Login lands on the portal chooser, workspace access issues a platform-scoped session for approved owner accounts, and direct login loops are rejected.

Enterprise launch hardening
Operational control record for secure access, paid-seat continuity, reviewed imports, output safeguards, incident recovery, and full platform owner access.
Platform owner access opens all portals through the post-login chooser.
Enterprise control gates
Active MRR seats remain Pro Se, Attorney, and Family Communications while institutional portals remain separated from paid-seat navigation.
Connector material stays staged until a person reviews destination, scope, and merge intent before promotion.
Paid-value outputs carry review posture, scope labels, and neutral wording before use outside the workspace.
Family Communications stays private by default; protective posture requires sustained harmful patterns and reviewed output controls.
The account workspace now exposes launch proof, enterprise readiness, connections, recovery, and route inventory from the portal chooser.
Paid-seat feature and safeguard matrix
- • Guided intake
- • Evidence registry
- • Timeline intelligence
- • Service/proof posture
- • Court-day packet
- • Settings and recovery
- • Review-required extracted facts
- • Private notes excluded from court packets
- • Court-neutral language
- • Folder upload and connector recovery
- • Matter workspace
- • Task and deadline posture
- • Evidence review
- • Discovery summary
- • Client-safe report
- • Professional packet output
- • Privileged notes stay private
- • Client-safe preview boundary
- • Reviewed connector imports
- • Court/client/private scope labeling
- • Private Family Mode
- • Structured threads
- • Saved drafts
- • Calm message templates
- • Before You Send review
- • Parent-safe digest
- • Private by default
- • No evidence-first framing
- • No single-message protective trigger
- • Reviewed digest before export
Owner operating runbook
- Access check
Open the secure sign-in page, sign in with the assigned method, confirm /portal opens before any workspace.
Pass signal: Portal chooser shows active paid seats and, for approved platform owner accounts, institutional portals.
- Seat smoke
Open Pro Se, Attorney, and Family Communications from the portal chooser and confirm each lands on its primary workspace.
Pass signal: Each active seat opens without an empty dead end and exposes settings, connections, recovery, reports, and exports where relevant.
- Import safety
Open connections and recovery surfaces for paid seats and confirm staged import review remains visible.
Pass signal: Imported records remain staged until reviewed and can be recovered after interrupted work.
- Output safety
Open launch readiness and enterprise readiness, then review packet/export/privacy safeguards.
Pass signal: Court-facing, client-safe, private, and family-communication outputs are separately labeled.
- Preservation check
Confirm deferred institutional routes remain available only through full-access portal selection and are not promoted as active MRR seats.
Pass signal: Judicial and justice surfaces remain preserved while active MRR navigation stays focused on sellable seats.
Enterprise risk register
Default all successful sign-in paths to /portal and reject the sign-in route as a next target.
Auth entry verifier and portal-access verifier check the post-login chooser contract.
Staged imports, review-before-merge controls, destination selection, and recovery are permanent paid-seat surfaces.
MRR seat-launch verifier checks connections, import queues, staged records, and recovery controls.
Output scope labels separate private, client-safe, court-facing, and family-communication digests.
Privacy and launch proof verifiers check private/court/client/FCS separation language.
Judicial and justice surfaces remain preserved but inactive in MRR navigation unless platform full access is present.
Portal chooser groups institutional portals behind full-access scope and preserves their paths.
Verification path
Final launch package readiness
Owner-facing record for the paid-seat release package, controlled configuration notes, responsive review, and final verification path.
Package manifest
Application source, public assets, route families, shared utilities, package manifest, lockfile, verifier scripts, and configuration examples remain in the release package.
Pro Se, Attorney, and Family Communications stay active for paid onboarding with settings, connections, recovery, reports, and export surfaces preserved.
Judicial Edition, Justice, Clerk, Judge, Prosecutor, Defender, and Law Court surfaces remain compatible and separated from active MRR navigation.
Controlled launch notes
Production service URLs, allowed accounts, session secret, OAuth redirect values, and provider keys must be supplied through the deployment environment before release.
Deployment preflight verifies required values and reports optional provider configuration separately.
Google and Microsoft entries remain safe when provider configuration is unavailable, and Google local-origin handling avoids invalid 0.0.0.0 redirects during local review.
Login and Google SSO origin verifiers protect the post-login portal chooser contract.
Imported material stays staged until a person confirms destination, scope, and merge intent before promotion into a matter.
Paid-seat connections and recovery verification protects staged import review and recovery controls.