Edu-Carone-SA puts hard walls between legal workspaces
The fork now treats access to matter data as a first-class security boundary, not an assumption.
Edu-Carone-SA has expanded row-level protections across the application so users can see and change only the records they own or have been explicitly invited to share. That includes connected records, where a loose permission check can otherwise expose more than intended.
- Shared projects, workflows and tabular reviews can remain available to approved collaborators.
- Reference case-law data is read-only, reducing the chance of accidental alteration.
- Contact messages stay limited to the administrative service account.
The team has also mapped which parts of the product require sign-in and added checks for anonymous, invalid-token and cross-user access. The work passed its stated test, build and code-quality checks, although audit logs, role-based permissions and session revocation remain on the roadmap.
So what Firms and legal teams assessing Mike for multi-user work should care because the fork makes client and matter separation materially more defensible.
Spotted something wrong? Or know the PR text has fresher detail than the writeup above?