Lawden

All features

Security & Permissions

7 roles with 3-level permission overrides. Per-document, per-role access control. External users see only what you grant. Identity provider SSO available.

Why this matters

The old way

All-or-nothing access

Permission models are too coarse. External counsel gets more access than intended. No way to prove who saw what.

  • Permission models are too broad — all or nothing
  • External counsel gets more access than intended
  • No way to prove who saw which document
  • Compliance audits require manual log collection

The Lawden way

Granular control, complete audit

7 roles with a 3-level permission override chain. Set defaults globally, override per organization, or fine-tune per resource. Every access and action is logged and exportable.

  • 7 roles: Super Admin, Firm Owner, Firm Admin, Lawyer, Paralegal, Client, External Collaborator
  • 3-level permission chain: Global default → Organization override → Per-resource override
  • External users restricted to their assigned rooms by default
  • 22 deal room capabilities and 8 client capabilities with granular allow/deny
  • Document-level permission overrides for sensitive files
  • Login tracking with IP address and document view audit trail
  • GDPR self-service account deletion and data export
  • Data retention automation (90d users, 30d sessions, 365d logs)
  • Identity provider SSO via Google OAuth
  • Every access and action is logged and exportable

Key capabilities

Granular control over who sees what, with a complete record of every access and action. SSO, GDPR self-service tools, and automated data retention included.

7 roles with 3-level overrides

Global defaults → Organization overrides → Per-resource overrides. Set once at the org level, override for specific users or rooms.

Granular capabilities

22 deal room capabilities and 8 client capabilities. Each can be allowed, denied, or reset to role default — per user.

Document-level permission overrides

Restrict sensitive documents to specific individuals — even within a shared deal room. Full document-level permission support via resource-scoped capabilities.

Login tracking with IP

Every login is logged with IP address, user attribution, and timestamp. Document views are tracked in the activity log.

Audit log export

Every action logged and exportable in CSV or JSON. Ready for compliance reviews and eDiscovery.

GDPR self-service tools

Users can delete their account or export all personal data directly from settings. Soft-delete with anonymization and session revocation.

Data retention automation

Automated scheduled cleanup: deleted users removed after 90 days, expired sessions after 30 days, activity and audit logs after 365 days.

Identity provider SSO

Google OAuth integration ready. Activated when configured via environment variables.

Error monitoring

Sentry error tracking initialized at the platform level. Captures and alerts on unhandled exceptions in production.

Ready to transform your deal workflow?

Join hundreds of law firms using Lawden to close deals faster.