Roles and permissions
Define roles and assign granular permissions to users.
Roles and Permissions controls what users can view and change across cases, contacts, documents, calendar, billing, reports, integrations, and administration.
How permissions work
Permissions are organized in a tree of resources and actions. Create a role for a job function, select the actions that role needs, and assign the role to users. Review access whenever a person's responsibilities change.
Configure a role
Permission resources
| Resource | Typical actions |
|---|---|
| Cases | View, Create, Update, Delete |
| People | View, Create, Update, Delete, ViewPii |
| Documents | View, Create, Update, Delete |
| Calendar | View, Create, Update, Delete |
| Billing | View, Create, Update, Delete, record payments, LEDES export |
| Reports | View, Generate, Export |
| Users and Roles | Manage |
| Audit | View |
| Integrations | Manage SharePoint or Egnyte firm configuration |
| Webhooks | View, Manage |
The ViewPii permission is separate from ordinary people access. Consider it carefully because it controls access to personally identifiable information. Billing, report export, integration management, and user management also deserve specific review before you grant them.
Default and custom roles
Default system roles display a Default badge and cannot be deleted. Use a custom role when the system roles do not match your firm's responsibilities. Give the custom role a clear name that explains its purpose, such as a practice-area or operations role.
The sidebar is not yet filtered by permissions. A visible navigation item does not necessarily mean that the user can complete every action in that area.
Review access
Test a role with a representative user after saving it. Confirm that the user can complete required work and cannot access actions that are outside the role's responsibilities. Review the user's full role assignment, not only the most recently edited role, because multiple assigned roles can affect effective access.
When a staff member changes duties, update the user record and review all assigned roles. When a staff member leaves, deactivate the account in Users rather than relying only on role removal.