For Florida law firms
The deprovisioning door: ending a member's access, everywhere it reaches, with the reason on the record
firm lane · Deterministic — no model call
Current availability
ShippedConfigured and enabled: a firm's administrator; never themselves, never the firm's last administrator.
- Where it lives
- Firm settings (/firms/manage → Team → End access) · /api/firm/team
- What unlocks it
- the firm's administrator, for the firm's staff
Status is evaluated against this deployment's configuration by the capability-status service at build time; the catalogue's facts were last reviewed on the date shown.
Capabilities
- ShippedOne door ends a member's place at the firm: their membership, the API keys they minted (a key the firm approved as a service's stays), their queued and running jobs, their calendar feed and any calendar connection they made, and every session they hold.
- ShippedOnce the person belongs to no firm at all, their device checks and their phones with the app are revoked too (the app wipes itself and signs out the next time it opens).
- ShippedThe reason is required (left the firm, role ended, access no longer needed, a security concern, or another reason named), and the record says who, when, why and what each step ended; the firm's administrators read the recent departures on the team page.
- ShippedSingle sign-on does not let a departed person back in; inviting the address again is the way back (the departure is then marked invited back).
- ShippedA Clio connection the person made is named so the firm reconnects it under a current member.
Limits
- An access token already issued lapses on its own (within the hour); the membership is gone at once, so the firm's data is closed to it immediately.
- The person's sessions end everywhere (sessions belong to the person, not to one firm); they sign in again for anything else they belong to.
- The door does not delete what the person did: their work stays on the firm's record.
What EstateDraftFL refuses
| Reason code | HTTP | What it means |
|---|---|---|
| forbidden | 403 | Only the firm's administrator ends a member's access. |
| self | 400 | An administrator cannot end their own access — another administrator can. |
| invalid | 400 | A reason is required, and another reason needs a note. |
| not-a-member | 404 | The person is not a member of the firm's staff. |
| last-admin | 409 | A firm keeps at least one administrator. |
Evidence
- supabase/migrations/20261003220000_phase21_sso_deprovision.sql
- supabase/migrations/20261003230000_phase21_mobile_devices.sql
- src/app/api/firm/team/route.ts
- src/components/FirmTeam.tsx
- src/lib/sso.ts
- src/lib/phase21-sso-routes.test.ts
- scripts/rls-negative-suite.sql
Last reviewed 2026-10-03