Discovery
The part where small firms get hurt.
Productions go out with Bates numbers that still resolve two years later, a privilege log that wrote itself, and a receipt of exactly what was sent and when. The check that stops you producing today what you withheld last spring runs before the production can lock.
Why this and not a folder of PDFs
Four ways discovery goes wrong, and what stops each one
The same document withheld in one production and produced in another
What it costs. A waiver argument handed to the other side, found by them rather than you, usually months later and usually about the one document that mattered.
What stands in the way. Privilege decisions attach to the document, not to a production, and every production is checked against every prior one before it can lock. A conflict stops the lock. It is not a warning you can click past.
A Bates number that no longer resolves
What it costs. A number cited in a deposition three years ago that now points at nothing, in front of a judge who is waiting.
What stands in the way. Ranges are allocated from a registry that guarantees uniqueness and are tied to the production that consumed them, so the reverse lookup survives the case.
A production you cannot prove you sent
What it costs. "We never received it." Reconstructing what went out, when, and to whom is exactly the thing you cannot do at the moment you need it.
What stands in the way. What was sent is recorded at the time — the document list, the hash of the bytes that actually left, the recipient, and a receipt when the delivery link is opened and downloaded.
A redaction that was never actually burned in
What it costs. The black boxes exist in your review tool and not in the file that leaves. The material somebody deliberately marked for withholding goes out in full, and you find out when the other side quotes it.
What stands in the way. Redactions are held as coordinates, and nothing here burns them into the page — so a production containing a redacted document is REFUSED rather than assembled. Two separate signals trigger the refusal, including a document somebody flagged before the geometry was drawn, which is the most dangerous shape of all. The bundle does not get built until a person deals with it.
The privilege log
Written when the production locks
A log assembled later, from the state of the file at the time you happen to build it, quietly changes as documents are re-reviewed. This one is captured at the moment the production is locked, so it says what was true when you produced.
Each entry identifies the document — date, type, participants, and the claim asserted — without disclosing what the privilege protects.
How it works
Discovery and productions
The model pre-sorts documents against parsed requests; an attorney confirms every call. A production cannot lock while it contains an unreviewed document, a document still marked privileged, or anything that contradicts a prior production — producing what you withheld before is a waiver argument, and it is invisible without cross-production comparison. Bates numbering is matter-wide and permanent.
- Numbers are burned onto the page when the bundle is assembled, which is an operator command rather than a button on the production screen.
- Redactions are recorded as coordinates and are not burned into pixels. A production containing a redacted document is refused rather than produced unredacted — see the assembly capability for why.
- Request parsing, the responsiveness pre-sort, confirming calls, and deficiency analysis exist in src/lib/discovery.ts but have no screen and no caller yet — the production build, Bates, privilege log, consistency check, lock, and delivery steps are the part a lawyer can reach today.
Every capability, with its limits → · See it on a real file →