Skip to main content
A user has one organisation role. Matter roles (Lead, Associate, Paralegal, Reviewer, Billing, Read Only) are separate and set per matter.

Org Admin

Full organisation control. The only role that can invite members, change roles, manage billing, and access all settings including NDPR admin tabs. Org Admins bypass workspace membership checks.

Partner

Senior practitioner. Can create workspaces, run automations, view billing, close matters, and approve conflicts. Cannot invite members or change org-level roles.

Fee Earner

Standard practitioner. Full access to practice work: matters, documents, Generate, Research, and Compliance. Can log time. Cannot close matters or manage clients page without partner-level access for some actions.

Paralegal

Similar to Fee Earner with restrictions. Cannot manage clients or log time independently.

Workspace Admin

Workspace-scoped administration. Can manage workspace settings and membership. Cannot access automations, integrations, or firm-wide admin.

Billing Manager

Can view billing and analytics. No access to practice pages. Cannot manage matters, documents, or generation.

Read Only

Can browse all practice content. Cannot create, edit, or delete anything. All write buttons are disabled.

API Consumer

Can access the integrations hub and API settings only. Cannot access practice pages at all.

Client

External role. Does not access the product shell. Receives portal links and uses portal.largence.com.

External Reviewer

External role. Can access only specific matters where they are assigned as a Reviewer matter role. View and comment only within those matters.

Data Protection Officer (DPO)

Independent compliance role. Organisation-wide read access to audit trails, NDPR/compliance records, export, and audit certificates. No impersonation, workspace management, billing, or matter documents by default. Matter document access requires a time-limited DPO elevation approved by an Org Admin for a specific matter and reason (investigation, regulatory audit, DSAR, or breach response). Elevations expire automatically and never include impersonation. Cannot be combined with operational roles (ORG_ADMIN, WORKSPACE_ADMIN, PARTNER, FEE_EARNER, BILLING_MANAGER).

External Auditor

External role assigned by Org Admin only. Read-only access to audit logs and compliance records for a specific audit engagement (purpose + expiry). No matter documents, billing, or analytics. Access requires an active (non-revoked, unexpired) engagement. Every audit view/export is logged. Cannot be combined with operational practice roles or ORG_ADMIN.
Product UI assigns one primary organisation role per member. The API stores roles as an array; DPO and External Auditor are exact-match capability roles (they do not inherit practice privileges via the org hierarchy). Matter roles remain separate and set per matter.

Capability matrix

* DPO matter/document access only with an active Org-Admin-approved elevation for that matter.
** External Auditor requires an active audit engagement.

Invite members

How Org Admins send invitations.

Workspaces

Workspace-scoped access and settings.