Skip to main content
Meytal Dahan
Back to insights

Permissions, Confidentiality, and UI Simplification: How Do You Design a Legal Portal with a Complex Permissions Mechanism?

Shibolet & Co. — Designed the firm's internal community hub - balancing the gravitas of a top legal practice with a social tone inviting enough that employees would actually use it - into a space precise enough to belong inside the firm and warm enough to feel lived-in.
One of the most critical challenges for engineering leaders (CTOs) in legal organizations is designing an access control system that meets strict information security standards on one hand, without turning the user experience into a nightmare on the other. In Shibolet & Co.'s internal portal, we had to manage an especially complex permissions setup: partners, salaried attorneys, interns, and operations staff — where each group has different view and edit rights across each of the hundreds of content units in the portal. Cracking this from a design standpoint required close collaboration with the system architecture. Instead of building cumbersome permission-settings screens like the ones found in classic enterprise systems, we built a "Permission Inheritance" logic in which permissions are derived automatically from the user's role in the organization. This way, administrators don't have to manually define who sees what — the system knows on its own, and presents CTOs and system administrators with a transparent, simple interface for managing exceptions only. In addition, the UI components were designed with special sensitivity to "No Access States." Instead of simply hiding content, the system displays a human explanation that guides the user on what to do if they believe they need access. The seamless link between the visual design and the security logic is what separates a well-functioning enterprise system from an architecture that "looks good on paper" and falls apart in implementation.

Get in touch

Have a project in mind?

Drop a line. Meytalyav@gmail.com

Related articles

Shibolet & Co.
Engineering LeadersProject-Specific Data Visualization

Visualizing a Community, Not a Dashboard

Say data visualization to engineers and they picture analytics dashboards. Shibolet's internal community hub needed the opposite. It was a community hub for a law firm, not an admin reporting tool. The job was making events, courses, benefits, and interest groups scannable and inviting, with light cues like who's attending or active. No charting engine, no KPI grid. Project-specific data viz means the representation answers this domain's real question. Here it was always: what's happening in my community, and what's for me?

Read
Shibolet & Co.
Project Managers

Running a Digital Project in a Legal Organization: How Do You Hit Deadlines When Partners' Time Is Worth Gold?

Project Managers in legal organizations — your biggest pain point is the billable hours of your partners. On the Shibolet & Co. project we developed a "Batched Approvals" method paired with Figma prototypes: every decision is presented with 3 clear alternatives, and a partner can sign off in 15 minutes instead of an hour. That's how you protect the Gantt and the budget.

Read
Shibolet & Co.
Product ManagersTypography & Visual Hierarchy

Typography as Triage: Ordering a Legal Community Hub

PMs keep asking: how do users know what matters when one screen does five jobs? On Shibolet's internal hub, a single view carried a compliance notice, a new course, a firm event, and a community invite. I didn't solve that with more tabs. I solved it with typography. A deliberate type ramp let official items read with authority and social content stay warm, in the same layout. Visual hierarchy is product triage made visible. Get the type ramp right and you stop negotiating screen real estate per stakeholder.

Read
Meytal Dahan

About

Making complicated into easy for users.

Senior product designer with a decade of work across complex systems - financial risk platforms, legal operations, healthcare apps, manufacturing tooling and insurance portals. The common thread is depth: products where the data is rich, the users are expert, and the interface has to disappear into the work.