Role rings: who can do what
Client
own matter
own matter
Clerk
supervised non-lawyer
supervised non-lawyer
Lawyer
licensed to practice
licensed to practice
Admin
lawyer + system administration
lawyer + system administration
Owner
owns the system
owns the system
The rings display the five stored roles in their authority order: owner > admin > lawyer > clerk > client. Owner
inherits Admin and Lawyer capability; Admin inherits Lawyer capability but cannot govern Owner. Clerk is deliberately
not a weakened Lawyer account. Anonymous is outside every ring and sees public pages only. Clients use the portal for
their own matters. Clerks reach /app/projects like everyone else and get a read-only rendering of their firm-assigned
Projects and the disclosed lawyer DRI; they never give legal advice. Owner, Admin, and Lawyer are lawyers, and MCP, Git,
drafting, approval, and administration surfaces stay lawyer-only.