For Florida law firms
Legal holds: a matter's records kept in every channel, and deletion that reaches every stored file
firm lane · Deterministic — no model call
Current availability
ShippedConfigured and enabled: firm staff of the matter's firm.
- Where it lives
- The matter's Records (/admin/matter/[id]/records) · Firm settings → Records (/firms/manage/records) · /api/admin/legal-hold
- What unlocks it
- the firm's own staff read; an attorney or administrator of the firm places and lifts a hold
Status is evaluated against this deployment's configuration by the capability-status service at build time; the catalogue's facts were last reviewed on the date shown.
Capabilities
- ShippedA hold keeps everything of a matter while it stands: the database refuses the deletion of the matter and of every record that carries it — for any person and for the platform's own server — and a signed-in person can neither delete nor overwrite its stored files.
- ShippedA hold carries two reasons kept apart: the public reason a person may be told, and the firm's confidential detail, which never leaves the firm and never enters the audit record.
- ShippedAn account deletion connected to a held matter waits whole — nothing is deleted, the request stays recorded with the public reason, and it resumes by itself when the last connected hold is lifted.
- ShippedDeletion reaches every stored file: every path the records name plus each folder walked to its depth, then walked again to prove it empty — no record is removed while a file remains.
- ShippedThe firm sees every matter on hold, the holds lifted and why, and how many account deletions wait on its holds (how many, never whose).
- ShippedA refusal under a hold says so wherever a person meets it — the delete controls on a matter, and the regenerations that replace a set on file (a probate filing set, a plan's documents, a matter's observations; the plan and the observations are asked before any drafting work) — never "try again".
Limits
- A hold is placed on a matter: holding everything of one person across matters means a hold on each of their matters.
- Derived machinery keeps its ordinary upkeep under a hold — the party index, notifications, bank-link tokens, reminder settings, saved bookmarks and live access control are not held (the access record is).
- A sandbox's holds are demonstrations: the sandbox sweep lifts them on the record before it removes the sandbox.
- An upload that never became a record (its registration failed) is removed by the platform's daily unregistered-upload cleanup after 24 hours, held matter or not — no record names it.
What EstateDraftFL refuses
| Reason code | HTTP | What it means |
|---|---|---|
| not-authorized | 403 | An attorney or an administrator of the firm, able to open the matter, places and lifts a legal hold. |
| firm-staff-only | 403 | Only the firm's own staff place or lift a hold; a support session reads. |
| invalid | 400 | A hold needs its public reason; a lift needs the reason it ends. |
| unknown-hold | 404 | That hold was not found on this matter. |
| already-lifted | 409 | That hold was already lifted. |
| legal_hold | 409 | A deletion, or a regenerate that would replace records on file, was refused because a legal hold applies — the matter's records are kept until the hold is lifted. |
| unavailable | 503 | The hold could not be read or recorded just now — nothing was changed. |
Evidence
- supabase/migrations/20260926233000_phase10c_legal_holds.sql
- src/app/api/admin/legal-hold/route.ts
- src/app/admin/matter/[id]/records/page.tsx
- src/app/firms/manage/records/page.tsx
- src/lib/legal-hold/policy.ts
- src/lib/storage-inventory.ts
- src/lib/account-data.ts
- src/lib/sandbox-cleanup.ts
- src/lib/mutate.ts
- docs/security/MASTER-PLAN-PHASE10C-2026-09-26.md
Last reviewed 2026-09-26