How it handles client data
This is the first question every firm asks, so here is the whole answer.
Where it runs
On each attorney's own computer, inside Claude Code. There is no MG Legal Ops server that receives, stores, or processes a firm's email, documents, matters, or time entries. The only network traffic is the same traffic to Microsoft 365 and Clio the attorney's own Outlook and browser already generate, made with the attorney's own sign-in.
Whose permissions it uses
The attorney's, and only theirs. It signs in with delegated permissions, which means it can see and do only what that attorney can. It never acts as another user and has no firm-wide access. The permissions requested are the narrow set needed: reading the attorney's own mail and calendar, writing a draft into their own Drafts folder, sending only on their confirmation, and reading and writing the specific Clio records described below.
What it can write, and how
Filing an email to a matter, a time entry, a task, a calendar entry, a new contact and matter, a draft, a send. Each is a separate, purpose-built action; there is no general "change anything" capability. Every one is proposed to the attorney first, exactly as it will happen, and runs only when they confirm it with a single-use code that expires within minutes. Every attempt is recorded in an audit log on that computer, holding identifiers only, never the content of an email. Anything it created can be undone the same way. It cannot delete mail, delete matters, or touch trust accounting.
What leaves the firm
Two things, both optional, both free of client data:
- Problem reports. When the assistant hits an error it can file a technical report with us so it gets fixed. Names, subjects, email addresses, message identifiers, and matter details are stripped before anything is sent, and the firm can turn this off.
- Monthly counts. With the firm's agreement, a monthly summary of what the assistant did: number of time entries and hours, emails filed, and so on. Counts only.
Both travel through a relay that holds a key per firm, so no firm can ever see another firm's reports.
The model
The assistant's reasoning runs on Claude, under the firm's own Claude subscription and Anthropic's terms for it. We recommend firms use a Claude plan with commercial terms. We do not see, log, or store the conversation.
What stays on the computer
Sign-in tokens, the audit log, and a small file of which email threads belong to which matters, all in files readable only by that user account. Deleting them signs the attorney out and forgets the shortcuts; nothing in Clio changes.
What it will not do
- State a billing gap or a duration as a fact. It flags possibilities; the attorney decides.
- Put the name of any tool into a time entry, a filed communication, or a client email. The software rejects such text.
- Follow instructions found inside an email. Content it reads is data, never direction, and it tells the attorney when a message tries otherwise.
Questions
Ask us anything about this at hello@mglegalops.com. We would rather answer a hard question before you sign than after.