LegalFab: The vertically integrated answer to the governance gap

“It is the most impressive thing I’ve been shown in this particular space in the market.” Neil Cameron, lead analyst for Legal IT Insider, examines LegalFab, a new agentic operating system for law firms. 

In Gen AI 3 I argued that the governance of AI agents is cross-system by nature. An agent traverses the document management system, practice management, finance and email in a single task, and no content vendor owns all of those. I set the enforcement layer out as a spine between the applications a firm buys and the data they consume, and observed that nobody owned it.

I have now seen LegalFab demonstrated for two hours by its chief executive, put a two-page question set to the company, and read the architecture document it has since published. I told them at the time that I would summarise what I had seen under the word ‘astonishing’. I do not withdraw it, and I want it at the top rather than buried, because most of what follows is the harder question of what has been evidenced.

LegalFab is the vertically integrated answer to that gap. Rather than build an enforcement layer between other people’s systems and other people’s agents, it proposes to own the resolution layer, the governance layer and the agents together. Three layers: a Knowledge Fabric that resolves entities across the estate, an Agentic Studio for composing teams of agents, and pre-built utilities of which compliance and conflicts is the most developed. The architectural claim carrying all the weight is “connect, don’t copy” – active metadata over live sources, with only the resolved layer persisted and raw records left behind the firm’s boundary.

Disclosure. I have known Simon Thompson professionally for several decades. I also told LegalFab during the demonstration that I am working with an alternative vendor on a pricing engine for a law firm pilot, and declined to be shown their pricing module. This review is unpaid and unsponsored.

The declaration

I asked the company where it sits relative to everyone else, and which layers a firm would continue to buy elsewhere. The written answer declines the framing entirely – LegalFab, it says, is a change in a firm’s operating model, not another product in the stack – and then answers anyway. The firm keeps its systems of record, infrastructure, identity, security and any specialist applications it chooses to retain. Everything above that is contested, explicitly and over time: some applications may remain, some become narrower systems of record, some capabilities get rebuilt on LegalFab.

Then this: Intapp is the clearest and most immediate example of the model LegalFab is built to succeed. The company says that LegalFab may progressively subsume solutions from incumbent legal technology providers, but the point is that firm’s do not have to replace these solutions before adopting LegalFab. It is once data, identity, governance, intelligence and execution are unified across the enterprise, that many functions currently requiring separate applications can increasingly be performed within the common LegalFab architecture. This transition will happen progressively.

I have not previously had a vendor name its displacement targeting so directly, in writing and for publication. It is the clearest statement of the vertical-integration thesis anyone in legal has made, and a considerable risk: a product that replaces conflicts, displaces the CRM and obviates the warehouse has no single budget holder and invites every incumbent it threatens to defend at once.

What the demonstration showed

The compliance sequence is the most immediate evidence of where the product is strongest. A commercial real estate matter days from completion; an email from a client director asking that funds go to a party nobody has heard of. The system scores it for money laundering risk, states which of the firm’s red-flag rules have triggered and why, separates known client and counterparty from unknown third party, and proposes a silent background check – silent because tipping off is an offence. The check returns no adverse media but characterises the new party as a probable shell: no trading history, registered at a formations agent, in a high-value transaction. The analyst accepts, and the system drafts a suspicious activity report onto the regulator’s template, populated and routed for approval.

The most important moment received the least airtime. A regulatory change – the FCA treating crypto asset exposure as high risk – was detected, matched against the client base, and then encoded: a no-code rules editor, a new condition, a weighting, saved, live across the firm. The gap between a compliance team learning of a change and the firm’s systems reflecting it is measured in weeks and is structural, because one team understands the rule and another encodes it. Collapsing that into one screen is a serious operational claim.

It is also the point at which an authorised user can make a rule change with firm-wide consequences. Firms should test the permissions, dual-control requirements, approval path, version history, rollback and audit trail there first. The same applies to the SAR: deciding whether and how to report engages criminal-law obligations, including tipping-off risk, and a system that assembles the document in thirty seconds changes the character of that judgment whether or not a human signs.

Permissions, and whose graph wins

Two answers arrived in two versions, and both reconciled properly when pressed.

On ethical walls, the demonstration suggested inheritance; the written answers describe enforcement at a derived layer, via a consolidated permission model that exists because the source systems’ models do not align. The company’s position is that these are halves of one mechanism. Inherited access controls are the floor and can only make it stricter, never looser; but a wall must hold around a client or matter living in several systems at once, which no single system can see, so it is also enforced on the resolved graph. Crucially, the reconciliation rules are said to be authored and signed off by the firm’s risk and general counsel function rather than the vendor, seeded from the conflicts system and existing barriers, inspectable rule by rule. A wall the firm does not own, as the company puts it, is not a wall.

That is the right answer. The caution is that seeding does quiet work: where three source models genuinely conflict, whoever writes the first version sets the default, and sign-off is not authorship. Firms should ask to see the reconciliation rules, not the reconciled result.

On graph precedence the rule is cleaner still: whoever genuinely owns the information wins. Cross-system questions – is this the same client in the DMS, in finance and in email – belong to the resolution layer, because no single system can answer them. Content a single system is the system of record for belongs to that system. Precedence is configurable per source and entity type, low-confidence resolutions route to human adjudication rather than resolving silently, and every resolution carries its lineage. Given that NetDocuments now has a context graph and iManage an inference layer, this is the most coherent statement of coexistence I have had from anyone.

Where the current evidence stops

Against that, the evidence base currently appears narrower than the proposition, largely by reason of novelty.

The company was founded in January 2026, is London headquartered with around forty staff, self-funded and angel-funded, and reports one production pilot with a UK full-service firm and one contract with a German IP boutique. Both are confidential and no reference is available. Conflicts is the most conservative purchase a law firm makes, and no architecture solves that.

Connectivity needs care. The software was demonstrated live in a populated environment and it completed the opening query – active matters unbilled for thirty days with average work in progress older than sixty days, by client. The interface showed the question decomposed into sub-queries, agents reaching the displayed operational sources, and an actionable table returned with matter-level financials behind it. That establishes an implemented cross-system workflow. It does not by itself establish the production status of every connector shown, and the source list on screen carried Elite, Aderant and PeopleSoft. The company is MCP-first but not MCP-only, reaching systems directly by API or database where an MCP surface is poor or absent, and Thompson made the point that legacy legal systems are often easier to reach that way rather than harder.

Asked for the running set, the company identified eleven systems as the focused set proved in its current deployments, and called it a narrow legal-specific list. It is worth reading closely, because it is not a marketing list. Alongside iManage, NetDocuments, Aderant, HighQ, Salesforce, SharePoint and the Microsoft stack sit STP – the Karlsruhe law firm and insolvency platform now trading as Septeo – and Genese, the Bremen patent and trade mark management system. Those two are not systems anyone names speculatively, and they appear to map onto the German IP boutique as the rest appear to map onto the UK firm. The company gave the list without padding.

Two things follow. Proclaim, Visualfiles and SOS Connect and such are absent because no customer has yet required them, which is consistent with the company’s stated model of treating connectivity as a commodity built per engagement – and the two deployments it describes required systems most vendors have never heard of, which supports its account that it builds what each engagement needs. For mid-market and defendant-insurance firms this is a delivery question rather than a capability one, but it is still a delivery question. The figure of over a thousand in the deck needs qualification: it describes the broader addressable connectivity surface, not a thousand production-proven legal connectors. The demonstration referred to 200-plus; the set evidenced in current deployments is eleven. The eleven are the more impressive number.

Asked to attribute two performance claims, the company confirmed that the straight-through-processing figure and the 85 per cent reduction in false positives comes from prior financial services work. Its benchmarking method is better than most, and it volunteers that its mature figures come from a financial-services production setting rather than a live legal deployment, with legal replication to be labelled model output until validated. That is a creditable admission. It also means that neither of the two headline figures put to me was supported by validated results from a live legal deployment. The wider gap is independent assessment. No independent product-level evaluation was made available to me establishing that the implementation matches the architecture document. That document is unusually good, and much of the architectural assessment in this review rests on it, but it is a description of intent written by the company whose intent it describes. A firm’s own security function will want more, and should ask early and properly: an accredited certificate verified through the accreditation body rather than the issuer or the vendor, and the underlying audit and penetration-test reports rather than summaries or certificates. That is a reasonable standard for anyone claiming to hold the record by which their own conduct is proved.

Assessment

I have not seen anything like this for law firms, and I have looked. Products exist that do parts of it: intake and conflicts, client intelligence, document understanding, agent orchestration. I have not seen another product resolve the estate, reason across it, act on it and encode the firm’s own rules in the same motion, nor take the compliance sequence end to end from an inbound email to a populated report on the regulator’s template. The architecture documentation is the best I have seen in this sector, and the candour on the mosaic effect – that inference from legitimately visible material cannot be claimed away, only bounded and logged – is rarer still.

The proposition does concentrate authority – over resolution, over permissions, over action, and over the record by which all three are proved. Every vendor produces its own audit trail, so that on its own is unremarkable. What is not unremarkable is that in a multi-vendor estate the records can disagree, and the disagreement provides an accidental check. Centralise resolution, permissions, action and their audit record in one platform and that check diminishes. This is less a criticism of LegalFab than the trade its model asks a firm to make: consistency and coherent control in exchange for some of the independence multiple systems supply by accident. Firms should make it knowingly, and should want independent assessment of the architecture in proportion to how much they hand over.

None of which is a reason not to look at it, indeed, it is a reason for looking at it sooner rather than later. Waiting for a fuller reference list reduces adoption risk; it also gives the incumbents whose territory LegalFab contests time to respond. The company chose the standard itself – proof, not assurance. I will report on progress.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top