01/10
Typical firm roles
Five roles cover most small and mid-sized Turkish firms. The mono figure shows each role's relative breadth of authority out of 100.
- 01/05
Partner / administrator
Breadth of authority 100/100
- Sees
- All files, finance and users
- Does
- Assigns roles and permissions, adds users, reads reports
- Cannot
- Cannot change the firm owner's role through delegated rights
- 02/05
Lawyer
Breadth of authority 75/100
- Sees
- Assigned files and their clients
- Does
- Manages cases, deadlines, hearings and documents; uses the AI assistant
- Cannot
- Cannot change user and role settings
- 03/05
Trainee
Breadth of authority 40/100
- Sees
- Assigned files, read only
- Does
- Adds notes and supports document preparation
- Cannot
- Cannot reach invoices, payments or settings
- 04/05
Assistant / secretary
Breadth of authority 45/100
- Sees
- Client cards, agenda and appointments
- Does
- Enters inquiries and appointments, uploads documents
- Cannot
- Cannot edit case content or see finance
- 05/05
Accounting
Breadth of authority 35/100
- Sees
- Invoices, expenses and collections
- Does
- Issues invoices and follows payments
- Cannot
- Cannot reach case and document content
02/10
How is a new role set up from start to finish?
A fictional firm defines a trainee role, ticks the permissions, invites the user and sees the outcome in the audit log. On screen only one thing changes at each step.
- 01/05
The administrator opens a new role: Trainee. A role is given to a duty, not to a person; the same role can later be assigned to other trainees.
- 02/05
Read permission is ticked for case files, client records and documents. Billing, settings and the AI assistant stay unticked; there is no access.
- 03/05
Zeynep Çelik is invited with the Trainee role. The account is not active until the invitation is accepted.
- 04/05
When Zeynep Çelik signs in she sees only the Files, Clients and Documents menus and the three files assigned to her; the firm's other files do not appear in her list.
- 05/05
Creating the role, granting permissions, the invitation and the first sign-in appear in the audit log with who did it, when and on which record.
A role is defined
03/10
Least privilege: nobody sees more than their job needs
The principle is simple: give each user only the access they need to do their job, and nothing more. The cost of excess access usually appears when a mistake or bad intent occurs; until that day it is a risk that quietly accumulates.
In a law firm in Turkey, two heavy obligations back the principle. The first is professional secrecy: Article 36 of the Attorneyship Law prohibits a lawyer from disclosing what they learn through their work, and Article 37 of the Turkish Bar Association's Professional Rules requires the lawyer to take measures that prevent assistants and trainees from breaching secrecy. The second is the KVKK, Turkey's data protection law: Article 12 of Law No. 6698 obliges the controller to take the technical and administrative measures needed to prevent unlawful access to personal data. Role design is the everyday form of both duties.
Breadth of access under three designs
- Full access for everyone
- Every file, open to all
- Role-based access
- As much as the role needs
- Role and assignment based access
- Only assigned files
- Write down who does what first, then build the roles.
- Tie access to roles, not people, so a role stays the same when the person changes.
- When in doubt, withhold; open access when a reasoned request arrives.
04/10
Trainees and assistants: the secrecy duty reaches helpers too
Article 37 of the Professional Rules expressly asks a lawyer to take measures that prevent their assistants, trainees and employees from acting against professional secrecy. Put differently, the lawyer remains responsible for a breach by a trainee or assistant, so the access you give them is not an act of trust but a control decision.
In practice, read-only access and the right to add notes on assigned files is enough for a trainee, and client cards, appointments and document upload are enough for an assistant. Finance, user management and bulk export should stay closed to both. Obtain a written confidentiality undertaking when the relationship begins; the duty continues after they leave.
Two views of the same client card
Trainee
- Name and file summaryVisible
- Assigned casesVisible
- Notes (read)Visible
- ID and tax numberHidden
- Invoices and paymentsHidden
- Other lawyers' filesHidden
Assistant
- Name, phone, emailVisible
- AppointmentsVisible
- Document uploadVisible
- Case contentHidden
- Invoices and paymentsHidden
- SettingsHidden
05/10
The departing-employee procedure
When an employee leaves, access has to close at once, because a leaver with an open account is an outsider who can reach the firm's client data. Article 12(4) of the KVKK says people who learn data may not disclose it unlawfully and that this duty continues after they leave their post; closing access is its technical counterpart.
In HukukBis, removing a user from the team closes their open sessions and ends their access. Still, keep the procedure in writing; the sequence below gives most firms a workable skeleton.
Steps after the leaving date
Close the account
Remove the user from the team; sessions are closed and access ends.
Reassign files
Assign their files and alarms to another lawyer.
Review shares
Check document share links already sent to clients.
Devices and email
Change corporate email, device and shared-account passwords.
Review the records
Look at recent access and activity records.
Remind them of confidentiality
Tell them in writing that the duty continues after they leave.
06/10
Two-step verification (MFA)
Permission design means little if anyone who takes over an account inherits its authority. Two-step verification adds a second check so a password alone is not enough. Turn it on first for administrator and partner accounts, and for all users if you can. HukukBis offers two-step verification, requires passwords of 12 to 128 characters, and manages sessions on the server.
Legislation does not mandate MFA by name. Article 12 of the KVKK requires an appropriate level of security; what that means depends on risk, and for a system holding client confidences a second step is a reasonable expectation.
The two-step sign-in flow
- 01Password. The user enters email and password.
- 02Second step. An additional verification code or approval is requested.
- 03Role's authority. Only the screens the role allows open.
07/10
Audit and records: authority was granted, but is it used?
Setting up authority once is not enough; you also need to watch how it is used. Records of who changed which record, and when, support debugging, breach investigations and decisions to narrow a permission. In HukukBis each case keeps a chronological activity log and audit records are retained.
Review the role and user list once a quarter: are there accounts no one uses, has a role's scope grown, has one person collected more roles than needed? The review takes half an hour, and you often make the most valuable permission fix during it.
Sample activity record
Demo Lawyer
Changed stage Case 2026/42
Assistant A
Added appointment Client A
Accounting B
Sent invoice Invoice 1042
Trainee C
Added note Case 2026/42
08/10
The access matrix: who can do what on which resource?
The matrix is the checklist of role design. Write the firm's resources in the rows and the roles in the columns; each cell is a decision. Leave no cell blank or undecided, because an undecided cell tends to turn into a hidden full access.
In HukukBis the matrix maps straight into the product: roles can be customised for your firm, and any combination of fine-grained permissions is assigned to a role. Permissions are split by resource and action; reading a case and updating a case, for example, are separate permissions. The table below is a starting draft.
| Resource | Partner | Lawyer | Trainee | Assistant | Accounting |
|---|---|---|---|---|---|
| Case files | Full access | Limited write | Read only | Read only | No access |
| Client records | Full access | Limited write | Read only | Limited write | Read only |
| Documents | Full access | Limited write | Read only | Limited write | No access |
| Invoices and payments | Full access | Read only | No access | No access | Full access |
| User and role settings | Full access | No access | No access | No access | No access |
| AI assistant | Full access | Limited write | No access | No access | No access |
Limited write: Limited write means writing on records related to the role's work and assigned to the person.
Roles and permissions module09/10
Firm examples: one principle, three sizes
The number of roles grows with how work is divided, not with how big the firm is. Three draft setups:
- 01/03
A three-person firm
Three roles are enough in a small firm: managing lawyer, lawyer and assistant. The managing lawyer covers accounting, and the assistant does not see finance.
- Managing lawyer
- 01
- Lawyer
- 01
- Assistant
- 01
- 02/03
A twelve-person firm
As work divides, accounting and trainee roles separate. Lawyers write only on files assigned to them, while partners see everything.
- Partner
- 02
- Lawyer
- 05
- Trainee
- 02
- Assistant
- 02
- Accounting
- 01
- 03/03
A corporate legal department
A department separates outside counsel, in-house lawyers and reporting users; outside counsel see only their own files, and management-report users are read-only.
- General counsel
- 01
- In-house lawyer
- 04
- Outside counsel
- 03
- Reporting
- 01
10/10
Common questions about access management
- 01
Which files should an assistant see?
An assistant usually sees client cards, appointments and the agenda, with read-only or no access to case content. The decision depends on what the assistant needs to do the job; if the need is unclear, do not grant access, and open it when a request arrives.
- 02
What permissions should a trainee have?
Read-only access and the right to add notes on assigned files is usually enough. Invoices, user management and bulk export should stay closed. Under Article 37 of the Professional Rules, taking measures that prevent a trainee from breaching secrecy is the lawyer's responsibility.
- 03
Is two-step verification mandatory?
Legislation does not make two-step verification mandatory by name; Article 12 of the KVKK requires an appropriate level of security. In a system holding client confidences, a second step is a reasonable measure and should be switched on first for administrator accounts.
- 04
When should a departing employee's access be closed?
On the day they leave, ideally the moment the employment ends. In HukukBis, removing the user from the team revokes their open sessions. Review file reassignment, share links and device passwords the same day.
Related guide and modules
- KVKK Compliance Guide for Law Firms in TurkeyWhat Turkey's data protection law requires of a law firm as data controller, from inventory and privacy notices to retention, access control and breach reporting.Read the guide (11 min)
- Legal Document Security and E-Signature GuideA checklist for client documents in Turkey: upload checks, malware scanning, access rights, e-signature, retention and breach steps.Read the guide (19 min)
Related modules
- Roles and permissionsSet up roles and assign permissions.
- Security and KVKKLayered protection and data isolation.

