Sign in with the firm’s identity
Microsoft 365 or Google. No extra password to invent for SPBX. The app lives at login.spbx.pro; after sign-in it knows which firm you belong to.
Trust
If it holds client files, you should be able to read how access works on this page, not in a buried PDF.
Microsoft 365 or Google. No extra password to invent for SPBX. The app lives at login.spbx.pro; after sign-in it knows which firm you belong to.
Every role enrolls an authenticator app. Sign-in is not complete without it — the app, APIs, and database rules reject a session that skipped the second factor. Permanent document deletes also require a fresh confirmation.
Every record is tagged to a firm. The system rejects reads and writes that cross that line. Hiding a menu item is not the control.
Staff see assigned cases. Contract attorneys see approved cases only. Asking for another case by URL returns a permission error, not an empty screen.
Files sit in private storage. The app mints a short-lived signed URL when someone with access needs to open one.
Creates, updates, uploads, deletes, logins, and permission denials are written down. That’s the record you can look at later.