12 · Client experience
Collect what the matter needs. Answer the question before they call.
Your client gets a room of their own: what the firm needs from them, what is due next, the documents they may read, the decisions only they can make, and the bill with its backing attached. Every read into that room is default-deny, so what they see is what the firm published to them.
Four conditions clear before a document appears here, and they are read again next time.
The question in the room
“My client rings me every Thursday to ask what is happening, and I still do not have the three documents I asked for in March.”
The client-facing reads are default-deny and screened again on every read. One write path is not yet at that standard, and it is named in the repository rather than here for the first time: publishing an invoice notifies every enabled portal client on the matter instead of the one principal it belongs to, and it writes its thread message without the exact-recipient receipt the client feed reads. Until that writer carries a receipt, a co-client on the same matter can learn from the notice that an invoice exists.
How it works
The mechanism, not the promise.
What the client sees
A home that says where each matter stands, in the firm's published words
One card per matter: the stage, a calm or needs-you state, the attorney's published outlook, and a where-we-are narrative absent until a lawyer writes it. It computes no date, says so where no target is recorded, and reads a failed load as a failure.
A defending client is not narrated from the claimant's chair
The valuation model, claim tree and research breakdowns are authored in claimant terms, where a strong claim is good news. Where the firm defends, a banner re-attributes it first: a strong claim for the other side is the client's exposure, a weak one their defence.
A shared brief they can read, pinned to the version you shared
A shared document opens as text with its citations live, so a cite is something the client can follow. The version served is the exact one the attorney shared. A cite into a work-product memo returns as plain prose with its id and filename removed.
The two voices in the room
One thread, two voices, and the client always knows which
Bron answers questions about the matter; switching to the firm names, above the composer, the attorney and team who will read what follows. A sent question reports one of three things: delivered, saved with delivery unconfirmed, or failed with a retry and the firm's number.
No model output reaches this surface at all
A source census walks every file under the client portal and refuses a chart renderer, an exposure band, a probability field or a simulation snapshot. The assistant's markdown renderer default-denies a chart fence, and the portfolio contract carries no low or high field.
It is not a lawyer, and it hands strategy back to one
The assistant says it is not a lawyer, and may put the outlook in plain language. Its prompt is floored in code, so no row can weaken that, and its retrieval is restricted to client-visible material and skipped when the exclusion list cannot be read.
Getting what you need from them
A request that is a checklist, item by item
A document request arrives as a numbered checklist rather than one email asking for everything, and an item is satisfied by photographing the paper against it. The file is written to browser storage before the upload, and discarded only once the server receipt returns.
Three honest answers to an ask, not one
A client can provide an item, say they cannot get it, or ask what it means. Cannot marks that ask blocked, puts their words on the thread and raises an attorney item, so ask four stops hiding five through seven. Asking moves no obligation.
Where an upload stands, read off receipts rather than optimism
Received means the firm holds the file and claims nothing about a lawyer having looked at it. Under review means the request reached the state routing a review task to a named attorney, which is the receipt. Reviewed means an attorney advanced it.
Two principals on one matter stay two clients
Each answer set is reduced to the authenticated account before any state, count or answered flag is derived, so a shared item is not stamped answered because the other principal answered it. The browser draft key binds the account; an accountless draft is purged.
An answer routes itself to a licensed, unscreened attorney
Every accepted client response commits one content-free outbox row, and the drain has no lookback window, so an unfinished row survives a restart. It re-reads the exact source and account, then re-proves portal entitlement, firm tenancy, the conflicts screen, bar licence and matter access.
Decisions and money
A decision posed in your options, and a receipt rather than a second question
Settlement authority, an engagement change: the attorney poses it with two to twelve options they wrote, and the client picks one. The recipient is one enabled portal account, never inferred from the matter. The decision id is the idempotency key, and a changed retry conflicts.
A bill whose lines say what each one rests on
ShippedA line backed by an approved run's gate receipt, one backed by a time entry and one backed by nothing get different words, icons and colours, with no field keying one uniform tick. Checked and absent is a finding; could not check is a limit.
The executed copy lands in the portal, unless the order says otherwise
ShippedSigning runs in-house, and one function pushes the executed copy into the client's room by setting the visibility bit every read-side gate then trusts. An attorneys-eyes-only or unreadable designation withholds that push and writes nothing. Withholding is recoverable: the seal and anchor still stand.
The boundary, read again every time
Four conditions, all of them, on every read, and a check that could not run
ShippedA document reaches the portal when its privilege classification is one of two reviewed values, its client-visibility flag is true, it carries no attorneys-eyes-only designation, and no co-client uploaded it. Absence is denial on each; a failed lookup or truncated page refuses the whole set.
Two axes, deliberately not one column
The firm's own privilege verdict and a court's protective order live in separate columns. Putting an attorneys-eyes-only value on the privilege column was refused: it would force the reviewer's verdict and the court's order into one field, where one has to overwrite the other.
A whitelist, so a new column upstream is hidden until someone names it
Every client-facing row is copied field by field from a named list rather than spread, so a column added upstream arrives hidden. The matter row drops the theory of the case and referral metadata; the intake row drops attorney notes, extracted facts and internal research.
Refusals
What it will not do, and why.
- Show a client a document whose privilege review never happened.
- The classification gate is a positive allow-list of two reviewed values. Blank, unrecognized and never-classified are not clean, and a subtractive filter over an empty lookup removes nothing and leaves the document sitting in the client's room. The set of ids a client may see is built up, never narrowed down.
- Read a designation it could not fetch as no designation at all.
- An absent attorneys-eyes-only marking and a failed read of that column are different facts. Silence is not a restriction; a failed read is not determinable and refuses the whole candidate set rather than a quietly smaller one. A page returning at the database row cap counts the same way, because a truncated screen loses restricted ids quietly. The asymmetry is the control.
- Let one portal client see another's own upload.
- Two principals on one matter are two clients, and what one hands the firm is the firm's to read and not the other's. The uploader exclusion runs strict on the paths that serve document text, so a denylist that cannot be computed refuses the read rather than falling back to no exclusion.
- Reclassify a document to get it around a protective order.
- The refusal names the axis on purpose, so nobody reaches for the wrong one. Attorneys-eyes-only is a court-ordered access restriction, not a privilege verdict, and an adversary's production can be correctly classified confidential, which the privilege gate admits, and still be forbidden to the party under the order. The remedy is recoding the designation in discovery review or obtaining relief from the order, and the message says so instead of leaving the attorney to improvise.
- Tell a client their upload was reviewed because it arrived.
- Reviewed is a claim about a lawyer's attention. Each state is the reading of a receipt that already exists, and a status the code could not read reports as unknown. A file sitting in a folder and a file an attorney has read must not render as the same sentence.
- Assemble the matter's weak spots for the client.
- The plain-language outlook is theirs to have. The strategy, the vulnerabilities, the arguments the other side would use and the internal settlement figure are work product, and no tool may be used to reassemble them. The question is answered by naming the attorney who handles it and is flagged for that attorney rather than quietly dropped.
- Give every line of the bill the same tick.
- A client who learns that the tick beside a gated receipt is the tick beside a hand-typed entry has been taught, by us, that our ticks are decoration. Four results, four sets of words: passed, failed, checked and absent, and could not check. The last two never converge. A line whose amount could not be read says so rather than showing zero.
- Hand a client a directory of everyone else on their matter.
- Item delegation is one grant, for one current item, authorized by firm staff. What the client sees is a frozen, attorney-approved label on that exact grant. The request's original recipient never changes, so the co-client privacy boundary stays where it was drawn.
- Put a deadline's description in front of the client.
- What is due and when is the client's. The description column carries the engine's authority and tolling caveats and, on a hand-entered date, free-text attorney strategy, so it is not on the list a client-facing deadline row is copied from. Two client reads once forwarded the whole row. The matter timeline is screened the same way, joining the published record with a separately screened chronology.
- Ask a client to decide the same thing twice.
- An exact retry returns the immutable row already recorded; a retry that changes the option or the note is refused as a conflict instead of overwriting the first answer. A transient failure in the task that tells the lawyer is repaired on the next close, not by putting the question back in front of the client. The stored option is a key and a label and nothing else, so no extra field rides along into the client payload.
One record
Nothing here stands on its own.
What feeds it
- The matter record and its phase
- Document requests and intake
- Deadlines and appointments
- Invoices, trust and the fee arrangement
- Signature envelopes
What it feeds
- The daily board and the brief
- Discovery answers and productions
- The responsible attorney
- Collections and the trust ledger
- The audit trail
Limits
What this does not establish.
- A read-side gate is not a write-side gate. Every condition described here runs when a client reads. A writer that composes its own client-facing notice is governed by the receipt it writes, which is why the invoice notice above is stated as open rather than described as closed.
- The portal shows what the firm published to this client. It is not a representation about material nobody recorded, and it is not a representation about material nobody shared.
- The outlook a client reads is the qualitative note an attorney published. The per-matter range, the claim tree and the simulation stay on the firm side, and no figure from them reaches this surface.
- On a matter with two principals the intake pipeline is one row with one status and one set of timestamps. Answer content stays isolated, and a co-principal can still infer from a status that moved that somebody submitted something.
- Delivery is reported, never assumed. A published update whose out-of-band notice failed is genuinely published and the client is genuinely uninformed, and the surface is built to say which of those happened.
Check the work before you believe it.
Run a sample manifest in your own browser, or read where publication refuses for want of evidence.