Org Admin
Full organisation control. The only role that can invite members, change roles, manage billing, and access all settings including NDPR admin tabs. Org Admins bypass workspace membership checks.Partner
Senior practitioner. Can create workspaces, run automations, view billing, close matters, and approve conflicts. Cannot invite members or change org-level roles.Fee Earner
Standard practitioner. Full access to practice work: matters, documents, Generate, Research, and Compliance. Can log time. Cannot close matters or manage clients page without partner-level access for some actions.Paralegal
Similar to Fee Earner with restrictions. Cannot manage clients or log time independently.Workspace Admin
Workspace-scoped administration. Can manage workspace settings and membership. Cannot access automations, integrations, or firm-wide admin.Billing Manager
Can view billing and analytics. No access to practice pages. Cannot manage matters, documents, or generation.Read Only
Can browse all practice content. Cannot create, edit, or delete anything. All write buttons are disabled.API Consumer
Can access the integrations hub and API settings only. Cannot access practice pages at all.Client
External role. Does not access the product shell. Receives portal links and usesportal.largence.com.
External Reviewer
External role. Can access only specific matters where they are assigned as a Reviewer matter role. View and comment only within those matters.Data Protection Officer (DPO)
Independent compliance role. Organisation-wide read access to audit trails, NDPR/compliance records, export, and audit certificates. No impersonation, workspace management, billing, or matter documents by default. Matter document access requires a time-limited DPO elevation approved by an Org Admin for a specific matter and reason (investigation, regulatory audit, DSAR, or breach response). Elevations expire automatically and never include impersonation. Cannot be combined with operational roles (ORG_ADMIN, WORKSPACE_ADMIN, PARTNER, FEE_EARNER, BILLING_MANAGER).
External Auditor
External role assigned by Org Admin only. Read-only access to audit logs and compliance records for a specific audit engagement (purpose + expiry). No matter documents, billing, or analytics. Access requires an active (non-revoked, unexpired) engagement. Every audit view/export is logged. Cannot be combined with operational practice roles orORG_ADMIN.
Product UI assigns one primary organisation role per member. The API stores roles as an array; DPO
and External Auditor are exact-match capability roles (they do not inherit practice privileges via
the org hierarchy). Matter roles remain separate and set per matter.
Capability matrix
* DPO matter/document access only with an active Org-Admin-approved elevation for that matter.
** External Auditor requires an active audit engagement.
Invite members
How Org Admins send invitations.
Workspaces
Workspace-scoped access and settings.
