence into a yes/no security questionnaire.
Prove rollback, portability and offboarding
Test failure before launch. Revoke a credential, interrupt a refresh, remove a user's matter access and correct a source record. Confirm the integrated view becomes unavailable or stale in a visible way and never invents a replacement value. Then exercise the disconnect plan: export required decision records, disable the connector, verify source systems continue normally and request deletion under the agreed terms. The firm should know which derived records it needs to retain and which copies should be removed. Portability includes documented formats and enough context to interpret an export. Offboarding also covers a provider feature or subprocesser change that makes the original approval obsolete. A Pilot that cannot be cleanly stopped is not genuinely bounded. Treat the rollback result as an acceptance criterion alongside functionality, performance and user value.
Source file
Primary reading
- 01Actionstep API
Actionstep Help Center
- 02Get Started With Custom Fields
Clio Help Center
- 03Guidelines for procurement and outsourcing
Australian Signals Directorate
- 04Australian Privacy Principles guidelines
Office of the Australian Information Commissioner