What a Twenty-Module Permission Matrix Actually Buys a Growing Firm
Twenty modules, four default roles, and server side enforcement that doesn't care how busy your team is: here's what actually breaks when a growing firm runs on a shared login instead.
Let me be very honest, when a firm calls us and they've grown from three attorneys to twelve in eighteen months, the thing that actually keeps the managing partner up at night isn't whether the associates are billing enough hours, it's whether the receptionist can see what the partner charges a client, or whether a paralegal who used to work the front desk still has a login that opens the trust ledger for a matter she's never touched. And so when we built the permission system inside Casely, we didn't build one on and off switch for admin versus everyone else, right, because that's basically the access model most growing firms are quietly running on, a shared login and a spreadsheet somewhere of who's supposed to see what, and it breaks the second the firm gets big enough that nobody remembers who has what anymore. We built it across twenty separate functional modules, documents, trust ledger, billing, matters, contacts, leads, calendar, tasks, settings, users, reports, conflict checks, portal access, and audit logs among others, and every one of those can be tuned per role, so what a receptionist sees on Monday morning is genuinely, structurally different from what a partner sees, not just a button that's hidden but a permission that's enforced at the server. Does that make sense, that's basically the whole premise of this post.
What twenty modules actually means in practice
So here's what I mean by twenty modules, because permission matrix is one of those phrases that sounds like enterprise software jargon until you sit across from a firm and watch what actually goes wrong without one. A five-attorney firm we talked to last year had exactly one login shared between two paralegals, and when one of them left, the firm had to change the password and walk the other paralegal through relearning it, and for about six weeks nobody was totally sure who had touched which matter, because the system had no idea there were two different humans behind that one account. Casely ships with four default roles, partner, associate, paralegal, and receptionist, and each of those roles gets its own read and write settings across every one of the twenty modules, so a receptionist can be given access to the calendar and intake because that's genuinely their job, without that same login being able to open a client's trust ledger or see what a partner is billing at nine hundred dollars an hour on a corporate matter. And the roles aren't fixed either, so if a firm wants something between paralegal and associate, for instance a senior paralegal who can draft invoices but not void them, that gets built in settings in a few minutes, not filed as a support ticket that sits for a week.
| Module | Receptionist | Paralegal | Associate | Partner |
|---|---|---|---|---|
| Trust ledger | No access | View only | Record deposits | Full access |
| Billing and invoicing | No access | View drafts | Draft invoices | Full access |
| Client portal | Schedule only | Respond to messages | Respond to messages | Full access |
| Settings and users | No access | No access | No access | Full access |
Why four default roles aren't the actual protection
Now the catch here is roles alone don't solve the problem, because a role is just a label, and the label only means something if the system enforces it at the exact point where it matters, which for a law firm is basically two places, the trust ledger and anything privileged. So when we say a paralegal has view only on the trust ledger, what that actually means mechanically is that the disbursement button doesn't just get hidden from their screen, their account literally cannot submit a disbursement request the database will accept, and if a partner tries to record a disbursement that would overdraw the matter, Casely blocks it atomically at the database transaction level with a message that reads "Disbursement exceeds trust balance. Bar rules prohibit overdrafts." It's not a warning you can click through, it's a hard stop, for everyone, regardless of role or seniority. That's the difference between a permission system that's cosmetic and one that's structural, and it's the difference that actually protects a firm's bar license, not just its org chart.
The ethical wall problem nobody talks about
For instance, one thing that comes up constantly with firms growing fast is conflicts, right, a litigation boutique picks up a lateral hire, and that lateral hire's old firm represented the other side of a case three years back, so now that one attorney needs to be walled off from that one matter permanently, no exceptions, no forgetting. Most systems handle that with a note in a shared doc or a verbal reminder not to open the file, which is basically an honor system, and honor systems fail the exact moment someone's in a hurry or just forgets which files are off limits to them. Casely enforces ethical walls server side, so a walled off user's API calls are blocked, not just the button hidden in their interface, meaning even if that attorney pulled up the matter through a saved link or a search result, the server itself refuses to return the data. That's a meaningfully different guarantee than we told them not to look.
What this actually replaces
At the end of the day, most of the firms we onboard aren't coming from another CRM, they're coming from a shared drive, a spreadsheet tracking who's allowed to see what, and a set of logins everyone quietly shares because setting up individual accounts felt like overhead nobody had time for. And look, that works fine at three people, I'm not going to pretend otherwise, but it stops working the moment a firm crosses into double-digit headcount, because now there's a receptionist, three paralegals, five associates, and two partners, and the spreadsheet hasn't been updated since March, and nobody's job is to update it.
| Feature | Spreadsheet and shared logins | Casely's permission matrix |
|---|---|---|
| Trust ledger visibility | Whoever has the login sees the whole balance and every entry | Set per role from no access to view only to full disbursement rights |
| Ethical wall enforcement | A note somewhere reminding people not to open a file | Blocked at the server so the walled off user's own requests fail |
| Client portal exposure | Whatever is uploaded to the matter privileged or not | Only what is tagged and privilege filtered specifically for that client |
| Who did what and when | Nobody is tracking it in real time | Every entry voided not deleted with who and why attached permanently |
Audit your own firm for thirty seconds
So let me be honest about how to actually tell if this is a problem for your firm right now, because it's easy to read a post like this and assume it applies to someone bigger than you, and it usually doesn't take much digging to find out otherwise.
- Can your receptionist see what a partner bills an hourly client
- Does anyone outside your two founding partners have a login that can void a trust ledger entry
- If an associate got walled off from a matter today would their old bookmarks and saved searches still surface it
- Do you know which of your attorneys has two-factor enabled and which don't
- Could a paralegal upload a privileged document and have it show up in the client portal by mistake
If you hesitated on more than one of those, that's not a character flaw, it's just what happens to access control at every firm that grows faster than its admin processes do, and it's exactly the gap this whole matrix exists to close.
Getting it live without a six week rollout
And the part firms are usually most surprised by is how little of this requires ongoing attention once it's set up, because the heaviest lift in the entire migration is importing the existing client and matter list, and that's genuinely achievable in a single pass, after which the trust ledger, the conflict checks, and the full permission matrix are all live immediately in their enforced form, not as a setting someone has to remember to flip on next quarter.
- 01Import the existing client and matter list in one pass
- 02Assign each teammate one of the four default roles or build a custom one in settings
- 03Turn on two-factor for the whole team from the Users page, no bypass once it's enabled
- 04Watch trust ledger blocks and conflict checks start enforcing themselves the same day
Along the way, an admin can open the Users page and see, per attorney, who's actually enrolled in two-factor and who's still putting it off, and anyone can sign out of every other active session with one click if a laptop goes missing or someone forgets to log out on a shared machine at a courthouse kiosk, which sounds like a small thing until it's the thing that mattered.
And look, I get why permission matrix sounds like the most boring possible thing to build a blog post around, it's not a feature anyone brags about at a bar association mixer, right, nobody switches case management systems because the role settings screen looks nice. But when I talk to firms six months after they've moved onto Casely, the thing they mention isn't the invoice button or the client portal, it's that they stopped worrying about who could see what, because the system just handles it now, quietly, in the background, across every one of those twenty modules, every single day, for every person on staff whether they've been there six years or six weeks. And so yeah, that is basically the whole case for it.