Estates, matters, cases, claims, demands, appeals, judgments, rulings, intervenors, parties. Most systems grow a table per noun and then spend years reconciling six answers to one question.
A bankruptcy case HAS an estate. A usury suit has none, an appeal has none, an engagement has none. Getting that one distinction right is what lets every other noun fit without a table each:
What a court entered is not editable by anyone signed in: rulings take no update permission at all.
A name, an entity kind, a jurisdiction and a registry file number are public-register facts. Sharing them discloses nothing — and NOT sharing them is what makes the same lender three unconnected rows in three firms, which is the actual defect.
That a party is in your case is a different thing entirely. A reader learns who you are suing and on whose behalf — client information that Tex. Disciplinary R. 1.05 reaches whether or not it is privileged, and the thing a competitor would pay for. So case parties, party contacts, claims and matters stay inside your firm, and a database probe asserts BOTH halves: that the registry has no firm boundary AND that those four still do. A check that only looked at the shared half would pass on the day somebody widened the wrong table.
“I have a judgment against this company — what is it worth and what can I sell it for” is a question the registry is built to answer eventually, with a click. It needs three things it does not have: what judgments exist against the entity, where it sits in the creditor queue, and whether it has filed. A judgment is a public record, which is what would make sharing it lawful — but nothing marks a ruling public yet, so exposing them today would disclose which firm has which case. That is enumerated in the code as NOT YET, on the page, rather than left to be discovered.
Not on a separate approvals page. A human is required at every decision, so decisions belong where you already look. Approving leaves a green line with your name joined live from the profile and a timestamp to the minute; editing forks a NEW task rather than reopening the old one; declining is its own record.

There is one renderer. The board the person who builds this uses and the board your firm gets are the same module with a different connection — no private staging area where the good version lives, and no demo build that diverges from the product the week after it is recorded.
The most expensive recurring defect on a system like this is not a bug. It is a correct rule that quietly takes work out of circulation — because from the board, “the system is working on it” and “nothing will ever touch this again” look identical. So every rule here that removes something from a queue owes that row one note explaining why, and the note is a kind of event that cannot advance the thing it explains.
A thread's audience is DERIVED from what kind of thread it is, never stored as a list of people somebody picked. A judicial participant is a neutral, is not a mediator, and is not a member of any participant's firm — so a firm-only thread and both halves of a caucus are false for them, and the only kind left computes its audience from the case participants and therefore cannot omit a party. There is no fourth kind, and adding one would be a decision about whether this platform can manufacture a Canon 3(B)(8) problem on behalf of a lawyer using it in good faith.
Only the mediator may convene a caucus. Caucus traffic is kept from the bench by the same predicate, which Tex. Civ. Prac. & Rem. Code § 154.073 requires independently. A message can be turned into a task.
Voice and video run in end-to-end encrypted rooms whose audience is the audience of the conversation — decided once, in one place. A judge joins unable to publish. No recording permission is ever issued, because recording is a legal decision and Texas being a one-party-consent state does not make a multi-party call simple. The client library is vendored at a pinned version and served from the same origin, so no third-party script sits on a page carrying privileged conversation.
A case carries a plan with steps you assign — to your associate, to co-counsel, to the client, back to yourself. Documents move both directions with every read and write logged, including this firm's, and the log is yours to read. Held-back work product is held back: the participant sees the released document and not the one beside it.

An arrow is drawn only where the plan has an edge. The first version put one between every pair of adjacent cards, which asserted an order the plan did not have — and a board that draws a sequence the case does not have is telling a trustee something false about what must happen before what.
The honest edge, and it is on a decision row rather than hidden: every participant sees every step's TITLE, with the unreadable ones marked “nothing on this step is visible to you” — the last card above. The alternative — hiding the step entirely — means a count you cannot see becomes a claim about the case derived from a fact about the reader. Which of those is right is a judgment about client information, so it is a decision put to the lawyer rather than a default chosen by the software.
Bring a live matter. The parts that do not fit yours are the parts worth hearing about.