Skip to main content

Claude, deployed directly. Governed to privilege & fiduciary standards.

Attri deploys Claude Enterprise directly at the firm and operates the governance layer that makes AI defensible under the duties that bind the practice, privilege, bar-association supervision, and fiduciary standards.

Book a governance briefing
Governance ConsolePrivilege preserved across every Claude surface.
Live · firm-owned tenant
Surfaces covered4 of 4
Claude EnterpriseSSO/SCIM · retention policy
Covered
Claude CoworkAttri governance overlay
Covered
Claude APIZero Data Retention
Covered
MCP connectorsiManage · NetDocuments · SharePoint
Covered
Privilege Ledger · Live14,328 decisions · 24h
14:02ALLOWmatter.read · attorney_412
14:07HOLDpii.detect · threshold 0.94
14:11BLOCKexport.unsigned · matter_88
14:18ALLOWprompt.submit · Heppner ws

AI is no longer a moat. The standard model, LLM plus document upload plus chat, has flattened differentiation. Firms are not buying the most advanced model. They are buying the system they trust to deploy without risk.

Legal AI has gone from exploration to infrastructure.

Every major legal AI platform shares a common inference engine. Claude is the model underneath most of the legal AI being adopted today. Wherever the firm buys, the governance question lands on the same model.

$16B+
Harvey + Legora · Q1 2026
1M
CoCounsel users · 107 countries
60/100
AmLaw 100 firms on Harvey
80%/15%
Capability vs. adoption

Attri deploys Claude Enterprise at the firm directly. No wrapper. No middle seat.

Claude Enterprise has four surfaces a firm uses differently. Attri stands them up directly with Anthropic, consulting-led, not resold, and operates the governance layer across all.

Claude

Claude Enterprise

SSO/SCIM, custom roles, retention configuration, Compliance API. Stood up with the right governance posture from day one, not retrofitted in quarter three.

Claude

Claude Cowork

The agentic desktop surface where the firm's most substantive AI work happens. Excluded from Audit Logs, the Compliance API, and Data Exports by default. This is where Attri closes the gap.

Claude

Claude API

Firm-built agents for matter workflows, contract review, deal-risk analysis, drafting. Zero Data Retention available on qualifying workloads.

MCP

MCP connectors

Governed tool-calling into iManage, NetDocuments, SharePoint, Google Drive. Every call carries identity, entitlement, and policy through.

A firm can run Harvey, CoCounsel, and Claude Enterprise simultaneously. Attri engages with the direct Claude Enterprise deployment the firm owns, including Cowork, where governance is the firm’s responsibility and where the Heppner ruling lives.

Learn more

The governance layer is what makes a direct Claude deployment defensible.

Six specific gaps a governance layer has to close, each touching a different duty the partnership already holds. Not flaws in Claude. The places where a general-purpose platform ends and a profession-specific governance layer begins.

Learn more
Privilege

Enterprise chat retains indefinitely by default.

Chat conversation data is retained until configured, minimum 30 days, and is not covered by Zero Data Retention. Privileged content on that surface creates a record the firm cannot control.

Mitigation

ZDR-eligible deployment for privileged work, stood up by Attri alongside the standard environment.

Audit

Cowork activity is excluded from the audit surface.

Cowork sessions are not captured by Audit Logs, the Compliance API, or Data Exports. For a firm whose most substantive AI work happens there, this is the hole that matters most.

Mitigation

The Cowork Recovery Agent captures session activity from the local data layer and files it into the hash-chained evidentiary record.

Matter

Matter segregation is a policy question first.

Claude Enterprise ships with capable primitives, workspaces, custom roles, domain-scoped SSO, retention. On their own, they don't express a firm's matter model.

Mitigation

AI Usage Policy drafted to the firm’s obligations, plus native configuration tuned to matter-level segregation. Not parallel RBAC; native primitives used well.

Policy

The Compliance API records. It doesn't prevent.

Audit logs tell you what happened. For PII, PHI, or privileged content, the log is written after the harm. Policy needs to be enforced at the prompt, not reviewed at the dashboard.

Mitigation

Pre-prompt middleware runs PII Redaction and Prompt Policy Checker inline. Every prompt leaves the trust boundary already scrubbed or blocked.

Duty

Supervision is a professional duty, not a config.

Model Rule 5.3 places a supervisory duty on attorneys for non-lawyer assistance, the ABA has extended this to AI. A vendor's SOC 2 posture does not relieve that duty.

Mitigation

Per-action records naming identity, role, prompt, policy checks, and completion. What an auditor or disciplinary panel will ask for, on demand.

Evidence

Defensibility requires a record the firm owns.

A vendor-held audit log is a dependency. A tamper-evident, hash-chained, exportable record, in the firm's own environment, is evidence. One can be subpoena'd around. The other can be produced.

Mitigation

Customer-owned evidentiary store, append-only, cryptographically linked, portable to existing eDiscovery tools.

How the governance layer is organised.

Each pillar addresses a distinct category of legal risk, implemented through specialised agents, operated under one observability platform.

SAML/OIDC with your IdP, SCIM lifecycle, and agent-layer entitlement enforcement that checks matter-level access before data is surfaced. Ethical walls honoured at runtime.

Per-action identityRoleMatterEntitlement
Learn more

Attri Observability

The single pane of glass. Every signal from every pillar lands in one customer-owned console. Dashboards for Legal, Security, and IT; alerts routed to the firm’s SIEM.

See Demo
Evidentiary_record · 0x7f3a
live
EVENT#9a4f
eventprompt.submitted
matterMATTER-2026-114-EM3
POLICY#c2e1
policypii.redact · tokenised [3]
ruleAUP §4.2 · client_name
ENTITLEMENT#7b0d
entitlementmatter.read · allow
wallethical_wall_7 · passed
MODEL#3f8c
modelclaude-opus-4-7 · cowork
tokensin=4,211 · out=1,802
COMPLETION#e1a9
completiondelivered · retention 90d
chainVALID · linked → f07c
sha-2560x8f3a…bc19
chain valid

The record we produce is the record you’ll be asked to produce.

When an AI-assisted filing is challenged, when opposing counsel moves to compel, when the state bar sends a letter, the question is the same: reconstruct, with evidence, what happened.

The evidentiary store holds every signal. Hash-chained, timestamped, identity-keyed. One file. Portable to your eDiscovery tooling. Admissible.

Fifteen specialised agents. Each writes to the same evidentiary record.

Each agent has one job. Must-have agents ship in every deployment. Good-to-have agents sequence into the roadmap.

Get Started
Pre-Prompt GovernanceMust have

PII Redaction Agent

Identifies personal data in prompts before they reach the model, tokenise, strip, or block per policy.

Pre-Prompt GovernanceMust have

Prompt Policy Checker

Validates every prompt against the firm-wide, team-specific, and matter-specific policy rules.

Evidentiary & AuditMust have

Audit Continuity Agent

Joins Compliance API, Usage & Cost API, Cowork session data, and agent activity into one reconciled stream.

Evidentiary & AuditMust have

Evidentiary Record Agent

Writes the reconciled stream to the firm-owned audit store in tamper-evident, hash-chained form.

Evidentiary & AuditMust have

Cowork Recovery Agent

Closes the Cowork audit gap, captures session activity directly from the user’s device.

Evidentiary & AuditMust have

Retention & Deletion Agent

Executes selective deletion via the Compliance API, honours legal holds, attests every action.

Policy & RiskMust have

Policy Violation Triage

Classifies suspected violations by severity and routes them to the correct reviewer with evidence attached.

Pre-Prompt GovernanceMust have

PII Redaction Agent

Identifies personal data in prompts before they reach the model, tokenise, strip, or block per policy.

Pre-Prompt GovernanceMust have

Prompt Policy Checker

Validates every prompt against the firm-wide, team-specific, and matter-specific policy rules.

Evidentiary & AuditMust have

Audit Continuity Agent

Joins Compliance API, Usage & Cost API, Cowork session data, and agent activity into one reconciled stream.

Evidentiary & AuditMust have

Evidentiary Record Agent

Writes the reconciled stream to the firm-owned audit store in tamper-evident, hash-chained form.

Evidentiary & AuditMust have

Cowork Recovery Agent

Closes the Cowork audit gap, captures session activity directly from the user’s device.

Evidentiary & AuditMust have

Retention & Deletion Agent

Executes selective deletion via the Compliance API, honours legal holds, attests every action.

Policy & RiskMust have

Policy Violation Triage

Classifies suspected violations by severity and routes them to the correct reviewer with evidence attached.

Evidentiary & AuditGood-to-have

DSAR / Subject Access Agent

Produces statutory subject-access response packs inside GDPR 30-day and CCPA 45-day deadlines.

Policy & RiskGood-to-have

Anomaly Detection

Flags abnormal usage against per-user, per-team, per-matter behavioural baselines.

Policy & RiskGood-to-have

Regulatory Change Watcher

Maps new bar-association and DPA guidance to the specific framework controls that may need adjustment.

IntelligenceGood-to-have

Knowledge Base Agent

Serves governed, version-controlled precedent into prompts with full citation tracking.

IntelligenceGood-to-have

User Intelligence Agent

Reasons over an individual attorney’s interactions, always within their own entitlements.

IntelligenceGood-to-have

Organization Intelligence

Aggregated, permission-respecting insight at the practice-group and firm level.

Cost & OperationalGood-to-have

Cost Attribution Agent

Reconciled cost estimates at practice group, matter, or attorney level, useful for chargeback and budget.

Cost & OperationalGood-to-have

Cost Anomaly Agent

Abnormal spend patterns, often the earliest indicator of abnormal usage.

CustomGood-to-have

Built with the firm

Contract-review agent against the firm’s own precedent library. Deal-risk agent over the investment committee archive.

CustomGood-to-have

Self-improving via Decision Intelligence

Custom agents that sharpen with use, tuned against the firm’s own matters, outcomes, and partner feedback.

Evidentiary & AuditGood-to-have

DSAR / Subject Access Agent

Produces statutory subject-access response packs inside GDPR 30-day and CCPA 45-day deadlines.

Policy & RiskGood-to-have

Anomaly Detection

Flags abnormal usage against per-user, per-team, per-matter behavioural baselines.

Policy & RiskGood-to-have

Regulatory Change Watcher

Maps new bar-association and DPA guidance to the specific framework controls that may need adjustment.

IntelligenceGood-to-have

Knowledge Base Agent

Serves governed, version-controlled precedent into prompts with full citation tracking.

IntelligenceGood-to-have

User Intelligence Agent

Reasons over an individual attorney’s interactions, always within their own entitlements.

IntelligenceGood-to-have

Organization Intelligence

Aggregated, permission-respecting insight at the practice-group and firm level.

Cost & OperationalGood-to-have

Cost Attribution Agent

Reconciled cost estimates at practice group, matter, or attorney level, useful for chargeback and budget.

Cost & OperationalGood-to-have

Cost Anomaly Agent

Abnormal spend patterns, often the earliest indicator of abnormal usage.

CustomGood-to-have

Built with the firm

Contract-review agent against the firm’s own precedent library. Deal-risk agent over the investment committee archive.

CustomGood-to-have

Self-improving via Decision Intelligence

Custom agents that sharpen with use, tuned against the firm’s own matters, outcomes, and partner feedback.

15
Governance agents
in production
6
Functional
families
24/7
Managed
operation
100%
Client retention on
live engagements

The framework learns, without crossing the lines it exists to defend.

A governance layer that ships on day one and never changes ages out of compliance. Regulators publish new guidance. Claude ships new surfaces. Bar associations issue new ethics opinions. Cases like Heppner redraw the privilege map overnight.

baseline_id mg_14matter_group_14
statusanomaly
normal bandanomaly
d1d3d5d7
window7d
samples2,104
tuned142 runs

Attri doesn’t just deploy. We stay, as the firm’s AI counsel.

Legal AI is not a one-time integration. A managing partner fields new questions every quarter, those questions don’t have vendor answers. They have advisory answers, informed by what other firms have done and what the framework already supports.

Get Started

Strategic AI counsel

A named senior consultant who knows the firm’s obligations, Anthropic’s roadmap, and the open questions the partnership is sitting on.

Quarterly reviews

A standing session with legal, security, and platform leadership. Regulatory changes. What the framework caught. Recommended tuning. Memorialised in writing.

24/7 managed operation

Incident response on policy violations. Anomaly review. Regulatory-change tracking. A 2am Saturday event is triaged the same way as a Tuesday afternoon one.

Sector intelligence

Every new regulation mapped for one client becomes a default for all. Detection rules compound across engagements, confidentiality intact.

The questions every serious legal buyer asks before signing.

Can't find what you're looking for? Talk to our team.

No. Harvey and CoCounsel are purpose-built legal AI platforms with their own audit surfaces and governance contracts. Attri does not wrap or replace them.

Our engagement is with the direct Claude deployment the firm runs alongside those platforms, Claude Enterprise, Cowork, the API, and MCP connectors. That’s the surface the firm owns itself, where governance is the firm’s responsibility.

The governance and compliance box, ticked. And kept ticked.