PlatformDelivery BoardAutomation & RunbooksOutcome ReceiptsJust-in-Time ElevationCredential VaultGoverned SessionsDevices & DiscoveryPatch ManagementReporting & ExportsRoles & Multi-Tenancy
Verified AI OperationsThe Operation LoopCommanded AutonomyCompare the operating modelThe Verified Operation Spec
SolutionsFor MSPsFor Enterprise & Internal ITHealthcareLegalFinancial servicesMunicipal & Education
ProofOperation walkthroughSecurity & architectureVerified Operation SpecFive questions for your RMM's AIChangelog
CompanyAboutFounder's noteContact
PricingBuy 1–20 technician licenses onlinePlans — from $499 per monthCustom requirementsFoundation Circle
Log in

Home/Solutions/Legal

Legal

Support the work. Respect the matter.

A firm's confidentiality obligations do not stop at the door of the IT closet. The person who repairs a fee-earner's laptop is, for as long as that repair lasts, someone with access to a machine full of privileged material — and at most firms nothing records who that was, what they were allowed to do, or when it ended. Seraph makes that a fact you can produce rather than a gap you hope nobody probes.

What the record names · OP-004417
the machineone workstation, named
the servicedocument client re-bound to its host
who said yesa named person at the firm, 16:24
the rightssix minutes, this operation only
who confirmed itthe workstation, on a fresh check
the matternever requested, never stored
the documentsnever opened, never read

The characteristic ticket

16:20, and the filing is at midnight.

Aisha is a litigation associate. Her document management client stopped authenticating this afternoon — a certificate renewal on the host changed the binding, and now every check-out fails. She has an e-filing due at 23:59 and a brief she cannot open. This is not a security incident. It is a Tuesday. But it lands on a machine that holds privileged material, and the way it gets fixed is exactly the thing a client's outside counsel guidelines will ask about at the next review.

  • 16:20

    She reports it where she already works

    A message in the firm's help channel. It becomes a typed outcome — the document client authenticates again on this workstation — not a paragraph a technician has to interpret at the end of a long day.

  • 16:22

    A proven fix is selected, not written

    The planner matches a certified runbook: re-bind the client to its host, with the check that defines success and the way back already written down. Nobody is drafting a script against a fee-earner's machine four hours before a deadline.

  • 16:24

    A named person at the firm authorizes it

    Not a policy, not the AI. A person, whose name is on the operation from that moment. Six minutes of rights are granted, scoped to this operation on this one workstation, expiring on the clock.

  • 16:26

    The work runs, and the credential never reaches the model

    The connection is authenticated before any generated step exists. The planner is given the operation, the target and the outcome to reach. The password is resolved by the executor from the vault and is never delivered to the model.

  • 16:29

    The workstation answers, and the record seals

    An independent check on the machine itself confirms the client authenticates. The rights expired at 16:30 whether or not anyone was watching. Aisha files at 21:40.

The boundary that matters

A screen that IT can walk through is not a screen.

Firms build ethical screens carefully: this matter, these three people, nobody else. Then a workstation breaks, and the person who fixes it works under an account that predates the screen, answers to no particular authorization, and leaves behind a ticket note. The screen is intact on paper and quietly permeable in practice. The fix is not to keep technicians away from machines — it is to make every approach to one asked for, bounded and named.

The matter screen, and what reaches inside itOP-004417
WITH A SHARED ADMIN ACCOUNT MATTER 4471 SCREENED TO THREE PEOPLE PLEADINGS AND MEMOS TIME ENTRIES AISHA'S WORKSTATION SHARED ADMIN never expires OPENS WHATEVER IT CAN OPEN WHAT YOU CAN SHOW THE CLIENT: a ticket note someone typed WITH A LEASED, RECORDED OPERATION MATTER 4471 SCREENED TO THREE PEOPLE PLEADINGS AND MEMOS TIME ENTRIES AISHA'S WORKSTATION LEASED IDENTITY one operation ONE SERVICE, EIGHT MINUTES WHAT YOU CAN SHOW THE CLIENT: OP-004417 · who, what, when, confirmed
We are careful about what this claims. Leasing does not build a physical wall around a file a technician could otherwise open. What it does is narrow what the access is for, stamp an expiry on it, and put a name on it — so the question "who approached that machine, and under what authority" stops being a matter of recollection.

Who asks for it

Three people the firm administrator answers to.

The firm administrator is usually the one holding this. Not a security team — often there is no security team — but the person who owns the vendor questionnaires, the insurance renewal, and the awkward email from a client's general counsel.

The client's outside counsel guidelines

Corporate clients now attach security terms to engagement letters: who may access systems holding our material, under what controls, and how you would know. Those clauses were written to be answered with evidence. Most firms answer them with a paragraph.

You answer with the operations that ran on the machines in question, each one named, bounded, confirmed and reversible.

Exports and client packs →

The professional-liability renewal

The automation section of a lawyers' professional-liability or cyber renewal asks what your tooling is permitted to do unattended, whether it holds standing privilege, and how you would detect it doing something else.

Answer it with records instead of prose. Nothing on this site is worth more to that conversation than a chain of operations nobody can quietly edit.

What a record holds →

The partner who owns the screen

When a screen is challenged, the question is not whether a policy existed. It is who actually touched what. A supervising partner needs to be able to look, not to be reassured.

Every operation on a machine carries the name of the person who authorized it and the name of any technician who took the wheel mid-operation under their own fresh lease.

How leases work →

The questions firms actually ask us.

Does the AI read our documents?

No. It is never given them. The work happens at the machine, service, account and update layer — restart a service, re-bind a client, repair a profile, rotate an account, apply an update. The planner receives the operation, the target and the outcome to reach. It does not receive credentials, and it is not handed matter content. What the record carries is the machine, the operation, the authorization, the confirmation and the undo.

Can you prove a screened person never touched a screened matter?

No, and we will not pretend otherwise — nobody can prove that negative from a tooling record. What we change is that the question becomes answerable in the first place. Every operation names who authorized it and who, if anyone, took the wheel. Instead of "we believe our screens held", you produce the list and let the partner read it.

Our client requires notice of any vendor access to their material. What do we hand them?

The operations that touched the machines associated with that client, over whatever period they asked about, as PDF for a human or CSV and JSON for their systems, under your branding. Each one carries the authorization, the privilege and its expiry, the confirmation from the machine, and the declared undo. A recipient can walk the chain and check it holds together without our help.

Does this replace the audit log in our document system?

No. That log tells you what happened inside the application — who opened a document, who checked it back in. It is the right tool for that and we do not duplicate it. Seraph records what happened to the machine and the services underneath it, which is precisely the layer your document system's log cannot see and where a technician's access actually lives.

What about time entry at month end?

Same shape, different urgency. A fee-earner locked out of time entry on the last working day of the month is the second most common version of this ticket, and it fails in the same places: an authentication binding, a profile, a stale credential. The value is not that Seraph is faster than your technician — it is that when the partner asks what happened to their machine, the answer already exists.

Straight about scope

What we do not claim here.

  • No practice-management or DMS integration. We do not connect to your document system, your practice management platform or your billing system, and we do not process matter content.
  • We supply evidence; we do not attest. We are not an assessor, and nothing here is an attestation that your firm meets a standard. Our own SOC 2 position is on the trust center.
  • No proof of a negative. A record shows what an operation did. It does not show that nothing else was ever seen on a screen.
  • No complete session recording. Where a technician has to be on a machine, we describe governed launch, authorization and binding to the operation — and we are deliberately narrow about what the session record covers today.

The professional-responsibility duty to make reasonable efforts against unauthorized disclosure is the firm's, not ours, and it is not discharged by buying software. What we think Seraph adds to it is unglamorous and specific: access to a machine holding privileged material becomes something that was asked for, granted narrowly, timed out, confirmed by the machine, and written into a record that later records depend on. If your risk partner wants to attack that claim, bring them to the demo — that conversation is more useful to us than a signed quote.

Fifteen minutes, on a live system

Bring the clause from your hardest client's engagement letter.

We will run an operation end to end, open the record, and show you exactly which line answers it — or tell you plainly that it does not.