Skip to content

Concept

Roles, permissions and scopes

What a person may do is decided by the permissions their roles grant, each at a scope, never by the name of their role.

Permissions, not job titles

Every action in the system asks for a permission: recording time asks for one, approving a document for another, posting a journal for a third. The system never asks whether someone is a partner. It asks whether they hold the permission, which means the firm, not the software, decides what each person may do.

A role is a named set of permissions. The firm starts with eleven, from managing partner down to receptionist, and changes them as it sees fit. A person can hold more than one role, and what they may do is everything their roles grant together.

The roles register with the number of people holding each role.
The firm's roles, with the number of people holding each.

Scopes

Many permissions are granted at a scope, which says whose records the permission reaches:

ScopeReaches
OwnRecords that are the person's own, such as their own time.
SupervisedTheir own, the people who report to them, and the matters they partner.
Practice areaEverything in the practice areas they belong to.
AllThe whole firm.

So an associate may hold Record time at own scope, while the head of litigation holds See recorded time at practice area scope.

A role's permissions, each granted at a scope.
A role's permissions, each granted at a scope.

Rules that always hold

  • The managing partner holds every permission.
  • Nobody may grant a permission they do not hold themselves.
  • An ethical wall overrides every permission, the managing partner's included.
  • The firm administrator role cannot lose the management of people and roles, and the managing partner role cannot lose the emergency override, so the firm can never lock itself out.
  • A role that people still hold cannot be deleted; move them to another role first, or deactivate it.

Was this helpful?