IvanJS17 gives Mike a hard security boundary

This fork turns a single-owner legal workspace into one that can enforce who sees, changes and downloads case material.

securityworkflow

IvanJS17 has put organisations, workspaces and matters at the centre of access control. Members are assigned roles, outsiders are kept out, and read-only users cannot write. Older email-based sharing has been removed until named invitations are ready.

  • Access rules now apply across the existing public data, with automated checks to catch gaps.
  • Revoked membership invalidates stale background work, so a job cannot continue under an old permission.
  • Uploads are checked against their actual file content, downloads require authentication, and failed processing is cleaned up.
  • Audit records are append-only, then exported daily in encrypted form with retention cleanup.

Managing partners, GCs and legal-ops leads should care if they need a clearer control line around shared matter data.

So what The GitHub changes are worth a closer look for teams assessing whether Mike can support role-based collaboration without casual file sharing.

View this fork on GitHub →

Spotted something wrong? Or know the PR text has fresher detail than the writeup above?