For Florida law firms
Disclosure classes and shares: who outside the firm may receive each document
firm lane · Deterministic — no model call
Current availability
ShippedConfigured and enabled: firm staff of the matter's firm.
- Where it lives
- The matter's Disclosure (/admin/matter/[id]/disclosure) · Firm settings → Disclosure (/firms/manage/disclosure) · /api/admin/disclosure · a share's link (/shared/[token])
- What unlocks it
- the firm's own staff read; an attorney or administrator of the firm classifies, shares and withdraws
Status is evaluated against this deployment's configuration by the capability-status service at build time; the catalogue's facts were last reviewed on the date shown.
Capabilities
- ShippedEach document (each version) is classified for the audiences outside the firm that may receive it — the client, a household co-planner, a fiduciary, a beneficiary — or for the firm only; the four are kept apart, and none implies another.
- ShippedA document nobody has classified stays with the firm: the client's portal, their helpers, a share and a signature request all refuse it until it is reviewed. The client side always sees what the client side uploaded.
- ShippedOne rule in the database decides every surface: the client's list, detail, download, search and portal, the files in storage, the extracted fields that quote a document, a share's link, the staff's preview, the client-safe decision packet and e-signature.
- ShippedA share gives one named recipient a link to chosen documents already classified for their audience; it closes when it expires (ninety days at most) or is withdrawn, and a document leaves an open share at once if its class stops naming the recipient's audience.
- ShippedStaff preview exactly what the client — or the recipient of any open share — sees, computed by the same rule.
- ShippedBeneficiary status links close when they expire or when the trustee or the firm withdraws them.
- ShippedFirm work product the client could read before — AI and workspace runs, drafts, reviews, analyses and chat — now answers only to its author and the matter's staff until it is delivered through the approved pathway.
Limits
- The platform does not send a share's link: the link is shown once, and the firm sends it.
- A household co-planner, a fiduciary or a beneficiary receives documents only through a share; there is no family-wide view.
- A new version of a document starts unreviewed; its class can be carried from the version it replaces, on the record.
- The client-safe decision packet lists only the documents the client may receive — the others are counted, never named.
What EstateDraftFL refuses
| Reason code | HTTP | What it means |
|---|---|---|
| not-authorized | 403 | An attorney or an administrator of the firm, able to open the matter, decides what leaves the firm. |
| firm-staff-only | 403 | Only the firm's own staff decide what leaves the firm; a support session reads. |
| not-shareable | 409 | A chosen document is unreviewed, not classified for the recipient's audience, not past the upload check, or without the recorded fingerprint a share pins — nothing was shared. |
| paused | 409 | New shares are paused for the firm; existing shares keep working. |
| shares-disabled | 503 | New shares are switched off on the platform; existing shares keep working. |
| not-classified-for-sharing | 409 | A document goes out for signature only once it is classified for someone outside the firm. |
| closed | 404 | A share's link has expired, been withdrawn, or never existed — the same answer for each. |
| unavailable | 503 | The rule could not be asked just now — nothing was changed and nothing was sent. |
Evidence
- supabase/migrations/20260926190000_phase10b_disclosure_classes.sql
- src/app/api/admin/disclosure/route.ts
- src/app/admin/matter/[id]/disclosure/page.tsx
- src/app/shared/[token]/page.tsx
- src/app/api/shared/download/route.ts
- src/lib/disclosure/policy.ts
- src/lib/disclosure/server.ts
- docs/security/MASTER-PLAN-PHASE10B-2026-09-26.md
Last reviewed 2026-09-29