Skip to content

AI governance for law firms

Enable AI in your firm. Keep matter access deliberate.

Cocha helps law-firm CIOs and CISOs deploy Claude Enterprise and Copilot with permissions, connected data, and ongoing governance in view. Steven R. Combs brings 15 years working with law firms and 30 years in IT.

60-minute working session · Written findings · Follow-up review · No obligation to purchase

What your team needs to decide.

Matter boundaries

Which users, groups, and connectors can reach a matter’s documents? Review access against your firm’s ethical-wall requirements before broadening a rollout.

Approved working practices

Give attorneys and staff a usable approved tool, clear handling rules, and a way to raise exceptions with IT and security.

Evidence for decisions

Record the controls checked, unresolved questions, and owners. Build a clearer basis for internal reviews and client security conversations.

Experience with real rollout decisions.

Claude Enterprise rollout

Cocha supported a net-new Claude rollout for a large Canadian law firm. The client’s feedback emphasized controls and considerations their team had not identified before Cocha became involved.

Copilot rollout and ongoing governance

Cocha supports a large U.S. law firm with its Copilot rollout and ongoing advice as the ecosystem changes.

Engagement summaries, not direct client quotations. Client names are withheld.

Senior-led delivery with Steven R. Combs: 30 years in IT and 15 years working with law firms. Gabriella San Miguel coordinates projects, scheduling, and business operations.

Start with the firm's actual workflows.

Start with a focused diagnostic. Where deeper analysis or changes are needed, we agree on a paid scope with your team before work begins. Implementation and ongoing advisory are tailored to the environment, not included in the free Snapshot.

Access priorities

A scoped review of sharing, guests, group membership, and connected sources relevant to the rollout.

A controlled pilot

Defined users and use cases, documented connector decisions, and agreed tests for the data boundaries that matter.

Ongoing governance

A cadence for evaluating Copilot and Claude changes, recording exceptions, and keeping IT and security involved.

A useful next step before a bigger commitment.

The free AI Readiness Snapshot covers five areas: data security posture, data access, monitoring coverage, Shadow AI exposure, and a Microsoft Secure Score baseline.

Your administrator reviews and runs a read-only SharePoint exposure script before the 60-minute working session. We provide written findings within five business days after the session and receipt of the required inputs, then hold a 30-minute review.

A bounded diagnostic, not a complete tenant audit, penetration test, regulatory certification, or implementation plan.

Read the Snapshot scope · See preparation requirements

Bring your existing IT team.

We work alongside internal IT, security, and your MSP. Your team remains part of the decisions, implementation, and handoff.

Steven leads the advisory work. Gabriella San Miguel coordinates project activity and scheduling.

Already have an agreed project? Request a project conversation.

Questions before you begin

Does the Snapshot verify every matter or ethical wall?

No. The free Snapshot is a bounded diagnostic. Detailed matter-permission testing and validation of ethical walls require a separately agreed scope.

Do we have to buy anything after the Snapshot?

No. The working session, written findings, and follow-up review are free. You can act on the findings with your own team. Deeper assessments, implementation, and advisory are scoped separately.

When will you respond?

We aim to respond within 4–8 business hours, Monday–Friday, 8 AM–5 PM Central. The overall schedule depends on your team's availability and the agreed inputs.

Read before you book.

Existing Cocha articles relevant to these decisions.