> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.whizcozy.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.whizcozy.com/_mcp/server.

# Identity and firm access

> How WhizBoard combines a signed-in user, a firm route, membership, and API role checks.

WhizBoard separates a person's identity from the firm they are working in. A firm slug selects the requested workspace; it does not grant access by itself.

**Status:** Implemented in the UI and API. Membership and role checks are performed server-side for each protected operation.

![Access flow diagram showing JWT identity and firm slug resolved through membership and a server-side role guard](/_fern-files/whizboard.docs.buildwithfern.com/db45faf3a0c50abc6af4e9a9c486546ad7b2638394603ca88e642077b546c4be/docs/assets/diagrams/firm-access.svg)

## What happens on a firm request

1. The browser sends the signed-in user's JWT with a request under a firm route.
2. The firm slug identifies the firm context requested by the browser.
3. The API validates the JWT, resolves the user and firm membership, and checks the role required by that operation.
4. The API returns the result or rejects the request when the membership or role check fails.

The JWT represents the user. Firm membership is stored separately, so a token does not grant access to every firm. The route slug is context, not authorization.

## UI roles and API authorization

The UI uses role information to choose labels, navigation, and presentation. The backend is the authorization boundary: sensitive operations must be checked by API dependencies and feature-specific rules. A hidden button or a client-side role value is not a security control.

## Session behavior

The UI keeps a session for the selected firm in browser storage. The remembered-session option can persist that UI state longer than a normal session, but the JWT still has its own expiry. When the API rejects an expired token, the user must authenticate again.

## Related guides

* [Account and password recovery](/account-and-password-recovery) covers sign-in and reset flows.
* [Teams and invitations](/teams-and-invitations) covers how firm membership is added.
* [System architecture](/system-architecture) shows the wider browser/API boundary.

## Code map

* UI session and firm context: WhizBoard UI, `src/lib/firm-session.ts`, `src/lib/firm-access.ts`, and `src/routes/$firmSlug.tsx`.
* API identity and membership checks: backend, `src/core/dependencies.py`, `src/models/membership.py`, and `src/services/firms.py`.