All features
Security & Permissions
7 roles with 3-level permission overrides. Per-document, per-role access control. External users see only what you grant. Identity provider SSO available.
Why this matters
The old way
All-or-nothing access
Permission models are too coarse. External counsel gets more access than intended. No way to prove who saw what.
- Permission models are too broad — all or nothing
- External counsel gets more access than intended
- No way to prove who saw which document
- Compliance audits require manual log collection
The Lawden way
Granular control, complete audit
7 roles with a 3-level permission override chain. Set defaults globally, override per organization, or fine-tune per resource. Every access and action is logged and exportable.
- 7 roles: Super Admin, Firm Owner, Firm Admin, Lawyer, Paralegal, Client, External Collaborator
- 3-level permission chain: Global default → Organization override → Per-resource override
- External users restricted to their assigned rooms by default
- 22 deal room capabilities and 8 client capabilities with granular allow/deny
- Document-level permission overrides for sensitive files
- Login tracking with IP address and document view audit trail
- GDPR self-service account deletion and data export
- Data retention automation (90d users, 30d sessions, 365d logs)
- Identity provider SSO via Google OAuth
- Every access and action is logged and exportable
Key capabilities
Granular control over who sees what, with a complete record of every access and action. SSO, GDPR self-service tools, and automated data retention included.
7 roles with 3-level overrides
Global defaults → Organization overrides → Per-resource overrides. Set once at the org level, override for specific users or rooms.
Granular capabilities
22 deal room capabilities and 8 client capabilities. Each can be allowed, denied, or reset to role default — per user.
Document-level permission overrides
Restrict sensitive documents to specific individuals — even within a shared deal room. Full document-level permission support via resource-scoped capabilities.
Login tracking with IP
Every login is logged with IP address, user attribution, and timestamp. Document views are tracked in the activity log.
Audit log export
Every action logged and exportable in CSV or JSON. Ready for compliance reviews and eDiscovery.
GDPR self-service tools
Users can delete their account or export all personal data directly from settings. Soft-delete with anonymization and session revocation.
Data retention automation
Automated scheduled cleanup: deleted users removed after 90 days, expired sessions after 30 days, activity and audit logs after 365 days.
Identity provider SSO
Google OAuth integration ready. Activated when configured via environment variables.
Error monitoring
Sentry error tracking initialized at the platform level. Captures and alerts on unhandled exceptions in production.
Related
Explore more features
Due Diligence
Structured DD request lists, centralized Q&A, document review, and automated checklists — all in the deal room.
Document Management
Version control, smart folders, status workflows, and per-role access. Legal-grade document management.
Compliance
SOC-2 ready architecture with strict data isolation, encryption, and comprehensive audit logging.
Ready to transform your deal workflow?
Join hundreds of law firms using Lawden to close deals faster.