Decide what each role can see and change.

Every member carries exactly one role, and that role decides which areas of Esqase appear in their sidebar and what they can do in each. A rule set once, rather than a reminder repeated.

One role each, built from four levels

Every member carries one role, and a permission in it is the right to do one thing in one area: view, create, update, or delete. Firms start with owner, administrator, attorney, and staff roles.

One role per member

Each person carries a single named bundle of permissions.

A firm owner can require two-factor authentication for everyone, so a role's access is only ever reached from an account carrying a second step.

Two-factor authentication

View, create, update, delete

Four levels of access, set per area of the app, and delete needs update.

Four roles from day one

Owner, administrator, attorney, and staff, yours to shape.

Review before an invoice or a document goes out

You set which roles are reviewed, which may review, and how many approvals an item needs. Invoices and documents are set separately, and each reviewer's decision shows as a badge on their avatar.

Rules you set once

Who is reviewed, who reviews, and how many must agree.

Billing and documents apart

Require review on invoices without slowing down signing.

Status on the record itself

Reviewer avatars carry each decision, where the work is.

Set up roles for your firm.

Browse the docs

FAQs

Permission levels, owners, two-factor, and how a review actually runs.

How do roles work in Esqase?

Every member is assigned exactly one role, and that role's permissions decide which areas of the app appear in their sidebar and which actions they can take. A role is a named bundle, for example Attorney or Staff, and you can build the ones your firm actually uses rather than working around a fixed list.

How precise can permissions get?

A permission is the right to do one thing in one area, at four levels: view, create, update, and delete. A role can read matters without deleting them, or record transactions without editing accounts. The levels stack: create, update, and delete all need view, and delete needs update.

What happens if someone lacks a permission?

The control simply is not there. An area a role cannot reach is left out of the sidebar entirely, and inside an area the buttons follow the level: no create access means no New button, no update access means no edit options. Nobody spends the afternoon clicking things that will refuse them.

Do firm owners follow the same rules?

No. Firm owners always have full access regardless of role, and their permission grid is read-only because there is nothing left to configure. A few actions stay owner-only whatever the grid says: inviting or promoting another owner, and managing the firm's subscription.

Can we require two-factor authentication?

Yes. A firm owner turns on Require two-factor authentication in the firm's profile settings, and anyone who has not enrolled lands on the setup screen before they can carry on working. Each member picks an authenticator app or a code by email and saves ten single-use recovery codes, and nobody can switch their own second step off while the firm requires it.

Can I keep a confidential matter off other screens?

Set that matter's visibility to specific members. Billing is firm-wide work, so a bookkeeper still sees the invoice, the payment, and the ledger entry, but the matter reads as Restricted matter with no link to open it. The amount, the client, the date, and the status stay visible, so your totals are right while the case stays confidential.

Do medical records get their own permission?

On the Professional plan, yes. The personal injury module adds two rows to the grid, one for the case and one for medical records and bills, and a member can hold either without the other. Someone chasing records never has to see what the case is worth. Update access on the medical row is worth guarding, because marking a bill as a lien reduces the client's share of the settlement.

What are approvals for?

Requiring a second reader before an invoice goes to a client or a document is sent for signature. You set the rules at firm level: which roles have their work reviewed, which roles are allowed to review, how many approvals an item needs, and who is added to every review automatically. Approving your own work is off by default, so the person who wrote a thing is not the person who releases it.

Can I require approval on billing but not on documents?

Yes. Invoices and documents are configured separately, so you can insist on review for anything with a number on it while leaving document signing to move at its own pace, or do the reverse if your risk sits in what gets signed rather than what gets billed.

Where do I see whether something has been approved?

On the item itself. Reviewers appear as a row of avatars on the invoice or the document, each wearing its own decision: a green check for approved, a red x for changes requested, an amber dash once those changes have been marked done and it is back with them. The invoices list keeps an In review tab, so everything waiting on a sign-off is one click away and nobody is chasing an answer through email.

What happens when a reviewer wants something changed?

They click Request changes and write what should change. That note is posted into the item's own comment thread, tagged as a review, so the feedback sits beside the work instead of in an email. Whoever fixes it marks each point done, the reviewer's avatar turns amber, and they are notified it is ready for another look. Marking a point done never approves anything on the reviewer's behalf.

Does an approval survive an edit?

No, and that is the point of having one. Changing an invoice's line items or totals, or the content of a document, clears the approvals collected so far and reopens the review with the same reviewers on it. Renaming, tagging, or moving a document does not, and neither does editing the notes around an invoice.

Give everyone exactly the access they need.