Who can see what, and who decided.
A firm’s reputation rests on discretion. Roles decide what each person can see and do, restricted matters stay restricted, and the sensitive actions — deleting, exporting, moving money — are gated and recorded.
Access that matches how a firm actually works
Roles for real job titles
From reception to managing partner, with permissions set the way your firm works rather than the way a template assumed.
Restricted matters stay restricted
Sensitive files can be limited to the people on them, so confidentiality is enforced by the system rather than by asking nicely.
Changes to access are recorded
Who granted what, when, and to whom — so a question about access has an answer attached to it.
What this protects
- Confidential matters stay confidential. A conflict-sensitive file is not visible to the whole firm simply because someone is curious.
- Departures are clean. Access ends when someone leaves, without needing to remember which shared drives and passwords they held.
- Sensitive actions are deliberate. Deleting records, exporting data and moving money require the right role — and leave a trace.
- Reviews get easier. When an insurer, auditor or regulator asks who could see what, the answer is a report rather than a reconstruction.
Permissions are only as good as the roles a firm defines; the defaults are sensible, and we will show you what they are and where to change them at the demonstration.
How a firm sets this up
Start from the firm’s roles
Reception, paralegal, associate, partner, accounts, practice manager — adjusted to the firm’s own titles.
Restrict what must be restricted
Matters that need limiting are marked, and access is granted to the people working on them.
Set sign-in policy
Two-factor required for the roles that handle money or client data; session length set to the firm’s comfort.
Review twice a year
Access is reviewed alongside the firm’s own compliance cycle, with the record showing what changed.
Set the roles with us
Bring your firm’s job titles to a walkthrough and we will show the roles, the restrictions and the sign-in policy in place.