Health Check · Legal

Salesforce health checks for legal.

Law firms and legal service providers run a health check to confirm that client confidentiality holds inside the CRM, not just in the document system.

What health check looks like for legal

A legal health check looks at the relationship and business development data firms keep in Salesforce, and at the confidentiality controls around it. We review how clients, matters, referral sources and prospects are modeled, who can see which relationships and whether ethical walls from the conflicts process are mirrored in the org. We also check intake flows, email and calendar capture, contact imports from lateral hires and whether attorneys actually use what was built. The report ranks confidentiality and privilege exposure first, followed by data quality and adoption issues that limit marketing and business development teams.

Why it differs

Why legal is different.

Law firms hold relationship data with obligations most businesses do not face. The fact that a company is a client, or is considering litigation, can itself be confidential. Ethical screens can restrict attorneys and staff from particular clients or matters, and those restrictions need to reach every system, including the CRM. Automatic email capture can pull privileged correspondence into records that marketing staff can read. Attorneys are also reluctant users, so data entry often falls to assistants and marketing teams who may lack context. A useful review looks at confidentiality, capture and adoption together, because problems in one usually explain the others.

Scope

What the work covers.

Ethical wall alignment review

We compare how screens are recorded in your conflicts or risk management process with how access is actually restricted in Salesforce. Sample screened users are tested against the affected clients, matters and related contacts. Where Salesforce relies on a manual step to apply a wall, we document the gap and how long a newly screened person could still see protected relationships.

Email and activity capture audit

Automatic capture tools can log client emails, meeting notes and attachments to Salesforce records. We review what is captured, which domains and folders are excluded and who can read the resulting activities. Particular attention goes to privileged communications and matter details that business development staff should not be viewing, along with retention settings for captured content. Shared inbox capture receives its own separate check.

Lateral hire contact imports

Incoming partners often bring large contact lists that are loaded quickly to support their practice. We look at how those imports were handled, how many duplicates they created, whether personal contacts and opposing parties were filtered out and whether the new records respect existing relationship ownership. The findings show whether import procedures need tightening before the next lateral group arrives.

Attorney adoption and data quality

We measure how often timekeepers and practice leaders log in, which records they update and where assistants or marketing staff fill gaps. Relationship fields, industry tags and practice area coding are checked for completeness. The goal is to show whether cross-selling reports and pitch lists draw on current, reliable information, or on data that stopped being maintained long ago. Stale relationship partner assignments are counted too.

Approach

How we run it.

We begin with the chief marketing or business development officer and the person responsible for firm technology, then bring in the general counsel or risk team for anything involving confidentiality. A small group of partners and assistants is interviewed about daily use. Access is read-only, and we review metadata and permissions instead of reading client communications. Confidentiality findings are delivered privately to the risk team first. The final report is organized so marketing, IT and risk can each see the items they own.

Conflicts and intake system

We check whether new clients, matters and ethical screens flow into Salesforce promptly and whether screen changes update access automatically or depend on someone remembering.

Practice management and billing

We review how matter, originating attorney and billing data reach Salesforce and whether revenue figures shown to business development staff are appropriately summarized.

Document management system

We confirm that links between Salesforce records and client documents respect workspace security and do not expose file names or content to unauthorized users.

Plan for it

What to get right first.

01

Treat client identity as confidential

Professional conduct rules generally require firms to protect information relating to a representation, which can include the identity of the client. The review shows where such information is visible, so firm counsel can decide whether current controls are adequate. It informs that decision without offering legal advice.

02

Filter capture before it starts

It is much easier to exclude privileged or sensitive email from automatic capture than to find and remove it later. Review capture rules, excluded domains and internal-only folders, and make sure attorneys understand what the tool logs before expanding it to more practice groups.

03

Check screens before AI search

Generative search and summaries across relationship data are powerful for pitch preparation. They are also an efficient way to surface a screened client to the wrong attorney. Test AI features with screened users before rollout, and confirm that every restricted record stays hidden in responses and summaries.

FAQ

Health Check for legal: questions.

Does the review look at client files or privileged content?

No. We work from configuration, permissions, capture rules and aggregate measures, and we test visibility with sample users rather than reading communications. Where a finding requires confirming that sensitive content exists, a firm staff member performs that check with our guidance. This keeps the review consistent with your confidentiality obligations while still producing specific, actionable findings.

Our in-house legal department uses Salesforce. Does this apply to us?

Yes, with a different focus. Corporate legal teams often use Salesforce for request intake, contract questions or matter tracking alongside the business's own org. We review how legal records are separated from sales and service data, who in the wider company can see them and whether legal hold or retention requirements are respected by any automated cleanup jobs.

Why do our cross-selling reports seem unreliable?

Usually because the data underneath is incomplete or inconsistent. Industry and practice codes vary by who entered them, relationship partner fields go stale when attorneys leave and duplicate company records split activity across several accounts. The review traces a few reports back to their source records and shows which fixes would make them trustworthy enough to guide client teams.

Can the health check cover our events and marketing list management?

Yes. Client events, alerts and newsletters generate a lot of contact data and consent questions. We review how subscription preferences are stored, whether unsubscribes sync between marketing tools and Salesforce and whether invitations respect ethical screens and client sensitivities. Accidentally inviting an adverse party to a client seminar is exactly the kind of risk the review looks for.

Planning health check for legal? Let’s talk it through.

One onshore team with 150 Salesforce certifications, a Salesforce Consulting Partner since 2017.

Tech Talk

A monthly brief for the people who own Salesforce, AI and revenue technology

What changed in Salesforce and AI this month, and what to do about it.

One email a month. Written by the consultants who deliver the work, not by a marketing team, for the leaders who make the technology decisions.

  • What changed in Salesforce, AI, integration and RevOps, and what it means for your org
  • At least one framework, checklist or reference architecture you can take into a meeting
  • Honest opinions, including when we disagree with what a vendor is selling
  • No sales sequence. We do not sell from this list

Consultant analysis, not vendor recaps. One click to leave.

One email a month. Your industry and your address, nothing else. We never share either, and you can unsubscribe from the bottom of any issue. See what’s in Tech Talk →

Call (314) 916-4095 Book a consultation
Call (314) 916-4095 Book a call