For Florida law firms
Capabilities, limits and refusals
Every firm surface with its current availability — shipped, staged, owner-gated, dark or retired — what it does, what it does not do, the typed reasons it refuses, and the evidence behind each line.
Shipped68
- Trustee duties packet and the trustee portal (TrusteeClear module)
Configured and enabled: always on; the solo lane records, the firm lane routes to the firm.
The packet organizes duties and deadlines; every action is your recorded decision, and the firm lane routes it to your firm.
- Firm workstation review · OCP · redline · cite-check (Opus 5)
Configured and enabled: firm staff only; the direct tenant refuses (HTTP 410).
Every result is work product for your own review on a paid matter; the citation panel verifies statutes against the corpus and cases for existence only.
- Grounded lane (litigation-class draft/review over SHA-256-pinned public filings)
Configured and enabled: firm staff; never instruments (gate-pinned).
Grounded operations run only on litigation classes with a usable public foundation; instruments are never grounded on filings.
- Case-citation existence check (CourtListener)
Configured and enabled: on when the token exists; treatment (Westlaw/Lexis) stays dormant.
Cite Check verifies that a case exists; whether it is still good law is a citator question the platform does not answer.
- Word add-in (deterministic in-document check)
Configured and enabled: sideloaded; Word on Windows and Mac (WordApi 1.4) — Word on the web not supported.
The add-in checks deterministically under your own session; an edit lands only as a tracked change you can reject.
- Outlook add-in (Beneficiary/Creditor Shield)
Configured and enabled: staff session; nothing auto-sends; the compose check runs with no model.
The pane proposes a classification a person confirms, and checks a message before you send it — the send is always yours.
- Calendar — ICS deadline feed
Configured and enabled: always on; fail-closed.
The feed carries confirmed dates — proposed ones only if you switch them on, labelled; it is read-only and revocable, and your circuit's practice may adjust a date.
- Square checkout (consumer offers, per-matter activations)
Configured and enabled: always on.
Every purchase settles through the provider's signed webhook; nothing unlocks on a browser redirect alone.
- Square firm subscriptions (Practice · Firm · Group)
Configured and enabled: always on (owner order 2026-09-19).
Subscriptions renew monthly through the provider and cancel from the console at the end of the paid month.
- Platform API v1 — scoped keys, honest pages and proposals (/api/v1)
Configured and enabled: firm admins mint scoped keys; the API reads, and its one write files a proposal the firm decides.
A key reads the firm's matters as ids and states under the grant its admin chose; it executes nothing — its one write is a proposal the firm decides.
- Matter Brain (firm matter Q&A over the record)
Configured and enabled: firm staff on the matter's tenant.
The Matter Brain quotes the record it can see — one primary document plus the structured rows — and names what it did not read.
- Firm drafting engines (caged drafter, draft support, letter studio)
Configured and enabled: firm staff; the consumer branch is deterministic-only (Decision A).
The drafter rephrases inside a cage over a deterministic skeleton; anything the cage rejects reverts, and the attorney adjudicates every suggestion.
- Document organization (classification, extraction, vault intelligence, trust analysis)
Configured and enabled: firm tenants only; the direct tenant answers HTTP 410 or a fail-soft skip.
Organization runs over clean uploads only and proposes labels and fields the firm confirms.
- Observations and statement import
Configured and enabled: firm tenants only.
Observations and imported statement rows are proposals for the matter team to confirm.
- Assistant, Deep Research and chat (firm tenants)
Configured and enabled: firm tenants only; the direct tenant answers HTTP 410 before any model call.
Conversational surfaces serve firm staff only; the self-help lane has none.
- Monday briefing, dispute-readiness narrative, statute-change sweep, hearing prep
Configured and enabled: firm staff; deterministic fallbacks where declared.
Digests and memos summarize deterministic records; they never predict an outcome.
- Reminder cron (email)
Configured and enabled: firm tenants get composed reminders; the direct tenant gets deterministic copy naming no firm.
Reminders are scheduled platform mail; the self-help lane receives deterministic copy only.
- Statute cards (general information)
Configured and enabled: generate-once per section, pinned to the law-version hash, cached.
A statute card explains a section in general terms; the section's own text, held verbatim, is the authority.
- Revision-bound approvals and approved delivery
Configured and enabled: firm staff; the attorney acts are refused to every other role (a platform admin is not a firm's attorney).
Every consequential act binds to the exact state its approver reviewed, once; a working copy is never a delivery.
- The chained record, verification manifests, the decision packet and the file hand-over
Configured and enabled: firm staff of the matter's firm; the ledger record and its Verify now are platform-admin only.
The record is checkable without trusting us, and every check says what it could not prove.
- Public verification: /verify, the offline verifier and the trust root
Configured and enabled: public; the document-file lookup is throttled per address and globally.
Checks run where the visitor is; only a fingerprint ever reaches us.
- Sources: every document version, its text beside its original, and find-in-source
Configured and enabled: firm staff of the matter's firm.
Every statement can be taken back to the exact words of the exact version it came from — or it says it cannot.
- Source-change impact: what each piece of work rested on, and what to review when that changes
Configured and enabled: firm staff of the matter's firm; the rollback lever SOURCE_IMPACT_PROPAGATION=off stops new proposals.
When a source changes, the work that used it is named — and a person, not the system, decides what changes.
- The propositions ledger: what the record says, and what says otherwise
Configured and enabled: firm staff of the matter's firm; the rollback lever PROPOSITION_SUGGESTIONS=off keeps model suggestions out.
The ledger shows what the record says and what says otherwise — it never scores the answer.
- Coverage manifests on every workspace run
Configured and enabled: every review, Opposing Counsel Pass, redline and cite-check run on the run lane.
A reviewer can see exactly what each engine was given — and what it was not.
- Matter workbench: source, issue, draft and decision in one place
Configured and enabled: firm staff of the matter's firm.
Source → issue → draft → decision without losing the place: every engine stays itself, and nothing decided elsewhere is overwritten.
- Revision memory: every redline decision kept against its exact base, and a tracked Word file that matches the final
Configured and enabled: firm staff of the matter's firm.
A decision stays with the exact base it was made on; the tracked file and the final never disagree.
- Overview & chat and Clients & matters: the matter in focus, its record and the assistant beside it
Configured and enabled: firm staff of the matter's firm.
The pages show the record as it is; the opening card is composed, never generated, and the assistant is the workspace's, gates and all.
- Saved conversations: every assistant conversation, reopened where it left off
Configured and enabled: firm staff of the matter's firm.
A conversation is its ledger rows — nothing new is stored to list them.
- The Matter command center: the client record, team and next steps of one matter in one place
Configured and enabled: firm staff of the matter's firm.
The center shows the matter's record as it is; every decision stays on the panel that makes it.
- The team's tasks on a matter: an owner, a target date and a status, checked off when done
Configured and enabled: firm staff of the matter's firm.
The team's tasks are the firm's own — never the client's steps, which stay in the client's portal.
- Review & decisions: each finding of a matter's document review decided by the firm, the decision record kept, then finalized and exported
Configured and enabled: firm staff of the matter's firm.
Every decision is the attorney's, recorded by the review's own door; the page composes the record, it never decides.
- Drafting desk: a plan's documents edited as working versions, with comments, version history and comparison, then exported
Configured and enabled: firm staff of the matter's firm.
A working copy is never an approved delivery; the plan's own version is the one the firm approves, on its workstation.
- Conflict screen of the firm's own records at every door
Configured and enabled: firm staff of the matter's firm.
The firm's own book is screened before anything exists — a finding is for an attorney's judgment, and no match is never a clearance.
- Engagement holds: an attorney decides each finding, then clears the hold
Configured and enabled: firm staff of the matter's firm.
A finding holds the engagement until an attorney decides it; the client never reads the finding.
- The firm's own conflict registers: declined parties, prior affiliations, joint representation
Configured and enabled: the firm's governance roles.
The firm keeps its own registers; every entry stays on the record, and nothing asks for a Bar number or a licence.
- The firm's consult door: a request screened before anyone opens it
Configured and enabled: any visitor on a firm's host; the firm's staff read the requests.
A prospect's request is screened before anyone opens it, and the prospect is never told what the screen found.
- The client intake: six steps a firm invites its client to, sent as a screened consult request
Configured and enabled: a member of the firm in a governance role invites; the invited address claims the intake once.
The client's answers are theirs until they send; the firm reads them only after its own records were screened for every name.
- Matter teams and ethical walls, enforced in the database
Configured and enabled: firm staff of the matter's firm.
A wall is a database policy, not a hidden button: a walled member of the firm reads nothing of the matter anywhere.
- Disclosure classes and shares: who outside the firm may receive each document
Configured and enabled: firm staff of the matter's firm.
A class is a database policy, not a label: an unreviewed document stays with the firm on every surface until someone here reviews it.
- Legal holds: a matter's records kept in every channel, and deletion that reaches every stored file
Configured and enabled: firm staff of the matter's firm.
A hold is database law, not a flag: the platform's own deletion paths are refused like anyone's while it stands.
- A matter's lifecycle: closed and archived with their reasons on the record, and an archived matter read-only everywhere
Configured and enabled: firm staff of the matter's firm.
Archived is database law for people and a question every server door asks — read-only, never deleted.
- Retention: the firm's policy, what it makes eligible, and the deletion of an eligible matter with its receipt
Configured and enabled: firm staff of the active firm (the direct consumer account has no retention policy).
Retention decides what MAY be deleted; a person deletes it, the database refuses anything a hold keeps, and the receipt stays.
- Deletion requests: a firm's client asks the firm to delete their records, and the firm answers on the record
Configured and enabled: a person whose matter sits at a firm (the direct consumer account deletes its own records itself).
A person asks and the firm answers on the record; the database refuses a 'deleted' that is not true, and a hold is named while it stands.
- Referrals: a client sends their matter to a Florida firm with recorded consent and a fresh sign-in
Configured and enabled: a client with a matter on the direct service; the list names active Florida firms only.
A referral carries the fingerprint of the words the client agreed to and a sign-in of the last ten minutes; the database writes both together and refuses a referral without them.
- Firm control: what the firm's rules enforce today, the engines it permits per surface, its house voice, and what no setting moves
Configured and enabled: a member of a firm's staff, with the second factor.
A firm may take a capability away and never add one; each switch is read by the code it names, Opus 5 is never a switch, and the house voice changes wording, never the law a draft carries.
- Document requests: the firm asks, the client answers one of three honest ways, and every upload says where it stands
Configured and enabled: a firm's matter — the firm's staff with the second factor on the firm side; the matter's own people in the client room.
The client answers in their own words and never decides anything legal; an answer reaches an attorney before anyone is told it is under review, and only an attorney calls it accepted or reviewed.
- Decisions answered once, and where things stand in the attorney's own words
Configured and enabled: a firm's matter — an attorney of the firm with the second factor on the firm side; the matter's client and active co-principals in the client room.
A decision card carries the attorney's question and options and the client's choice — never advice written by software; the account of the matter is absent until an attorney writes it.
- Pinned shares: a share's link gives exactly the version that was shared
Configured and enabled: every share of a firm's matter — pinned when it is made.
A share gives the bytes that were shared and nothing else; a newer version is a new share, made by the firm.
- Two clients on one matter stay two clients
Configured and enabled: a firm's matter whose conflict check is clear and records joint representation, with the joint consent dated.
Two clients on one matter stay two clients: nothing one of them does is ever shown as the other's, and what they share, they share by choice.
- Every computed date shows how it was reached
Configured and enabled: a firm's matter — the firm's staff; a walled matter's derivations never appear.
A date is only as sound as its rule and the event it counts from — the derivation names both, and never guesses a missing one.
- Three-way reconciliation: the bank's figure, the ledger's cash, and principal plus income
Configured and enabled: anyone who can open the matter.
A bank figure no one supplied is not a zero: "not reconciled" is the honest reading until someone types the statement.
- Two attorneys for a large outflow: the firm's release threshold
Configured and enabled: a firm with at least two attorneys, whose administrator has set a threshold.
Two attorneys above the line, one below it, and anyone may ask the trustee to hold — the database, not the page, holds the rule.
- Statements frozen when executed: an accounting, or a beneficiary's distribution statement, kept as its exact bytes and hash
Configured and enabled: anyone who can open the matter reads; a firm's staff (on its matters) or the direct service's trustee executes.
An executed statement is its bytes and their hash: a correction is a new statement, and a signed receipt keeps the hash it acknowledged.
- The reconciled trust ledger for accounting software: QuickBooks Online, Xero and the fiduciary ledger, from an executed accounting
Configured and enabled: a firm's staff, on an executed accounting whose period end the ledger reconciles at.
The export is the statement in another shape, and only over a reconciled ledger: a statement that is not ready says what opens it.
- Execution evidence: each instrument's signing pinned to the approved version, its steps as facts, and a record that completes only on its evidence
Configured and enabled: a firm's staff on the firm's estate-plan matters; a signing is prepared only on a version approved by the firm's recorded review decision.
A signing stays on the version it was prepared on, and its record completes only on evidence — never on a box ticked.
- Funding as evidence: each asset's way into the plan, its standing read from evidence with its basis — never from a box
Configured and enabled: a firm's staff on the firm's estate-plan matters; an asset funds the trust of an approved, released version.
A line on Schedule A lists an asset; only evidence — with its basis — says where it stands.
- Firm playbook: the firm's own clause text, approved version by version — never over the client's instructions
Configured and enabled: a firm's administrators, attorneys and paralegals propose; only the firm's attorneys approve and retire.
A firm's preference never overrides what the client instructed: the client's instruction tokens are a variant's floor.
- Estate-plan brief: the client's instructions, the differences with the firm's playbook and the extracted facts, and the package read against itself
Configured and enabled: the firm's staff, on a plan whose drafting is unlocked.
Nothing is inferred: the brief repeats the client's own words, and a difference is shown — never resolved — by the platform.
- Estate-plan review and the Opposing Counsel Pass, run explicitly on a version's documents
Configured and enabled: the firm's staff, on a plan with a drafted version.
A review informs the attorney's judgment; it never replaces the attorney's decision, or a word of the document.
- Administration handoff: from the approved plan (or the vault file) to the trust administration or the probate — the event, the facts confirmed, authority verified, no access granted
Configured and enabled: a firm's administrators, attorneys and paralegals prepare and record; only the firm's attorneys verify authority and activate.
A death or role record never grants access: the firm invites the fiduciary itself, through the email-bound, conflict-screened invitation, when it decides.
- Signed webhooks: nine events as they happen — ids and states only, signed, at least once, never about a matter with a wall
Configured and enabled: the firm's admin (or a webhooks:manage key) registers, tests, rotates and disables; deliveries run every five minutes.
Verify each delivery's signature before trusting it, and de-duplicate by its event id — a delivery may arrive more than once.
- The dispute preparation pack: the chronology, the issues with their sources, the requests to draft and the approved filing set
Configured and enabled: the firm's staff, on a matter they can open.
The pack is the record in order, with its sources: it predicts nothing and sends nothing; the firm's attorney decides what is used.
- The deprovisioning door: ending a member's access, everywhere it reaches, with the reason on the record
Configured and enabled: a firm's administrator; never themselves, never the firm's last administrator.
Leaving ends everything the person held at the firm, in one transaction, with the reason kept — and an invitation is the only way back.
- Redline, Opposing Counsel Pass™ and Cite Check: the firm's runs of each, and a new one
Configured and enabled: firm staff.
The lane pages list what ran; every run is the workspace's, on its own terms.
- Tasks & calendar: every task and date across the firm's matters
Configured and enabled: firm staff.
A date's authority is its matter's: the page gathers them, the Tasks tab decides them.
- TrusteeClear™: the firm's trust administrations, each with its duties, ledger, statements and beneficiaries
Configured and enabled: firm staff.
The trustee's duties are the trustee's; the page shows where each matter stands.
- Documents & templates, Team & permissions, Billing & integrations: what the firm keeps, governs and connects
Configured and enabled: firm staff.
A hub gathers; each page it opens governs its own record.
Staged5
- Citator treatment (Westlaw KeyCite · Lexis Shepard's)
Built and dormant until a partner provisions credentials: partner credentials from Thomson Reuters / LexisNexis.
Treatment slots are dormant until a citator partner provisions credentials; existence checks run today.
- Calendar — OAuth push (Google / Microsoft)
Built and dormant until a firm turns it on: the firm's own OAuth credentials.
OAuth push waits on your firm's own credentials; the ICS feed needs none.
- Clio — matter link and packet export
Built and dormant until a firm turns it on: the firm's own Clio credentials.
Clio is staged behind your firm's own Clio account; once connected, a matter is linked deliberately and only an approved packet is exported, then checked back.
- DocuSign / e-signature (scoped)
Built and dormant until a firm turns it on: DOCUSIGN_BASE_URL · ACCOUNT_ID · ACCESS_TOKEN.
E-signature is staged behind your firm's DocuSign credentials, and wills, trusts, powers of attorney and health care directives are never sent through it — they are signed at the supervised ceremony.
- Plaid / bank sync
Built and dormant until a firm turns it on: the firm's own Plaid credentials.
Bank sync is staged behind your firm's own Plaid credentials and is read-only when it runs.
Owner-gated10
- ChatGPT 5.6 Sol tier and the dual consensus mode
Waiting on the platform owner: the governed OpenAI key (owner gate).
The alternate engine and the dual mode appear only once the platform owner configures the second engine; nothing pretends otherwise.
- Fable 5 tier (per-document surcharge)
Waiting on the platform owner: FABLE_DRAFT_SURCHARGE_CENTS (owner prices it).
The maximum tier is priced per document and stays disabled until the owner names that price.
- Stripe (alternate rail)
Waiting on the platform owner: STRIPE_SECRET_KEY · WEBHOOK_SECRET (+ tier prices).
Stripe is a dormant alternate rail; Square carries every live purchase.
- Transactional email (Resend) and the delivery ledger
Waiting on the platform owner: RESEND_API_KEY (present) + RESEND_WEBHOOK_SECRET (absent — the ledger is blind).
Mail sends today; delivery confirmations depend on a webhook secret the owner has not yet set.
- Turnstile on public forms
Waiting on the platform owner: NEXT_PUBLIC_TURNSTILE_SITE_KEY (absent); the firm consult door also verifies server-side with TURNSTILE_SECRET_KEY.
Public forms work today; the bot challenge mounts once the owner keys it.
- Upload malware scanner (quarantine pipeline)
Waiting on the platform owner: SCANNER_* (absent); structural checks always run.
Every upload passes structural validation; an external malware scan runs only once the owner arms a scanner — the receipt says which.
- External monitor bearer (HEALTH_TOKEN)
Waiting on the platform owner: HEALTH_TOKEN (absent).
Liveness is public; the detailed health read waits on a bearer the owner has not yet set.
- The governed MCP server: the firm API's reads as tools for an AI assistant, and one tool that files a proposal
Waiting on the platform owner: PLATFORM_MCP_ENABLED — until the platform sets it, /mcp answers 404 to every request.
An assistant connected here reads what the key may read and nothing more; whatever it proposes, the firm decides.
- Single sign-on for a firm: its own identity provider, its own domain, just-in-time membership
Waiting on the platform owner: SAML 2.0 turned on for the Supabase project, then SSO_SAML_ENABLED=1 on the deployment, and each firm's provider registered with `supabase sso add` (owner steps, docs/auth/SSO-OWNER-GUIDE.md); Supabase Pro includes 50 single sign-on users a month, then $0.015 each.
The firm proves its domain, the platform activates, and the person's own identity record decides which firm they join — never the request.
- The EstateDraftFL app for iPhone and Android: sign in, matters, send a document, notifications, remote revocation
Waiting on the platform owner: the owner's Expo project, the sign-in allow-list entry estatedraftfl://auth/callback, Apple (and, for Android notifications, Firebase) credentials through Expo's build service, the store submissions, then MOBILE_APP_PUBLISHED=1 on the deployment (mobile/README.md).
The app is a door to the same platform, as the same person: nothing it holds outlives a revocation, and nothing on a lock screen names a matter.
Status is evaluated against this deployment's configuration by the capability-status service at build time; the catalogue's facts were last reviewed on the date shown.