Legal · Colleague: Lex

From contract intake to DSAR fulfilment, on autopilot with approval

Lex, your Legal Colleague, routes contracts, drafts NDAs from templates, handles DPAs, coordinates legal holds, and answers the security questionnaire — every draft grounded in your library.

Phase 5 · Q3
Capability 01

19 pre-built Legal playbooks

Contract intake · NDA drafting · MSA/SOW from templates · contract status · counterparty redline tracking · DocuSign envelope management · vendor legal review · DPA handling · subprocessor list · legal hold · eDiscovery collection · subpoena response · DSAR routing · privacy review for new features · IP assignment · policy Q&A · security questionnaire · outside counsel engagement · corporate actions.
grounded answer · sources
answer

Priya’s Okta lockout can be cleared via self-serve MFA challenge — no IT intervention required. If MFA fails, escalate to IT on-call.

cited from
01
IT · Okta account lockout policy
runbook · updated 4d ago
02
HR · Emergency access procedure
policy · updated 2w ago
03
Ticket #48211 · priya · resolved
past ticket · similar match
Capability 02

Grounded in your templates

Every NDA / MSA / SOW draft starts from your approved template library, not a generic template scraped from the web. Redlines show the diff against the template so counsel can spot deviations in seconds. Custom terms surface for attorney review.
approvals · pending 4
unlock okta account
priya.sharma · self-serve · read-only
denyapprove
refund $128.40
stripe · ord_A4b2c · manager approval
denyapprove
revoke prod IAM role
aws · role/analyst · step-up MFA
denyapprove
reset zoom SSO
kiran.mehta · self-serve
denyapprove
Capability 03

Approvals where required

Attorney sign-off on non-standard MSA. GC approval on corporate actions and outside-counsel engagement. Privacy counsel on DPA custom terms. Every approval chain configured once and enforced with step-up MFA on the reviewer.
context · priya.sharma
priyateamon-calloktagithubworkday
Capability 04

Deadline-aware

SLA calendar for every statutory deadline — DSAR windows (30 days GDPR / 45 CCPA), subpoena response times, discovery deadlines. Escalation ladder before deadline. No missed statutory response, ever.
reports · this week
Auto-resolved
78.4%
+4.1 pt
Avg. loop time
11.4s
-2.1s
Approvals pending
12
-3
Coverage
94%
+1.2 pt
monsun
Capability 05

Connected to Ironclad, DocuSign, and the eDiscovery stack

Contract status lookup + envelope management in Slack. Legal hold applies across Google Vault + M365 Purview + Slack + email in one playbook. eDiscovery collection packages with chain-of-custody documented per matter.
grounded answer · sources
answer

Priya’s Okta lockout can be cleared via self-serve MFA challenge — no IT intervention required. If MFA fails, escalate to IT on-call.

cited from
01
IT · Okta account lockout policy
runbook · updated 4d ago
02
HR · Emergency access procedure
policy · updated 2w ago
03
Ticket #48211 · priya · resolved
past ticket · similar match
Capability 06

Security questionnaire response, drafted

Vendor questionnaire lands; Lex matches each item against your answer library (Vanta + Drata + past questionnaires), drafts responses, routes to security for review. Turnaround under 2 days — down from the industry-standard 2 weeks.
approvals · pending 4
unlock okta account
priya.sharma · self-serve · read-only
denyapprove
refund $128.40
stripe · ord_A4b2c · manager approval
denyapprove
revoke prod IAM role
aws · role/analyst · step-up MFA
denyapprove
reset zoom SSO
kiran.mehta · self-serve
denyapprove
The BeforeQuery method

Visibility. Reasoning. Action.

Every playbook, every action, every answer follows the same three-beat rhythm — one that keeps every write behind evidence and every decision behind policy.

01

Visibility

Read the full context — who is asking, what they own, what they can access, what breaks if we touch it. Nothing acts on incomplete signal.

02

Reasoning

Match the request to a grounded answer or a playbook. Cite the source paragraph, weigh the risk tier, and route to the correct approver where policy demands it.

03

Action

Execute the write on your systems with an audit-log id, an entity list, and a rollback path. Confirm the outcome with the requester in the same thread.

How every request flows

From ask to resolution in one loop

Six stages every request travels. What changes is how many stages policy lets the agent execute without waiting on a human.

01
Request

In Slack, email, widget, MCP, or the helpdesk. Same voice, same context.

Slack · Teams · Zendesk · Widget · MCP
02
Retrieve

Grounded lookup against your knowledge with source paragraphs held aside.

Knowledge Studio
03
Reason

Read the Context Graph — who, what they own, what breaks if we touch it.

Context Graph
04
Approve

Route to the correct approver per policy. Reversible writes gated, destructive step-up.

Approval matrix
05
Execute

Act on Okta, Stripe, Workday, GitHub, or your own systems. Logged and attributable.

Actions runtime
06
Verify

Confirm the outcome with the requester. Feed the result back into future decisions.

Feedback loop
Watch it work

Customer questionnaire → 240 questions answered in 2 hours

The enterprise-security-questionnaire tax, gone. Answer library grows with every submission.

slack · #it-help
live
$sales · deal-9812:Acme sent 240-question CAIQ security questionnaire, due Friday
·
lex parse XLSX: 240 questions across 12 categories xlsx.parse
·
lex match against library: 180 high-confidence · 42 partial · 18 novel answer.library
·
lex draft 180 auto-filled with citations · 42 flagged for edit draft.batch
·
lex route 18 novel questions to SMEs (CISO, CTO, VP Eng) sme.routing
lexsales:Draft ready for your security-lead review. Est 2 hours to sign-off.
drafted · 8m · 92% of questions auto-answered·sources cited · library updated

Every accepted answer feeds the library. Next quarter's Acme-shaped questionnaire will hit 220 high-confidence matches instead of 180.

Enterprise-grade by default

The controls your security team is going to ask about

SOC 2 Type II
audited annually
GDPR
EU data residency
HIPAA-ready
BAA available
SSO / SAML
Okta · Entra · Google
SCIM 2.0
auto-provision
Audit log
every write, traceable
Bring your key
AES-256-GCM at rest
Bring your model
Anthropic · OpenAI · self-host
Zero training
your data stays yours
Rollback
every write reversible
TLS 1.3
in transit
99.9% uptime
SLA on Enterprise

Frequently asked questions

Common questions about Agentic Legal

Both. For standard-template contracts (NDA, MSA, SOW from your approved forms) Lex drafts the full document with the parties + terms filled in — legal reviews before send. For non-standard requests, Lex routes to the right attorney with the intake info bundled and drafts a first response based on prior similar deals.
Ironclad and DocuSign as first-party in Phase 5. PandaDoc, Adobe Sign, ContractPodAi via UIA. Contract status, envelope tracking, redline detection, and metadata updates work across all supported CLMs.
Subject request lands via form or email. Lex verifies subject identity, enumerates data locations across your systems (CRM, marketing, data lake), packages the response per your policy (access, deletion, portability), and routes to privacy counsel for review before send. Statutory-deadline countdown surfaces in the queue.
One playbook applies the hold: identifies custodians from HRIS + IdP, applies Vault / Purview hold on their mailboxes and drives, notifies each custodian, tracks acknowledgement. Full audit trail per matter. Every future termination checks against active holds before wiping data.
Lex Colleague + 19 Legal playbooks + Ironclad / DocuSign / Google Vault / M365 Purview integrations + approval chains with GC / attorney sign-off + statutory-deadline SLA tracking + security-questionnaire response.

Run legal on BeforeQuery

Book a demo and see what Agentic Legal does on your own data — usually within 45 days.