Team, branding and billing
The account-level settings: who's in your firm, what your clients see, and what you pay.
Firm details
Under Settings → Firm details, owners and admins can set the country your firm operates in. It's asked for at signup, and this is where you change it — or fill it in if your account predates the question.
Nothing in the product behaves differently because of it. We use it to know which markets to support properly, starting with the data-protection rules that apply in each one.
Inviting your team
Under Settings → Team, invite colleagues by email address. They get a link, set a password, and land in your organisation — they don't create a separate account or firm.
Three roles:
| Role | Can do |
|---|---|
| Owner | Everything, including billing. The person who signed the firm up. |
| Admin | Everything day-to-day, plus branding, storage, team invites and billing. |
| Member | The actual work: build, send, chase and review requests. Can't change firm settings, delete requests, or touch billing. |
Invites expire, so a stale one in an old inbox doesn't stay live forever. Re-invite if someone misses it.
Removing someone
When a colleague leaves, press Remove beside their name under Settings → Team. Their access ends immediately — requests, client records and uploaded documents all become unreachable to them on their next click — and the seat is freed for someone else. It's recorded in the audit log.
Removing someone from your firm doesn't delete their ChaseDocs login, and you can invite them back at any time. Three things it won't do:
- Owners and admins only — the same bar as inviting.
- You can't remove yourself. If you're leaving, ask another owner to do it.
- Only an owner can remove an owner, and never the last one — a firm with no owner would have nobody who can manage it or undo the change.
Seats
Your plan sets how many people can hold a seat — see the table below. A pending invite holds a seat from the moment you send it, so if you're at the limit, revoke an outstanding invite to free one up. Settings → Team shows seats used against your allowance.
Re-sending an invite to someone already invited replaces the old one rather than taking a second seat.
Member is the right default for most staff. Deleting a request destroys a client record, which is why it's restricted to owners and admins — cancelling a request, the thing you actually need when a client drops out, is available to everyone.
Branding the client portal
Under Settings → Branding, upload your logo and set an accent colour. Both appear on the page your client opens, so the request reads as coming from your firm rather than from a tool they've never heard of. There's a live preview of the portal header as you edit.
Available on Team and Firm plans, and during the free trial. On Solo the portal shows your firm's name with standard ChaseDocs styling.
Keep the logo simple and high-contrast — it renders small, on a phone, often in daylight. A wordmark usually beats a detailed crest.
Plans and billing
Everyone starts on a 7-day free trial with every feature unlocked and a cap of 50 active requests. No card to begin.
Plans are billed in USD by card, monthly, through Polar — our merchant of record, which also handles invoices and any applicable tax. Manage the subscription, card and invoices from Billing in the app; that opens the payment portal directly. Billing is owner and admin only.
Current prices and limits are on the pricing section and in Billing in the app — the app is the authority if the two ever disagree.
What the plans change
| Feature | Solo | Team | Firm |
|---|---|---|---|
| Requests, templates, reminders | Yes | Yes | Yes |
| Group requests | Yes | Yes | Yes |
| Document check incl. expiry rule | Yes | Yes | Yes |
| AI auto-naming | Yes | Yes | Yes |
| Bring-your-own cloud storage | Yes | Yes | Yes |
| Seats | 1 | 5 | Unlimited |
| Custom portal branding | — | Yes | Yes |
| Audit log | — | — | Yes |
Plans differ on size, not on capability. Group requests, the full AI document check and bring-your-own storage are on every plan — they're the point of the product, and gating them would gate the job itself. What a bigger plan buys you is more people at a time, more seats, and custom branding.
When the trial ends
Your data stays put. You'll be blocked from sending new requests until you pick a plan, but nothing already sent is interrupted and nothing is deleted. Files in your own connected storage were never ours to remove.
The audit log
On the Firm plan, Audit log records who did what, to what, from where, and when. It's what you reach for when a client, a colleague or a regulator asks you to account for how a particular document was handled.
Owners and admins only. The log records each team member's activity, including the address and device they worked from, so it stays with the people accountable for the firm's data rather than being readable by the whole team.
What gets recorded
- Document access. Every time a member of your firm opens or downloads an uploaded document. This is usually the first thing anyone asks about, so it's recorded even though no data changed.
- Uploads and AI checks — what a client sent, and the verdict the check returned.
- Request lifecycle — sent, resent, submitted, cancelled, reopened, deleted, restored, and permanently deleted at the end of the retention window.
- Client portal links copied. A copied link is access to that client's documents without a login, so who made one is recorded alongside document access.
- Consent — recorded, withdrawn, and restored.
- Team — invites sent, accepted and revoked, and members removed.
- Storage and billing — connecting or disconnecting your cloud, plan changes.
Each entry carries the action, who took it, what it acted on, the time, and — for actions taken by a person — the IP address and browser they used. Automated jobs are recorded as the system, with no IP, because there is no person or device behind them.
What never gets recorded
Document contents, filenames, the text of a client's answers, account numbers, and client names stay out of the log entirely. It records that a document was accessed and which one — never what was in it. That's a deliberate limit: a log that quoted the documents would become another copy of exactly the data we've promised not to keep.
Filtering and export
Filter by activity, by who acted (staff, client, automated job or billing), and by date range, then Export CSV to get the filtered set as a file. Click any entry to expand it and see the full detail behind it, including a link through to the request it refers to.
When you'd actually use the export
The screen is for looking something up. The CSV is for proving it to someone outside your firm — a client's lawyer, an auditor, a regulator, an insurer. Typical moments:
- A client asks who at your firm saw their documents. Filter to Document access and their date range, export, send.
- A suspected breach or a leaked link. Export the relevant window early — it's the evidence behind the notice you owe the client and the regulator.
- A dispute. "You never sent it" or "you deleted my file" — filter to the request and the record answers it.
- An annual review, or a client's security questionnaire before they sign.
- Anything that will outlive the 365-day window. Export before the entries age out; after that they're gone.
Filter before you export. The CSV honours whatever filters are on screen, and a targeted extract is far more useful to the person receiving it than the whole log.
Treat the file as confidential. It contains staff email addresses and IP addresses, which are personal data in their own right. Don't email it around unprotected or leave it in a shared folder.
Timestamps in the export are UTC. Client names are not included by design — the log holds the request identifier instead, so look the name up in your dashboard rather than storing a second copy of it in a file that outlives the record.
How long entries are kept
Audit entries are kept for 365 days, then deleted automatically. That's long enough to cover a full annual cycle and any investigation, and short enough that the log itself honours the same retention discipline it exists to demonstrate — it holds staff email addresses and IP addresses, which are personal data too.
How tamper-resistant it is
Entries are append-only: once written, nothing in ChaseDocs can edit an audit entry, and the database rejects the attempt outright. Entries are removed only by the 365-day retention sweep.
To be precise about the limit, because it matters if you're relying on this: that protects against changes made through the application. It is not a cryptographic guarantee against someone with direct access to the underlying database. If you need tamper-evidence at that level, talk to us before you commit to it.
What isn't in the log
Sign-ins and sign-outs aren't recorded — those are handled by our authentication provider and don't currently reach the audit log. Everything a signed-in user then does is recorded.
Still stuck? Email support@usechasedocs.com and a human will answer.
ChaseDocs