CaseWizard

Roles and permissions

Define roles and assign granular permissions to users.

Roles and Permissions controls what users can view and change across cases, contacts, documents, calendar, billing, reports, integrations, and administration.

How permissions work

Permissions are organized in a tree of resources and actions. Create a role for a job function, select the actions that role needs, and assign the role to users. Review access whenever a person's responsibilities change.

Configure a role

Open Administration → Roles and Permissions.
Select Create for a new custom role, or open an existing custom role to edit it.
Review the permission tree and select the resource and action pairs the role requires.
Save the role after checking the selected permissions.
Open Administration → Users and assign the role to the appropriate user records.

Permission resources

ResourceTypical actions
CasesView, Create, Update, Delete
PeopleView, Create, Update, Delete, ViewPii
DocumentsView, Create, Update, Delete
CalendarView, Create, Update, Delete
BillingView, Create, Update, Delete, record payments, LEDES export
ReportsView, Generate, Export
Users and RolesManage
AuditView
IntegrationsManage SharePoint or Egnyte firm configuration
WebhooksView, Manage

The ViewPii permission is separate from ordinary people access. Consider it carefully because it controls access to personally identifiable information. Billing, report export, integration management, and user management also deserve specific review before you grant them.

Default and custom roles

Default system roles display a Default badge and cannot be deleted. Use a custom role when the system roles do not match your firm's responsibilities. Give the custom role a clear name that explains its purpose, such as a practice-area or operations role.

The sidebar is not yet filtered by permissions. A visible navigation item does not necessarily mean that the user can complete every action in that area.

Review access

Test a role with a representative user after saving it. Confirm that the user can complete required work and cannot access actions that are outside the role's responsibilities. Review the user's full role assignment, not only the most recently edited role, because multiple assigned roles can affect effective access.

When a staff member changes duties, update the user record and review all assigned roles. When a staff member leaves, deactivate the account in Users rather than relying only on role removal.

Next steps

On this page