Claude, deployed directly. Governed to privilege & fiduciary standards.
Attri deploys Claude Enterprise directly at the firm and operates the governance layer that makes AI defensible under the duties that bind the practice, privilege, bar-association supervision, and fiduciary standards.
Book a governance briefingAI is no longer a moat. The standard model, LLM plus document upload plus chat, has flattened differentiation. Firms are not buying the most advanced model. They are buying the system they trust to deploy without risk.
Legal AI has gone from exploration to infrastructure.
Every major legal AI platform shares a common inference engine. Claude is the model underneath most of the legal AI being adopted today. Wherever the firm buys, the governance question lands on the same model.
Attri deploys Claude Enterprise at the firm directly. No wrapper. No middle seat.
Claude Enterprise has four surfaces a firm uses differently. Attri stands them up directly with Anthropic, consulting-led, not resold, and operates the governance layer across all.
Claude Enterprise
SSO/SCIM, custom roles, retention configuration, Compliance API. Stood up with the right governance posture from day one, not retrofitted in quarter three.
Claude Cowork
The agentic desktop surface where the firm's most substantive AI work happens. Excluded from Audit Logs, the Compliance API, and Data Exports by default. This is where Attri closes the gap.
Claude API
Firm-built agents for matter workflows, contract review, deal-risk analysis, drafting. Zero Data Retention available on qualifying workloads.
MCP connectors
Governed tool-calling into iManage, NetDocuments, SharePoint, Google Drive. Every call carries identity, entitlement, and policy through.
A firm can run Harvey, CoCounsel, and Claude Enterprise simultaneously. Attri engages with the direct Claude Enterprise deployment the firm owns, including Cowork, where governance is the firm’s responsibility and where the Heppner ruling lives.
Learn moreThe governance layer is what makes a direct Claude deployment defensible.
Six specific gaps a governance layer has to close, each touching a different duty the partnership already holds. Not flaws in Claude. The places where a general-purpose platform ends and a profession-specific governance layer begins.
Enterprise chat retains indefinitely by default.
Chat conversation data is retained until configured, minimum 30 days, and is not covered by Zero Data Retention. Privileged content on that surface creates a record the firm cannot control.
ZDR-eligible deployment for privileged work, stood up by Attri alongside the standard environment.
Cowork activity is excluded from the audit surface.
Cowork sessions are not captured by Audit Logs, the Compliance API, or Data Exports. For a firm whose most substantive AI work happens there, this is the hole that matters most.
The Cowork Recovery Agent captures session activity from the local data layer and files it into the hash-chained evidentiary record.
Matter segregation is a policy question first.
Claude Enterprise ships with capable primitives, workspaces, custom roles, domain-scoped SSO, retention. On their own, they don't express a firm's matter model.
AI Usage Policy drafted to the firm’s obligations, plus native configuration tuned to matter-level segregation. Not parallel RBAC; native primitives used well.
The Compliance API records. It doesn't prevent.
Audit logs tell you what happened. For PII, PHI, or privileged content, the log is written after the harm. Policy needs to be enforced at the prompt, not reviewed at the dashboard.
Pre-prompt middleware runs PII Redaction and Prompt Policy Checker inline. Every prompt leaves the trust boundary already scrubbed or blocked.
Supervision is a professional duty, not a config.
Model Rule 5.3 places a supervisory duty on attorneys for non-lawyer assistance, the ABA has extended this to AI. A vendor's SOC 2 posture does not relieve that duty.
Per-action records naming identity, role, prompt, policy checks, and completion. What an auditor or disciplinary panel will ask for, on demand.
Defensibility requires a record the firm owns.
A vendor-held audit log is a dependency. A tamper-evident, hash-chained, exportable record, in the firm's own environment, is evidence. One can be subpoena'd around. The other can be produced.
Customer-owned evidentiary store, append-only, cryptographically linked, portable to existing eDiscovery tools.
How the governance layer is organised.
Each pillar addresses a distinct category of legal risk, implemented through specialised agents, operated under one observability platform.
SAML/OIDC with your IdP, SCIM lifecycle, and agent-layer entitlement enforcement that checks matter-level access before data is surfaced. Ethical walls honoured at runtime.
Attri Observability
The single pane of glass. Every signal from every pillar lands in one customer-owned console. Dashboards for Legal, Security, and IT; alerts routed to the firm’s SIEM.
The record we produce is the record you’ll be asked to produce.
When an AI-assisted filing is challenged, when opposing counsel moves to compel, when the state bar sends a letter, the question is the same: reconstruct, with evidence, what happened.
The evidentiary store holds every signal. Hash-chained, timestamped, identity-keyed. One file. Portable to your eDiscovery tooling. Admissible.
Fifteen specialised agents. Each writes to the same evidentiary record.
Each agent has one job. Must-have agents ship in every deployment. Good-to-have agents sequence into the roadmap.
PII Redaction Agent
Identifies personal data in prompts before they reach the model, tokenise, strip, or block per policy.
Prompt Policy Checker
Validates every prompt against the firm-wide, team-specific, and matter-specific policy rules.
Audit Continuity Agent
Joins Compliance API, Usage & Cost API, Cowork session data, and agent activity into one reconciled stream.
Evidentiary Record Agent
Writes the reconciled stream to the firm-owned audit store in tamper-evident, hash-chained form.
Cowork Recovery Agent
Closes the Cowork audit gap, captures session activity directly from the user’s device.
Retention & Deletion Agent
Executes selective deletion via the Compliance API, honours legal holds, attests every action.
Policy Violation Triage
Classifies suspected violations by severity and routes them to the correct reviewer with evidence attached.
PII Redaction Agent
Identifies personal data in prompts before they reach the model, tokenise, strip, or block per policy.
Prompt Policy Checker
Validates every prompt against the firm-wide, team-specific, and matter-specific policy rules.
Audit Continuity Agent
Joins Compliance API, Usage & Cost API, Cowork session data, and agent activity into one reconciled stream.
Evidentiary Record Agent
Writes the reconciled stream to the firm-owned audit store in tamper-evident, hash-chained form.
Cowork Recovery Agent
Closes the Cowork audit gap, captures session activity directly from the user’s device.
Retention & Deletion Agent
Executes selective deletion via the Compliance API, honours legal holds, attests every action.
Policy Violation Triage
Classifies suspected violations by severity and routes them to the correct reviewer with evidence attached.
DSAR / Subject Access Agent
Produces statutory subject-access response packs inside GDPR 30-day and CCPA 45-day deadlines.
Anomaly Detection
Flags abnormal usage against per-user, per-team, per-matter behavioural baselines.
Regulatory Change Watcher
Maps new bar-association and DPA guidance to the specific framework controls that may need adjustment.
Knowledge Base Agent
Serves governed, version-controlled precedent into prompts with full citation tracking.
User Intelligence Agent
Reasons over an individual attorney’s interactions, always within their own entitlements.
Organization Intelligence
Aggregated, permission-respecting insight at the practice-group and firm level.
Cost Attribution Agent
Reconciled cost estimates at practice group, matter, or attorney level, useful for chargeback and budget.
Cost Anomaly Agent
Abnormal spend patterns, often the earliest indicator of abnormal usage.
Built with the firm
Contract-review agent against the firm’s own precedent library. Deal-risk agent over the investment committee archive.
Self-improving via Decision Intelligence
Custom agents that sharpen with use, tuned against the firm’s own matters, outcomes, and partner feedback.
DSAR / Subject Access Agent
Produces statutory subject-access response packs inside GDPR 30-day and CCPA 45-day deadlines.
Anomaly Detection
Flags abnormal usage against per-user, per-team, per-matter behavioural baselines.
Regulatory Change Watcher
Maps new bar-association and DPA guidance to the specific framework controls that may need adjustment.
Knowledge Base Agent
Serves governed, version-controlled precedent into prompts with full citation tracking.
User Intelligence Agent
Reasons over an individual attorney’s interactions, always within their own entitlements.
Organization Intelligence
Aggregated, permission-respecting insight at the practice-group and firm level.
Cost Attribution Agent
Reconciled cost estimates at practice group, matter, or attorney level, useful for chargeback and budget.
Cost Anomaly Agent
Abnormal spend patterns, often the earliest indicator of abnormal usage.
Built with the firm
Contract-review agent against the firm’s own precedent library. Deal-risk agent over the investment committee archive.
Self-improving via Decision Intelligence
Custom agents that sharpen with use, tuned against the firm’s own matters, outcomes, and partner feedback.
The framework learns, without crossing the lines it exists to defend.
A governance layer that ships on day one and never changes ages out of compliance. Regulators publish new guidance. Claude ships new surfaces. Bar associations issue new ethics opinions. Cases like Heppner redraw the privilege map overnight.
Attri doesn’t just deploy. We stay, as the firm’s AI counsel.
Legal AI is not a one-time integration. A managing partner fields new questions every quarter, those questions don’t have vendor answers. They have advisory answers, informed by what other firms have done and what the framework already supports.
Strategic AI counsel
A named senior consultant who knows the firm’s obligations, Anthropic’s roadmap, and the open questions the partnership is sitting on.
Quarterly reviews
A standing session with legal, security, and platform leadership. Regulatory changes. What the framework caught. Recommended tuning. Memorialised in writing.
24/7 managed operation
Incident response on policy violations. Anomaly review. Regulatory-change tracking. A 2am Saturday event is triaged the same way as a Tuesday afternoon one.
Sector intelligence
Every new regulation mapped for one client becomes a default for all. Detection rules compound across engagements, confidentiality intact.
The questions every serious legal buyer asks before signing.
Can't find what you're looking for? Talk to our team.
No. Harvey and CoCounsel are purpose-built legal AI platforms with their own audit surfaces and governance contracts. Attri does not wrap or replace them.
Our engagement is with the direct Claude deployment the firm runs alongside those platforms, Claude Enterprise, Cowork, the API, and MCP connectors. That’s the surface the firm owns itself, where governance is the firm’s responsibility.
