figma guide

Designing breach settlement protective order compliance and restricted data room UI in Figma: PO-* orders, CONF-AEO rooms, and USR-GST-* access tiers

Design breach settlement protective order compliance and restricted data room UI in Figma with PO-* order configs, CONF-AEO sealed rooms, tiered USR-GST-* access, and audit trails for DSQ-* productions.

Published
Updated
Sep 06, 2026
Read time
9 min
Level
Intermediate

Quick answer

Protective order UI turns court-stipulated confidentiality rules into enforceable product behavior—not PDF warnings on a download page. Design PO- order configs* that define CONF- tiers*, USR-GST- access scopes*, watermark rules, and LOG-PO- audit* for every view in settlement DSQ- data rooms*. Highly confidential (CONF-AEO) and sealed exhibits need separate virtual rooms with stricter MFA, no bulk export, and automatic TOK-GST- expiry* aligned to the order. The restricted data room sits between EXP-DSQ-* production delivery and opposing counsel review—where most accidental disclosures happen. Start from the Figma guides hub and pair with privilege log UI, IP allowlist, and session timeout patterns.


Who this is for

  • Product designers building tiered guest counsel portals for class action and breach settlement discovery.
  • Settlement administrators and e-discovery vendors configuring PO-* rules without engineering tickets per matter.
  • Legal ops and security proving LOG-PO-* compliance when opposing counsel alleges unauthorized disclosure.

Protective order lifecycle overview

ProtectiveOrderProgram — PO-992-001 · dsq_id: DSQ-992-001 · Status: Active
├── Triggers:
│   ├── Court enters stipulated protective order
│   ├── DSQ-* production ready for opposing counsel review
│   ├── Amendment to order changes CONF-* tier definitions
│   └── Sanctions motion requires enhanced audit export
├── ID namespace:
│   ├── PO-* (protective order config) · ROOM-* (virtual data room)
│   ├── CONF-* (confidentiality tier) · USR-GST-* (guest user)
│   ├── TOK-GST-* (access token) · ACL-GST-* (room permission)
│   ├── LOG-PO-* (protective order compliance event)
│   ├── WM-* (watermark profile) · EXP-SEAL-* (sealed exhibit pack)
│   └── LINK-DSQ · LINK-PRIV (cross-refs)
├── Room types:
│   ├── ROOM-STD — CONF-STD production browse
│   ├── ROOM-HIGH — CONF-HIGH watermarked · limited print
│   ├── ROOM-AEO — attorneys' eyes only · opposing counsel excluded
│   └── ROOM-SEAL — court-sealed · judge-authorized viewers only
├── Enforcement:
│   ├── Upload PO-* PDF → parse tier definitions (manual confirm)
│   ├── Map EXP-DSQ-* docs to CONF-* via [PRIV-* / RED-DSQ-* tags](/designing-breach-settlement-privilege-log-and-confidentiality-designation-ui-in-figma/)
│   ├── Issue USR-GST-* invites per room · not global portal
│   ├── LOG-PO-* every view · print attempt · download denial
│   └── Auto-revoke TOK-GST-* at order expiry or matter close
└── Outcomes:
    ├── Opposing counsel accesses only permitted CONF-* tier
    ├── Sanctions-ready LOG-PO-* export
    └── COC-DSQ-* records room delivery method
ROOM-* typeTypical viewersExport allowed
ROOM-STDAll designated counselPer order · often none
ROOM-HIGHLead counsel + experts under agreementNever bulk
ROOM-AEOIn-house + outside counsel onlyView-only
ROOM-SEALNamed individuals + court orderPhysical handoff only

Verdict: One guest portal with a confidentiality checkbox is not enough—build separate ROOM- with ACL-GST- enforcement.**


PO-* order configuration UI

ProtectiveOrderConfig — PO-992-001 · matter: MAT-2026-441 · court: N.D. Cal.
├── Order metadata:
│   ├── Upload stipulation PDF · docket number · effective date
│   ├── Expiry / review date · auto-alert before TOK-GST-* mass revoke
│   ├── Related DSQ-* · SET-* settlement reference
│   └── Designating party contacts for tier disputes
├── Tier builder (CONF-*):
│   ├── Define labels: Public · Confidential · Highly Confidential · AEO
│   ├── Marking text for headers/footers (WM-* template)
│   ├── Permitted use language (litigation only · no business use)
│   └── Return/destruction obligations on matter close
├── Access rules matrix:
│   ├── Role: opposing counsel · co-counsel · expert · vendor
│   ├── Which ROOM-* each role may enter
│   ├── MFA required? · [IP allowlist](/designing-ip-allowlist-and-network-restrictions-ui-in-figma/)?
│   └── Expert designation workflow (upload executed agreement)
├── Technical controls:
│   ├── Disable print · screenshot deterrence · session timeout minutes
│   ├── Download: none · single-doc · counsel-only ZIP with LOG-PO-*
│   └── Watermark: email · timestamp · matter ID on every page
└── Publish:
    ├── PO-* v1 active → rooms inherit rules
    ├── Amendment upload → PO-* v2 diff view · re-acknowledge USR-GST-*
    └── LOG-PO-* config change event

Use forms patterns for tier builder fields and accordions for role-specific access rules.


ROOM-* virtual data room browse UI

DataRoom — ROOM-HIGH-992 · po_id: PO-992-001 · docs: 4,218 · Status: Open
├── Room header:
│   ├── CONF-HIGH badge · PO-992-001 link
│   ├── WM-* preview: "CONFIDENTIAL — MAT-2026-441 — {user_email} — {timestamp}"
│   ├── Terms re-acceptance if PO-* amended
│   └── Session timer ([session timeout UI](/designing-session-timeout-and-re-authentication-ui-in-figma/))
├── Document browser:
│   ├── Folder tree mirroring Bates prefix · doc type
│   ├── Search within room scope only · not full archive
│   ├── Filter: date · author · [PRIV-* linked](/designing-breach-settlement-privilege-log-and-confidentiality-designation-ui-in-figma/) docs excluded from browse
│   └── Sort: Bates · relevance · recently added
├── Document viewer:
│   ├── Watermarked render · no native file unless order permits
│   ├── Page-level LOG-PO-* view event
│   ├── Print button disabled · show order citation on attempt
│   └── "Request de-designation" workflow → counsel queue
├── Activity sidebar (admin):
│   ├── USR-GST-* online now · last access
│   ├── Anomaly: rapid page flip · bulk open pattern
│   └── Link [security alerting](/designing-security-alerting-rules-and-notification-routing-ui-in-figma/)
└── Close room:
    ├── Matter closed order uploaded
    ├── Revoke all TOK-GST-* · email destruction reminder
    └── COC-DSQ-* "room closed" event

Best for: multi-tier productions under federal or state protective orders. Skip separate rooms when entire production is single-tier CONF-STD—use one ROOM-STD with simpler ACL-GST-*.


USR-GST-* invitation and ACL-GST-* provisioning UI

GuestAccessInvite — USR-GST-MORRIS-001 · rooms: ROOM-STD-992, ROOM-HIGH-992
├── Invitee profile:
│   ├── Name · firm · bar number (optional verify)
│   ├── Email · role: opposing counsel · expert · vendor
│   ├── PO-* acknowledgment checkbox · timestamp captured
│   └── Expert: upload executed designation · admin approve
├── Room assignment (ACL-GST-*):
│   ├── Checkboxes per ROOM-* · grayed if role ineligible
│   ├── ROOM-AEO: never for opposing counsel · show explanation
│   ├── ROOM-SEAL: manual GC approval · named list only
│   └── Effective dates · auto-expire TOK-GST-* on PO-* end
├── Security:
│   ├── Magic link + MFA ([2FA UI](/designing-two-factor-authentication-and-security-settings-ui-in-figma/))
│   ├── Optional IP allowlist per firm
│   ├── Device limit: 2 concurrent sessions
│   └── Re-auth for ROOM-HIGH elevation
├── Invite lifecycle:
│   ├── Sent → accepted → LOG-PO-* first login
│   ├── Suspend · revoke · extend (approval chain)
│   └── Offboard: [member offboarding patterns](/designing-member-offboarding-and-deprovisioning-ui-in-figma/) for vendor access
└── Bulk invite:
    ├── CSV import · conflict check duplicate USR-GST-*
    └── Template for co-counsel firms on same side

Pair invitation emails with email verification patterns—guest users often register from personal devices.


CONF-AEO and ROOM-SEAL sealed exhibit UI

SealedRoom — ROOM-SEAL-992-EXH-4 · po_id: PO-992-001 · viewers: 3 authorized
├── Access gate:
│   ├── Court order upload naming authorized individuals
│   ├── Dual approval: settlement admin + general counsel
│   ├── USR-GST-* must match named list exactly
│   └── No self-service invite · no opposing counsel
├── Browse constraints:
│   ├── Exhibit list only · no full-production search
│   ├── In-person viewing option tracked in COC-DSQ-*
│   ├── No download · no copy/paste · aggressive session timeout
│   └── LOG-PO-* includes video session ID if remote court viewing
├── Physical production alternate:
│   ├── Track encrypted drive serial · chain of custody
│   ├── COC-DSQ-* handoff · recipient signature capture
│   └── No ROOM-SEAL UI if court forbids electronic access
└── De-seal workflow:
    ├── Order amendment → move docs to ROOM-HIGH
    ├── Re-tag CONF-* · regenerate watermarks
    └── LOG-PO-* de-seal event · notify prior ROOM-SEAL viewers

Sealed exhibits often cannot be hosted electronically—design UI to record physical delivery in COC-DSQ-* even when ROOM-SEAL browse is disabled.


LOG-PO-* compliance audit and sanctions defense UI

ComplianceAudit — LOG-PO-992 · export_id: EXP-AUD-992-001 · period: Q3 2026
├── Event types logged:
│   ├── login · logout · session_timeout · mfa_challenge
│   ├── doc_view · page_view · search_query · print_attempt
│   ├── download_denied · download_allowed (with file hash)
│   ├── po_acknowledgment · po_amendment_reaccept
│   └── room_enter · room_denied · acl_change
├── Audit dashboards:
│   ├── By USR-GST-* · by ROOM-* · by document Bates
│   ├── Anomaly highlights: after-hours bulk access · geo mismatch
│   ├── Compare LOG-PO-* to opposing counsel access log requests
│   └── Export for sanctions hearing · [compliance export format](/designing-compliance-exports-and-legal-hold-ui-in-figma/)
├── Retention:
│   ├── LOG-PO-* retained per PO-* destruction schedule
│   ├── HLD-* blocks delete while matter active
│   └── Link [archive retention](/designing-breach-settlement-archive-and-long-term-record-retention-ui-in-figma/) for long-term storage
└── Integrity:
    ├── Immutable append-only log store
    ├── Hash chain per day · tamper alert
    └── Separate from LOG-DSQ-* · correlatable by timestamp

Use audit log UI patterns for the reviewer-facing timeline and tables for filtered exports.


Comparison: ROOM-* vs USR-GST-* portal vs physical production

DimensionROOM-* (this pattern)USR-GST-* single portalPhysical COC-DSQ-*
Tier enforcementStrict per roomRisky if one portalN/A
Audit granularityLOG-PO-* per pageLOG-DSQ-* view eventsManual sign-off
CostHigher buildLowerShipping + labor
Best forMulti-tier PO-*Single-tier productionsSealed · air-gapped
RevocationInstant TOK-GST-*SameRecall media

Common mistakes

  1. Single portal for all CONF- tiers*— opposing counsel sees HIGH or AEO material inappropriately.
  2. Watermark optional— PO-* violations often stem from untracked copies; WM-* on every page.
  3. No PO- amendment workflow*— stale rules after court order change.
  4. Experts get same ACL as counsel without designation upload.
  5. LOG-PO- not exportable*— cannot defend against sanctions without audit pack.

  1. Upload PO- PDF* and configure CONF-* tiers plus WM-* templates in admin.
  2. Map EXP-DSQ- docs* to rooms via RED-DSQ-* / CONF-* tags from privilege log workflow.
  3. Create ROOM-STD / ROOM-HIGH / ROOM-AEO with inherited PO-* rules.
  4. Invite USR-GST- users* with ACL-GST-* room checkboxes and MFA.
  5. Enable LOG-PO-* on all view and denial events; wire anomaly alerts.
  6. Close matter with TOK-GST-* revoke, destruction reminder, and COC-DSQ-* room closure.

FAQ

Opposing counsel demands CONF-AEO access?

Deny by default per order · surface PO-* citation in UI · escalation workflow to settlement counsel · LOG-PO-* denial event.

Can experts access ROOM-HIGH?

Only with executed expert designation uploaded and approved · separate ACL-GST-* · shorter TOK-GST-* expiry.

Screenshot prevention?

Deterrence only— watermark + LOG-PO-* + order language · do not promise technical block on all platforms.

PO- template library* · ROOM-* prefix by matter · USR-GST-* may need separate invites per DSQ-*.

Vendor e-discovery hosting vs built-in rooms?

Hybrid OK · LOG-PO-* via webhook from vendor · COC-DSQ-* records primary custody · API keys for integration.

Matter closed— when delete ROOM-*?

After PO- return/destruction period* · HLD-* release · proof of deletion for LOG-PO-* if required.


Next steps

Share on X

§ Keep reading

Related guides.