A bug that support cannot see
An associate reports that your product shows the wrong clause summary on a matter. Your support person cannot reproduce it on test data. To investigate, they would need to see the document and the output. The options are poor. They could ask the associate for screenshots, which means client material sent by email. They could use the admin account that sees everything in the firm's workspace, which the firm's security questionnaire said support would only do in exceptional circumstances. Or they could guess.
They ask for screenshots. The associate sends several, with the client's name visible. Now privileged material is sitting in your help desk.
Why support access is a problem for legal tech
Law firms hold confidential and privileged information. Their clients and their own policies limit who can see it. When you sold the product, you told the firm your staff would not access their content without good reason and permission. Your tools may not make that easy.
- Support either sees nothing or uses an admin account that sees everything.
- There is no way to ask the firm for permission inside the product.
- Screenshots and attachments with client content end up in the help desk.
- Nobody records when support staff opened firm data, or why.
- Diagnostic information that would solve most problems without content is not available.
What clumsy support access costs
Either support is slow, because staff cannot see enough to solve problems, or it is risky, because they see too much. Client material in your help desk becomes something you have to protect and eventually delete, and it would be awkward to explain in a security review. A firm that discovers support staff opened a matter without permission may reconsider the relationship entirely.
Support staff are put in an unfair position too. They want to help the fee earner with a deadline, and the quickest route is often the one that breaks the promise made in the sales process. Without tools that make the right route quick, good people take shortcuts, and nobody can later show whether they did or not.
How we build support access firms can accept
What we build lets support solve most problems without content, and makes content access, when needed, consented, limited and recorded.
- Diagnostic views that show what support needs without client content: document structure, page counts, processing states, error codes, model version and timings for a given request.
- Redacted replays: a copy of the user's screen state with text content masked, so layout and behaviour problems can be seen.
- An access request built into the product: support asks for access to a specific matter or document, with a reason, and the user or the firm's admin approves or declines.
- Time-limited access that expires automatically, restricted to what was approved, never the whole workspace.
- A support access log the firm's admins can view, showing who accessed what, when, why and who approved it.
- Help desk settings that block or strip client attachments, and a screenshot tool that masks content by default.
| Support need | How it is met |
|---|---|
| Why did processing fail? | Diagnostic view, no content |
| Why does the screen look wrong? | Redacted replay |
| Why is this output wrong? | Access request to that document, time-limited |
| Firm wants to check support activity | Support access log |
| User wants to send a screenshot | Masked screenshot tool |
What level of access support should have, and on what terms, is agreed between you and each firm. The product enforces it and records it.
The wrong clause summary, investigated properly
The associate reports the problem from the help button. Your support person opens the diagnostic view and sees the document was processed with a low OCR score on two pages. That might be enough. To be sure, they request access to the one document with a reason. The associate approves it with a click. Support has access for a limited time, confirms the scanned pages were the cause, and the access expires. The firm's admin can see the whole episode in the support access log. No screenshots were emailed.
Is support putting client content at risk?
- Support staff use an admin account that sees all firm data.
- Users send screenshots with client content to your help desk.
- There is no in-product way to request and approve access.
- You cannot tell a firm who on your team has opened their data.
- Most problems cannot be diagnosed without seeing content.