Skip to contentSaltar al contenidoAle nan kontni anПерейти к содержимомуדלג לתוכן
EstateDraftFL

For Florida law firms

The deprovisioning door: ending a member's access, everywhere it reaches, with the reason on the record

firm lane · Deterministic — no model call

Current availability

ShippedConfigured and enabled: a firm's administrator; never themselves, never the firm's last administrator.

Where it lives
Firm settings (/firms/manage → Team → End access) · /api/firm/team
What unlocks it
the firm's administrator, for the firm's staff

Status is evaluated against this deployment's configuration by the capability-status service at build time; the catalogue's facts were last reviewed on the date shown.

Capabilities

  • ShippedOne door ends a member's place at the firm: their membership, the API keys they minted (a key the firm approved as a service's stays), their queued and running jobs, their calendar feed and any calendar connection they made, and every session they hold.
  • ShippedOnce the person belongs to no firm at all, their device checks and their phones with the app are revoked too (the app wipes itself and signs out the next time it opens).
  • ShippedThe reason is required (left the firm, role ended, access no longer needed, a security concern, or another reason named), and the record says who, when, why and what each step ended; the firm's administrators read the recent departures on the team page.
  • ShippedSingle sign-on does not let a departed person back in; inviting the address again is the way back (the departure is then marked invited back).
  • ShippedA Clio connection the person made is named so the firm reconnects it under a current member.

Limits

  • An access token already issued lapses on its own (within the hour); the membership is gone at once, so the firm's data is closed to it immediately.
  • The person's sessions end everywhere (sessions belong to the person, not to one firm); they sign in again for anything else they belong to.
  • The door does not delete what the person did: their work stays on the firm's record.

What EstateDraftFL refuses

Reason codeHTTPWhat it means
forbidden403Only the firm's administrator ends a member's access.
self400An administrator cannot end their own access — another administrator can.
invalid400A reason is required, and another reason needs a note.
not-a-member404The person is not a member of the firm's staff.
last-admin409A firm keeps at least one administrator.

Evidence

  • supabase/migrations/20261003220000_phase21_sso_deprovision.sql
  • supabase/migrations/20261003230000_phase21_mobile_devices.sql
  • src/app/api/firm/team/route.ts
  • src/components/FirmTeam.tsx
  • src/lib/sso.ts
  • src/lib/phase21-sso-routes.test.ts
  • scripts/rls-negative-suite.sql

Last reviewed 2026-10-03

← All surfaces