TKOResearch
Menu

Industry

Review the matter boundaries before a document copilot becomes firm infrastructure.

A law firm’s assistant may search client documents, draft work product and connect to email or its document management system. We review who can reach each matter, what data leaves the firm, and who approves sending, sharing or changing records. Counsel can also commission a separate review of technical claims and system materials for disputes, diligence or post-incident work.

What you receive

What the engagement covers.

  • Client/matter and staff-role access matrix, including firm-supplied ethical-wall rules
  • Data-flow map covering retrieval, context, citations, exports, logs and caches
  • Vendor terms and configuration questions with document dates and unresolved assumptions
  • Findings register with reproduction conditions, technical impact and remediation owners
  • Rollout decision memo with permitted use, unresolved risks and retest conditions

01

Start with a firm-owned workflow

Choose one pilot: an associate summarizing matter documents, a knowledge team searching approved precedents, or an assistant drafting an email for attorney review. Record the intended user, client, matter, sources and allowed actions before reviewing the vendor.

  • Translate the firm’s approved ethical-wall and matter-access rules into technical test inputs. Membership in the same firm does not by itself authorize access to every matter.
  • Separate attorneys, paralegals, contractors, knowledge staff, IT administrators and connector service identities. Include role changes and departed staff.
  • Use invented matters and redacted configuration for initial scoping. Agree on authorized systems, test accounts, data handling and stop conditions before accessing sensitive materials.

02

Follow a document beyond the search result

  • Check source permissions at retrieval and before context assembly, including revoked access and cached candidates.
  • Inspect citation titles, snippets and source links as well as answer text. Test direct export, shared conversations and generated files for the same matter boundary.
  • Map answer caches, embeddings, conversation memory, diagnostic logs and backups. Record deletion and retention behavior separately for each store.
  • Review document-management, email and storage connectors: delegated versus service access, token scope, administrators, external sharing and revocation.

03

Review the vendor and the action boundary

  • Obtain the actual service agreement, data-use and training terms, retention settings, deletion process and subprocessor information for the selected product tier. Record where contractual terms and available configuration differ.
  • Identify whether prompts, uploaded files, retrieved passages and outputs receive different treatment. Unanswered questions become rollout conditions.
  • Require an accountable person to review citations and substantive output before use. Define which actions need approval, including sending, external sharing and changes to matter records.
  • Bind technical approval to the intended action, recipient, content and current permissions. Include cancellation, changed drafts and failed or repeated requests in the test plan.

04

Professional guidance and the technical review

ABA Formal Opinion 512, issued July 29, 2024, discusses competence, confidentiality, communication and supervision when lawyers use generative AI. It supports asking concrete questions about a tool’s capabilities and limitations. The technical review supplies system-specific materials; the firm’s counsel determines applicable professional obligations, client communication and consent.

05

Separate counsel and expert-support work

Counsel managing a dispute, diligence question or post-incident assessment may need an independent analysis of supplied technical materials. That engagement starts with its own question, material request list, conflicts and scope review, and a counsel-facing technical memo. It is separate from approving the firm’s internal AI pilot.

06

What to send and what happens next

  • Send the proposed workflow, product and tier, decision deadline, system owner and a redacted architecture sketch. Keep client files and credentials out of the initial contact form.
  • Provide a source inventory, role/matter matrix, connector scopes, applicable vendor documents and known access exceptions through the agreed review channel.
  • Prioritize boundary failures before expanding the pilot. Each finding names an owner, acceptance test and review point; remediation implementation and retest scope are agreed separately.

Limits

Scope and limitations.

  • This is a scoped engineering service. It does not provide legal advice, determine privilege, certify compliance or guarantee confidentiality.
  • A document review cannot establish runtime isolation. Unavailable configurations, inaccessible systems and unperformed tests are recorded as limits.

Next step

Describe the system, question, and timing.

Scope a firm AI review