"Nobody uses it properly"
Sometimes true, usually incomplete. Adoption failures are normally design failures wearing a training costume: if the system takes eleven clicks to do what the old spreadsheet did in two, people are behaving rationally.
An org can pass every technical test and still cost the firm money every day — plans nobody follows, automation firing in an order nobody designed, reports two partners read differently. We inspect what is actually configured and running, then tell you what it is costing you and what fixing it is worth. The deliverable is findings and a costed roadmap, not a repair.
Trusted by 500+ organizations — including law firms and legal technology companies building their case, billing and reporting operations on Salesforce with Twopir Consulting.








Audit Coverage
None of these are diagnoses. Each one has several possible causes, and guessing wrong means paying to fix something that was never the problem — which is exactly what an audit prevents.
Sometimes true, usually incomplete. Adoption failures are normally design failures wearing a training costume: if the system takes eleven clicks to do what the old spreadsheet did in two, people are behaving rationally.
Almost always a definitions problem rather than a reporting one. Two dashboards answering the same question differently means two different date fields, two different stage interpretations, or free text where a picklist belonged.
Order of execution. Flows, validation rules and assignment logic added over time by different people, each one sensible alone, interacting in ways nobody has ever mapped end to end.
Or worse, failing silently. Most law firm integrations were built without retry logic, error alerting or reconciliation, so the first sign of a problem is a partner noticing a number is wrong weeks later.
Could be data volume, could be a trigger doing a query inside a loop, could be a page layout with fifteen related lists. These have completely different fixes and only one of them is expensive.
A sharing model that grew by exception. Every "can you just give them access to" request leaves a trace, and after two years nobody can state with confidence which roles see which matters.
A Litify audit is a structured inspection of what is actually configured and running in your org, delivered as a findings register with a costed remediation roadmap. We read the metadata, trace the automation, test the integrations, profile the data and look at how the system is genuinely used — then write down what we found, what it costs you, and what fixing each thing is worth.
Because Litify is a Salesforce application, a Litify audit is a Salesforce audit with legal-specific judgement layered on top. The technical inspection covers objects, fields, record types, Flows, validation rules, Apex, profiles, permission sets, sharing rules, page layouts, report types and integration configuration. The legal judgement is what tells us whether a matter plan makes sense for a defense practice, or whether a case type taxonomy will survive the firm's next hire.
The audit deliberately stops at findings. We do not change anything during it, and the roadmap is written so another partner could execute it. An audit whose conclusion is always "hire us for a large remediation project" is a sales document, and everyone can tell.
Objects, fields, record types, picklists and relationships — including the fields nobody has populated in two years.
Flows, validation rules, assignment logic and Apex, traced end to end for order of execution and conflict.
Profiles, permission sets, roles, sharing rules and org-wide defaults, against what the firm believes is true.
Every connected system, its auth model, error handling, retry behaviour and whether anyone would notice a failure.
Report types, dashboards and the metric definitions behind them — and where two answers to one question come from.
Completeness, duplication, stale records and the fields whose values contradict each other.
Who logs in, who creates records, which features are dead, and which workarounds have grown up beside the system.
Page load, list view and report timings, and the specific causes behind anything slow.
Pick by the decision you need to make. A board conversation needs different evidence from a remediation plan, and paying for depth you will not use is waste.
A one-week read across all six domains, sized to answer a yes-or-no question quickly. Enough to know whether the issue is real, roughly where it sits, and whether deeper work is justified.
Answers "Is this worth spending money on?" Not detailed enough to build a remediation plan from, and priced accordingly.
The standard engagement. Every domain inspected properly, every finding evidenced, each one costed in time or money, and a sequenced roadmap with dependencies mapped.
Answers "What is wrong, what is it costing, and in what order should we fix it?" This is the version most firms need.
For firms weighing a repair against a fresh org. Adds a data migration feasibility view and an honest comparison of the two paths, including the costs people usually forget.
Answers "Do we fix this or start again?" We recommend a rebuild only when the numbers support it, and we show you the numbers.
Scroll the table sideways →
| Every finding carries | What that means in the document | Why it is there |
|---|---|---|
| Evidence | The specific object, Flow, field, report or log entry the finding came from — quoted, with enough detail for your own admin to reproduce it. | Verifiable |
| Severity | Critical, high, medium or low, judged on operational and financial impact rather than on how technically untidy it is. | Verifiable |
| Cost of issue | What it costs today, in hours, write-downs, rework or risk. Where we cannot quantify it honestly we say so rather than inventing a number. | Judgement |
| Root cause | Why it is there — a design decision, an accumulation, a missing owner. Fixing symptoms without this is how orgs end up audited twice. | Judgement |
| Remediation effort | A sizing in days, split by configuration versus development, so you can see which fixes are cheap. | Judgement |
| Dependency | What must be fixed first. Sequencing is most of the value — several findings usually share one root cause worth fixing once. | Judgement |
The inspection is the same every time; the judgement is what changes. Below is what we actually look at, so you can tell whether an audit proposal is real or generic.
Where most serious findings originate. Case Type drives the questionnaire, the matter plan and every integration that creates an intake, so errors here propagate everywhere.
Traced end to end rather than listed. Individually sensible automations interacting badly is the most common cause of "it does things we did not ask for".
Compared against what the firm believes is true, which is usually the more useful comparison. Sharing models grow by exception and nobody re-reads them.
Not whether they are configured but whether they are reliable, and whether anyone would find out if they stopped.
Where "the numbers are wrong" gets resolved into a specific cause. Usually several causes, with one root.
What people actually do, measured rather than surveyed — plus the specific technical causes of anything slow.
An audit is only as good as its evidence. This is how we gather it — read-only throughout, and nothing in this list changes anything in your org.
A full retrieval of org metadata: objects, fields, record types, layouts, Flows, validation rules, Apex, profiles, permission sets and sharing configuration, analysed offline rather than clicked through in setup.
Reveals The complete configured surface, including everything added over the years and never removed.Who logs in, how often, what they create and which reports actually get run. Adoption claims and adoption data rarely match, and the data is the one worth acting on.
Reveals Dead features, unused fields, the gap between configured and used, and which roles have quietly disengaged.Field-level completeness, duplication, value distribution and contradiction across the record set. Sampled where volume requires it, always with the method stated.
Reveals Where the data cannot support the reporting the firm wants, and which fields are effectively abandoned.Every path a record can take on create and update, mapped across Flows, validation and Apex in execution order — the exercise almost no org has ever had done.
Reveals Conflicts, redundant logic, silent failures and the automation nobody remembers building.Error logs, failure rates and retry behaviour for every connected system, plus a reconciliation check between Litify and the systems it is supposed to agree with.
Reveals Silent failures, drift between systems, expiring credentials and integrations with no owner.Short sessions with each role to test what the evidence suggests. The metadata tells us what exists; people tell us why, and which of it anyone still relies on.
Reveals Intent behind odd configuration, the workarounds that never show up in data, and which findings matter most to the firm.Read-only from start to finish. We change nothing during an audit, which keeps the findings honest and means the engagement carries no risk to a live org.
Read-only access to a sandbox or production, plus agreement on which of the six domains matter most. We confirm the namespace, objects and package version in your org rather than assuming them.
Metadata retrieval, usage data, data profiling and integration logs — gathered systematically so the analysis runs on evidence rather than on a walkthrough.
Automation traced end to end, sharing model reconstructed, reporting definitions compared, data quality profiled. This is where the root causes separate from the symptoms.
Short sessions with each role to test what the evidence suggests and establish which findings the firm actually feels. Ranking without this is guesswork.
The findings register, cost-of-issue view and sequenced roadmap, delivered in a working session rather than emailed. Your admin should be able to reproduce every finding.
What we do not do during an audit We change nothing. No configuration, no deletions, no "quick fixes" along the way — partly because a live org deserves that discipline, and partly because an auditor who starts fixing things stops being able to tell you honestly what was wrong. The roadmap is written so another partner could execute it. If the answer turns out to be that your org is in good shape and the problem is elsewhere, that is a legitimate finding and we will say it.
An audit is cheapest when it is preventive and most valuable when it is decisive. These are the four points where firms get the most out of one.
When you are about to commit real budget to fixing something. Knowing the root cause first is the difference between fixing the problem and fixing a symptom of it.
A new COO, firm administrator or admin taking over a system nobody documented. An audit is the fastest way to know what you have actually inherited.
Adding a practice or a location to an org that is already strained. Better to know what will break before you multiply the load on it.
Agents read the records your team creates. If case types are inconsistent or matter data is thin, an agent will confidently produce output nobody should act on — and an audit tells you that before you find out the expensive way.
Two engagements from our legal practice. Both began by establishing what was really wrong before anything was rebuilt — which is the same discipline an audit applies on its own.
Twopir provided Salesforce customisation and integration services to help us build a robust, compliant, and scalable legal operations platform — connecting case management, document processing, and financial systems into one unified workflow. The result was transformative for how we run case-to-cash operations.
Streamlining case-to-cash operations with Salesforce, AWS and QuickBooks.
Twopir's specialized Salesforce customization enabled efficient integration of third-party systems and streamlined administration and billing, leading to seamless financial operations and enhanced productivity. Automated mass billing and matter management minimized errors across our entire legal workflow.
A 50% efficiency gain from Accounting Seed and Salesforce integration.
The value of a diagnostic depends entirely on its willingness to reach an inconvenient conclusion. We have told firms their org was healthy and the problem was elsewhere.
Litify's object and field reference sits behind a customer login, and public sources disagree on details as basic as the namespace prefix. We confirm the real objects, fields and package version in your org in week one — and we say so rather than quoting from a blog post.
The specific object, Flow, field or log entry it came from, quoted, with enough detail for your own admin to reproduce it. A finding you cannot check is an opinion, and opinions do not justify a remediation budget.
What a finding costs you today, in hours, write-downs, rework or risk. Without that you cannot tell a critical finding from a tidy one — and where we cannot quantify something honestly, we say so instead of inventing a number.
Several findings usually share one root cause worth fixing once. The roadmap is ordered so you get value early and never pay twice for the same underlying problem.
Written so another partner, or your own admin, could carry it out. We would like to do the work, but an audit whose only possible conclusion is "hire us" is a sales document and everyone can tell.
This page covers one service. Each one below goes into the detail a specific team needs — pick the one closest to the question you arrived with.
Six domains: the data model and case type taxonomy; automation and logic, including Flows, validation rules and Apex traced end to end for order of execution; security and sharing, compared against what the firm believes is true; integration health, including error handling and whether anyone would notice a silent failure; reporting and data quality, including where two reports disagree and why; and adoption and performance, measured from usage data rather than surveyed. Each finding carries its evidence, a severity, a cost of issue, a root cause, a remediation sizing and its dependencies.
A health check runs about a week; a full audit two to four weeks depending on org complexity and how many integrations are in play. We need read-only access to a sandbox or production, and short interview sessions with each role that uses the system. Nothing in the engagement changes anything in your org — the audit is read-only from start to finish, which is both safer for a live system and necessary for the findings to stay honest.
Rarely, and only when the numbers support it. Most struggling Litify orgs are technically live and operationally weak — the case type taxonomy was rushed, matter plans do not match how the team works, automation was layered on without an execution order, or reporting never had agreed definitions. That is repair work inside the existing org, and it keeps your history, your integrations and your users' logins. The pre-migration depth exists specifically to answer the repair-or-rebuild question properly, and it shows you the comparison rather than asserting a conclusion.
Not during the audit — deliberately. An auditor who starts fixing things loses the ability to tell you honestly what was wrong, and a live org deserves that discipline. The roadmap is written so another partner, or your own admin, could execute it. We are usually asked to do the remediation afterwards and are glad to, but the audit is priced and scoped to stand alone.
It is a Salesforce org audit with legal-specific judgement layered on top. The technical inspection is the same discipline — objects, fields, Flows, Apex, profiles, sharing, integrations, report types. What differs is the judgement: whether a matter plan makes sense for a defense practice, whether a case type taxonomy will survive the firm's next lateral hire, whether the sharing model actually supports an ethical wall. A generalist Salesforce audit will find the technical debt and miss the legal operating problems.
Yes, and this is one of the clearest cases for it. Every named agent — intake qualification, conflict checking, matter summaries, damages, invoice review — reads the records your team creates. If case types are inconsistent, matter data is thin or stage definitions were never agreed, an agent will confidently produce output nobody should act on. The audit tells you whether your data can support agents before you find out the expensive way, and the readiness finding is usually the most valuable page in the report.
A findings register where every item carries its evidence, severity, cost of issue, root cause, remediation sizing and dependencies; a cost-of-issue view that lets you tell a critical finding from a merely untidy one; and a sequenced roadmap ordered so the cheapest wins and the shared root causes come first. It is delivered in a working session rather than emailed, because the ranking conversation is where most of the value gets transferred.
A first conversation covers what is going wrong, how long it has been going wrong, and which audit depth actually answers your question. If a health check is enough, we will say so.
Read-only · evidence-backed findings · costed roadmap · executable by anyone