For Florida law firms
Revision-bound approvals and approved delivery
firm lane · Deterministic — no model call
Current availability
ShippedConfigured and enabled: firm staff; the attorney acts are refused to every other role (a platform admin is not a firm's attorney).
- Where it lives
- /api/admin/approvals · /api/admin/deliveries · approve, finalize, clear, accept, send, respond and confirm
- What unlocks it
- firm staff on the matter's tenant; approving, finalizing and delivering need an attorney-level role and the firm's responsibility confirmation
Status is evaluated against this deployment's configuration by the capability-status service at build time; the catalogue's facts were last reviewed on the date shown.
Capabilities
- ShippedEvery consequential act — approve and deliver a packet, finalize a review, clear or decline a trustee's action request, accept a referral, send for signature, resolve a beneficiary request, confirm a §736.1008 limitation notice, deliver an approved version — first shows a receipt card: ids, version, the SHA-256 digest of what was reviewed, counts, the names of unconfirmed values and who the act reaches. Never document text.
- ShippedConfirming spends a single-use token that lives ten minutes and is bound to that digest and to the act's arguments (decision, recipients, acknowledgements); concurrent confirmations resolve to one winner in the database.
- ShippedTwo-pass batch approval on the review queue and the beneficiary-request queue: pass one mints receipts for the picked items and executes nothing; every receipt starts unticked; pass two spends only the ticked receipts, each through its own route.
- ShippedApproved delivery: a separate act that seals the exact version an attorney decision covers, renders its exact bytes, records the authorization, writes the client's portal record and sends an e-mail notice through the outbox with the provider's receipt; working-copy exports stay available and labelled and are never a delivery.
- ShippedThe workspace Ask marks any reply that reads as a completed act with "No action was performed — this is a proposal." — the Ask lane takes no action.
Limits
- Approved delivery covers the firm estate-plan lane (the generation-bound review decision) and the firm probate lane (the filing-set digest recorded on the review decision). A probate approval recorded before revision binding must be recorded again before it can be delivered.
- The trust-administration packet's approval remains its delivery to the trustee's portal (one bound act), as it always was.
- The e-mail leg needs the client's deliverable address and the transactional mail provider; without them the portal record is the delivery, and the record says so.
- The recipient is the matter's own client, re-checked at execution together with the version's disclosure class (Phase 10): a firm's estate plan or probate filing set is the client's by kind.
- No override exists for: finalizing a review with open recommendations; delivering or approving without an attorney-level role and the firm's responsibility confirmation; sending a notice whose recipient address fails validation.
- Two acts carry a recorded override, written to the audit trail before the act runs (and nothing runs if it cannot be written): approving past below-threshold values, and delivering despite open plan-check errors.
What EstateDraftFL refuses
| Reason code | HTTP | What it means |
|---|---|---|
| approval-required | 428 | The act was called without a receipt's token; open the receipt card and confirm it. |
| approval-stale | 409 | The subject changed after the receipt was shown (a new draft, a moved date, a changed request); review the current state. |
| approval-args-changed | 409 | The decision, recipients or acknowledgement differ from the receipt that was confirmed. |
| approval-expired | 409 | Receipts last ten minutes. |
| approval-consumed | 409 | The receipt was already used; every approval is single-use (a replay is refused). |
| approval-invalid | 409 | The token does not belong to this act, subject or person. |
| approval-unavailable | 503 | The approval record could not be checked, so nothing was done (fail closed). |
| attestation-required | 403 | The act needs an attorney-level role and the firm's responsibility confirmation — no override. |
| recipient-invalid | 400 | A notice's recipient address failed validation — no override. |
| open-findings | 409 | The plan check reports errors; resolve them, or acknowledge them (recorded before delivery). |
| decision-stale | 409 | No attorney decision covers the current version; approve the current version first. |
| decision-not-revision-bound | 409 | The probate approval predates revision binding; record it again on the current filing set. |
| working-copy-not-deliverable | 409 | A working copy is never an approved delivery. |
| not-a-firm-matter | 409 | A self-help matter has no attorney decision to deliver; a customer's election is never an approval. |
| already-delivered | 409 | This exact version is already delivered to this client. |
| recipient-not-member | 409 | The matter's client is no longer a member of the firm. |
Evidence
- src/lib/approvals/bind.ts
- src/lib/delivery/approved.ts
- supabase/migrations/20260925120000_phase5_approval_tokens_delivery.sql
- docs/security/MASTER-PLAN-PHASE5-2026-09-25.md
Last reviewed 2026-09-26