For Florida law firms
Referrals: a client sends their matter to a Florida firm with recorded consent and a fresh sign-in
both lanes · Deterministic — no model call
Current availability
ShippedConfigured and enabled: a client with a matter on the direct service; the list names active Florida firms only.
- Where it lives
- The client's matter (/matter/[id]) → Refer to a Florida firm · the firm's Today page (/admin) → Incoming referrals, with the receipt card before acceptance · /api/transfer/firms · /api/transfer/request · /api/transfer/accept · /api/transfer/decline
- What unlocks it
- a client of the direct service, signed in within the last ten minutes, refers their own matter to an active Florida firm; the firm's staff accept or decline it
Status is evaluated against this deployment's configuration by the capability-status service at build time; the catalogue's facts were last reviewed on the date shown.
Capabilities
- ShippedThe client chooses an active Florida firm and consents in their own language (five languages); the consent records the fingerprint of the exact words shown and their version, with the browser, the address and the firm named.
- ShippedSending needs a sign-in from the last ten minutes: an older one is answered "confirm it's you" — a fresh sign-in link that returns the client to their matter.
- ShippedThe database is the one writer: the consent and the referral are written together, a referral is refused without the client's own consent for that matter, and a matter has one open referral — asking again answers with it.
- ShippedThe firm sees whether each referral carries its recorded consent and accepts only one that does: the accept door and its receipt card refuse one without, and the approval binds the exact consent.
Limits
- A referral starts from the direct service: a matter already held at a firm is that firm's record and is not referred from it.
- Documents stay on the client's own matter; the firm's copy starts from the role check (the boundary before the conflict check).
- Changed consent wording is a new version with its own fingerprints — a page left open across the change is asked to reload before it sends.
What EstateDraftFL refuses
| Reason code | HTTP | What it means |
|---|---|---|
| consent required | 400 | The client ticks the consent before the referral is sent. |
| reauth_required | 401 | The client's latest sign-in is older than ten minutes — sign in again with a fresh link, which returns to the matter. |
| not found | 404 | The matter was not found among the client's own on the direct service. |
| destination not found | 404 | The firm is not an active Florida firm accepting referrals. |
| consent-text-changed | 409 | The consent wording changed since the page loaded — reload to read it, then send. |
| consent-not-recorded | 409 | The referral carries no recorded consent — the firm asks the client to send it again. |
| unavailable | 503 | The referral could not be read or recorded just now — nothing was changed. |
Evidence
- supabase/migrations/20260928200000_phase10c_transfer_consent.sql
- src/app/api/transfer/request/route.ts
- src/app/api/transfer/accept/route.ts
- src/lib/transfer/consent.ts
- src/lib/transfer/reauth-server.ts
- src/components/TransferRequest.tsx
- src/components/TransfersInbox.tsx
- docs/security/MASTER-PLAN-PHASE10C-PART4B-2026-09-28.md
Last reviewed 2026-09-28