Five questions a law firm CIO should ask before adding IP operations software: SSO and provisioning, DMS exposure, M365 fit, AI sprawl, exit terms.
The partner in the patent group bought it in March. Nobody told you. In June, the vendor’s completed security questionnaire lands in your inbox, forwarded with one line: “Can you approve the DMS connection by Friday?” The invoice is paid. The training is booked. You’re the last to know and the first to answer for it.
That’s the normal order at most firms, and it’s backwards. The five questions below are the ones to ask before the invoice, about any IP operations software. We’ve answered each one for PracticeLink where we can. Where a straight answer depends on the vendor, we’ve said what a good one contains.
Does it support single sign-on with our identity provider, and how are users provisioned?
Yes. PracticeLink supports single sign-on through Microsoft accounts on Azure, through Azure B2C for firms that need to accept more than one kind of sign-in account, and through Windows domain authentication. SSO can be optional or required. B2C tenants are the firm’s to manage, in its own Azure portal. Underneath all three sits role-based access through users and groups.
Provisioning is the half of the question vendors skip, so don’t let them. Ask three things. How does a new user get created? How does a departing user lose access the same day HR closes the account? Do the roles the tool uses line up with groups your directory already knows about? A good answer names the mechanism and names who owns it. A vague answer means your help desk owns it, one ticket at a time.
If it connects to our document management system, does that create new exposure?
It shouldn’t, and there’s a simple test for whether it does. PracticeLink works with iManage and NetDocuments, among other document systems. Who can see a document inside PracticeLink, including inside a client portal, follows the permissions already set in your DMS. Where a document gets filed is decided by rules configured up front, not picked on the fly by whoever happens to be holding it.
The test. Take a matter with an ethical wall on it and a user who’s outside that wall. Log in as that user. If the document is visible through the new tool, you’ve found exposure the vendor didn’t mention. If it isn’t, the tool is inheriting your permissions instead of inventing its own.
Then verify a few more things with any vendor. Where the DMS credentials live, whose account they run under, and how they’re rotated. Which folders the tool writes to, and which it only reads. What happens to work in flight when the DMS is down for maintenance. And where a misfiled document goes. PracticeLink has error and soft-delete destinations configured per DMS instance, so a document that can’t be filed lands in a known place instead of a random folder. Ask every vendor that last one and watch how long the pause is.
Where does it run, and does it fit an M365 shop?
PracticeLink runs on Microsoft Azure as a cloud service. Your users work in a browser. There’s nothing to install on desktops and no server to stand up in your rack.
For a firm already on Microsoft 365, that means sign-in through the Microsoft accounts your people already have, and a hosting provider your team already knows how to evaluate. Ask any vendor, ours included, to put the hosting provider and region in writing. It’s a one-line answer. The ones who can’t give it in one line are telling you something.
On security controls, the list you’ll want on paper is SSO, role-based access, encryption, and audit trails. We keep written security best-practices documentation and recent penetration testing reports, and both are available on request. Ask every vendor for the actual test report, not the summary slide. Read the date on it. Then ask what’s changed since.
We already have too many AI tools. Does this add another one?
No. PracticeLink isn’t a drafting tool, a research tool, or a chat window. It’s the place where the output of the AI tools your firm already runs lands on the matter and moves to the next person who has to act on it.
Say the firm has eighteen AI tools spread across practice groups. Each one produces something, and each something sits in its own tab until a person notices it, saves it, names it, and files it. That’s the sprawl that actually costs you. Not eighteen logins. Eighteen places work can stall. You don’t fix that by buying a better generator. You fix it by giving all eighteen one place to land and one review step before anything touches the matter.
A restaurant kitchen doesn’t get calmer by hiring a sixth cook. It gets calmer when every plate goes through one pass before it leaves. Same idea. The drafting tools your attorneys picked keep doing what they do. PracticeLink is the pass. If you want the longer version of this argument, we wrote up the AI questions to ask before you buy.
Does this add a vendor to manage, or reduce the ones we have? And what do we own if the contract ends?
Honest answer: it adds one contract and asks you to remove none. PracticeLink works with the docketing system and the DMS your firm already runs. There’s no migration off either, and neither gets replaced. That’s a deliberate trade. One more vendor, in exchange for not owning a replacement project for the two systems your practice can least afford to disturb.
The exit question is the one to get in writing from anyone. For PracticeLink, the plain version is this. Your docket stays in your docketing system. Your documents stay in your DMS. Your matter records stay in the systems that own them today. PracticeLink reads from those systems and moves work between them, so the systems of record are yours and are where they always were, contract or no contract.
And the firm decides, workflow by workflow, who does the keystrokes. Your own team on one process, an outside service on another, with visibility of all of it from one place either way.
That choice stays with you.
Ask any vendor one more thing. What do you hold that we don’t, and how do we get it back? Every vendor holds something. The good ones can list it.
The tools attorneys want will keep arriving, and more of them will have AI in the name. The ones worth approving will answer these five without a follow-up call. For the operations side of the same evaluation, the buyer’s checklist is the list your operations director should be carrying. And how PracticeLink connects your existing IP tools shows where PracticeLink sits alongside the systems you already run.
Our security documentation and most recent penetration test report are available on request.