Role rings: who can do what

Outside to centre: Client; Clerk (supervised non-lawyer); Lawyer (licensed to practice); Admin (licensed lawyer with system administration); Owner (system owner). Anonymous is outside every ring and sees public pages only.
Client
own matter
Clerk
supervised non-lawyer
Lawyer
licensed to practice
Admin
lawyer + system administration
Owner
owns the system

The rings display the five stored roles in their authority order: owner > admin > lawyer > clerk > client. Owner inherits Admin and Lawyer capability; Admin inherits Lawyer capability but cannot govern Owner. Clerk is deliberately not a weakened Lawyer account. Anonymous is outside every ring and sees public pages only. Clients use the portal for their own matters. Clerks reach /app/projects like everyone else and get a read-only rendering of their firm-assigned Projects and the disclosed lawyer DRI; they never give legal advice. Owner, Admin, and Lawyer are lawyers, and MCP, Git, drafting, approval, and administration surfaces stay lawyer-only.