Skip to main content
HukukBis logo: Hukuk Bilgi İletişim Sistemi (legal information and communication system)

Who can see what?

A role is the name of a set of permissions. You build your roles from granular permissions and invite your team by email; everyone sees only the work they are cleared for.

Matrix of roles and permission groups
RoleCasesClientsDocumentsFinanceAIWebhooksRoles
Company ownerProtected rolePermission grantedPermission grantedPermission grantedPermission grantedPermission grantedPermission grantedPermission granted
AdministratorExcept webhooksPermission grantedPermission grantedPermission grantedPermission grantedPermission grantedNo permissionPermission granted
LawyerFinance and roles offPermission grantedPermission grantedPermission grantedNo permissionPermission grantedNo permissionNo permission
AssistantRead and data entryPermission grantedPermission grantedPermission grantedNo permissionNo permissionNo permissionNo permission
AccountingFinance focusedNo permissionPermission grantedNo permissionPermission grantedNo permissionNo permissionNo permission

Sample permissions of the selected role

Company owner

  • Manage roles
  • Create invoices
  • View cases
  • Manage integrations

Company owner

01/05Same screen, two roles

Same screen, two roles.

The company owner sees the whole menu. The assistant sees only the case, client and document screens; the other menu items never appear. A permission decides both the menu and the actions on the screen.

Whether a search result or a webhook and API action is visible depends on the same permission model; the access rules work the same way across the whole product.

A managing partner setting up a new associate's access
Access setup

Company owner · Case list

  • Cases
  • Clients
  • Documents
  • Finance
  • AI
  • Webhooks
  • Roles

Assistant · Case list

  • Cases
  • Clients
  • Documents
  • 4 menu items stay hidden
02/05Permissions, roles, structure

Your firm's structure carries into the software.

  1. 01/03

    Permission groups

    Permissions describe actions, not screens. Reading a case, updating it and deleting it are separate permissions, and so are creating an invoice and viewing one. Permissions are named by group and action, so what a role can do is written in plain terms.

    The groups follow the firm's daily work: cases, clients, documents, finance, AI, webhooks and role management.

    Cases
    View casesCreate casesEdit casesDelete cases
    Clients
    View clientsAdd clientsEdit clients
    Documents
    View documentsUpload documentsDelete documents
    Finance
    View invoicesCreate invoicesView payments
    AI
    Use AICreate drafts
    Webhooks
    View integrationsManage integrations
    Roles
    View rolesManage rolesInvite users
  2. 02/03

    Roles and invitations

    A role is the name of a set of permissions. You create a new role, tick the permissions one by one and assign it to as many users as you like. The intern sees only files, accounting only enters finance, the partners manage everything.

    One rule protects the company owner: the owner's role or status cannot be changed with delegated authority. Nobody can assign more permission than they could grant themselves. If you wonder where to start with role design, the guide to role and permission management in law firms suggests sample role sets.

    Adding someone to the team takes an email address and a role. The invitee follows the link in the email to the acceptance page, creates the account and joins the firm with the chosen role; you never need to know or send a password. Until they join, the invitation shows as pending. You can later move the user to another role or remove them from the firm; the change takes effect at once.

    Role and permission assignment simulation

    New role: Intern

    • Cases
    • Clients
    • Documents
    • Finance
    • AI
    • Webhooks
    • Roles
    Invitation sent

    The intern's menu

    • Cases
    • Clients
    • Documents
    • Finance
    • AI
    • Webhooks
    • Roles

    Create the role

    1. 1/5

      Create the role

      The administrator opens a new role and names it in the firm's own words.

    2. 2/5

      Tick the permissions

      Which actions the role may take in which groups is ticked one by one.

    3. 3/5

      Invite the user

      The new member is invited by email with the chosen role.

    4. 4/5

      The invitation is accepted

      The invitee creates the account on the acceptance page and joins the firm.

    5. 5/5

      The menu follows the access

      The user sees only the screens they are cleared for; other menu items never appear.

  3. 03/03

    Branches, teams and multiple companies

    Firms that work in several cities set up branches, and firms that split by practice area set up teams. You define branches and teams, attach members to them and set visibility with role permissions. The commercial team sees its own files, the criminal team its own; the partners see all of them.

    One person can work in several companies: for example in their own firm and in the legal department of a holding company. After login you choose the company to work in from the company selector, and the screen holds only that company's data. The corporate legal department solution shows this setup.

    Example Law Firm

    Istanbul branch
    Commercial team · Employment law team
    Ankara branch
    Criminal team

    Company selector

    • Example Law Firm
    • Example Holding Legal Department
03/05Account and data

Access only means something if the person logging in is the right one.

  • MFA

    Two-step verification can be turned on for every account; once on, a second verification step is required in addition to the password. As firm administrator you can make it the standard for the whole team.

  • Session

    Sessions stay open for a limited time. When a member is removed from the firm their open sessions end too; a departing employee does not find the door open the next day.

  • Password

    Strong password rules apply, and password reset and email verification flows are ready to use.

  • Firm separation

    Each firm's data stays inside its own boundary: a session can only see its own company's records. Separation between companies is not left to a screen filter.

  • Activity log

    Which user did which action on which record and when is logged. The bigger picture is on the security and KVKK page.

04/05Questions

What do people ask about roles and permissions?

  1. 01/05

    Are there ready-made roles?

    You define roles to fit your firm. Common roles such as administrator, lawyer, assistant or accounting take a few minutes to create by ticking permissions. The company owner role is protected and cannot be changed with delegated authority.

  2. 02/05

    Can a user work at more than one firm?

    Yes. The same user can be linked to several companies and chooses the company to work in from the company selector after login. The screen always shows only the selected company's data.

  3. 03/05

    What does a departing employee see?

    The sessions of a member removed from the firm end and their access to that company's data stops. Any other company their account belongs to is not affected.

  4. 04/05

    Can MFA be made mandatory?

    Two-step verification (MFA) can be turned on for every account; once on, login asks for a second verification besides the password. As firm administrator you can make it the standard for your whole team.

  5. 05/05

    Is branch data kept separate?

    Separation between companies always applies. For branches and teams inside one company you decide with role permissions who sees what; you open or close visibility across branches by your firm's own rule.

Set up access to match how the firm really works.