Governance Core
The firm's AI supervision record, in one place.
A register of every AI tool, a policy engine that runs on every governed task, a COLP dashboard over the whole estate, and a tamper-evident evidence chain underneath. Not a pilot. Compliance infrastructure, with a renewal date.
What it is
Four parts, one record.
Each part is useful on its own. What makes it a system of record is that they all write to the same evidence chain.
The register
Every AI tool in the firm, who approved it, at what risk tier, under what policy, and how each entry is actually substantiated. Shadow tools included.
Inside the registerThe policy engine
Your AI use policy, running as code rather than sitting in a document. 19 checks on every governed task: 13 protocols and 6 deterministic gates, mapped to the SRA duties they answer.
The COLP dashboard
One worklist and one set of numbers across the whole estate, with per-tool provenance on every figure. Failing signals rank first, and every flagged item carries an action.
The evidence chain
Every governed event hashed, linked to the one before it and immutable at the database level, with exports shaped for a regulator, an insurer or a client.
Inside the evidence chainThe COLP dashboard
Risk before vanity metrics.
A supervision screen that opens on what needs a decision, with per-tool provenance on every number. Amber says a closer look is needed, never panic.
COLP dashboard
All tools
AI outputs governed
312
last 30 days
Citation pass rate
94%
up 3 points
Fabrications caught
17
4 from external tools
Open flags
3
1 blocking
Worklist, needs a decision
Fabricated authority in an external tool's output
Information-barrier warning on a draft
Three citations we could not auto-confirm
Data protection review due on a register item
By tool, pass rate and volume
LegalAI Space agents
An AI assistant
A general-purpose copilot
Unattributed
The COLP
The whole estate, worklist first. Which tools are producing work, what proportion of citations pass, what was caught, who signed off, and what still needs a decision today.
A supervising partner
Their team's matters and their own sign-offs, without the firm-wide noise. Oversight scoped to what they are actually accountable for.
A fee-earner
Their own record and nothing else. Framed as protection rather than surveillance, because a supervision tool that reads as monitoring gets routed around.
The guardrails
Two protocols. One before the work, one after.
Governance is not a setting a fee earner can switch off. Named guardrails run automatically on every agent. One protocol clears the matter before any work begins; the other checks the output before a lawyer ever sees it. Nothing skips them.
19 named protocols and gates ship with the platform, 6 of them deterministic Layer-3 gates enforced in code, not by a model. Each agent implements them through its own protocol stack. Nothing skips them.
Pre-run protocolsCleared before anything happens
These sit in front of the agent, not behind it. They decide whether the work should run at all, and on what.
Conflict Check
Screens the matter against connected CRM and practice-management data before a single keystroke of work. A conflicted matter never starts.
Jurisdiction Gatekeeper
Blocks work that mixes jurisdictions the matter is not configured for. A Scottish authority cannot reach an English matter.
PII Redaction
Detects and redacts personal data from agent inputs before processing: confidentiality enforced at the door, not audited after.
Planning Protocol
Writes a step-by-step plan before execution, jurisdictions, authorities, privilege concerns, and holds it for approval. The run is deliberate, not improvised.
In-run & post-run protocolsChecked before a lawyer sees it
These sit between the agent and the fee earner. The output is verified and scored before it is shown.
Legal Citation Verifier
Independently re-fetches and verifies every citation against the primary source: format, existence, current status. We do not trust the model's recall: we re-check its homework.
Regulatory Compliance Check
Evaluates the output against the SRA Code, FCA rules, ICO guidance and the EU AI Act: rule by rule, with a severity on every finding.
Output gate: draft, never advice
Every output is marked a draft for a qualified lawyer. Send-gated agents (pre-action, cease-and-desist, DSAR) never deliver on their own. A person sends them.
The guardrails named above are not the whole set. 19 protocols and gates ship in the catalogue. The rest run on the same automatic basis, none of them optional.

The register
Including the tools nobody approved.
The entries that matter most are the ones a firm would rather not write down. The register states the evidence depth behind each row, so nobody mistakes an attestation for telemetry.
AI register
5 tools registered · 1 pending review · AI use policy in force
LegalAI Space agents
ApprovedGoverned risk · COLP · Native evidence
Harvey
ApprovedHigh risk · COLP · Usage API
Microsoft Copilot
ApprovedMedium risk · IT director · Audit-log ingest
ChatGPT, personal accounts
Not permittedShadow risk · Unassigned · Attestation only
A practice-area tool under evaluation
Under reviewHigh risk · Head of KM · Manual, quarterly
The evidence chain
What comes out at the end.
Each governed event is hashed and linked to the one before it. Change an earlier link and every hash after it stops matching.
run_started
hash 9f41…c2
citations_verified
prev 9f41…c2
policies_evaluated
12 linked verdicts
human_review
named reviewer
certificate_issued
insurer pack
report_exported
sha256 anchored
The exports are shaped for whoever is asking: an SRA-aligned period audit report, a per-run evidence pack, a PI insurer pack, a client AI-use disclosure, an EU AI Act oversight attestation, or a frozen inspection bundle.
The obligation is already here.
The SRA Standards and Regulations
The SRA already requires proper governance, competence and a record of how work was produced. Every one applies to AI-assisted work today, because the regulator does not wait for new rules.
Courts sanctioning unverified AI
In Ayinde v London Borough of Haringey and Al-Haroun v Qatar National Bank, handed down 6 June 2025, the Divisional Court addressed fabricated authorities in court filings and referred individuals to their regulators. An unverified output is a professional risk, not a convenience.
EU AI Act, high-risk obligations
The AI Omnibus, in force 27 July 2026, moved the high-risk application date from 2 August 2026 to 2 December 2027 for standalone systems, and to 2 August 2028 where the AI is embedded in a product. Transparency duties and the record-keeping expectation are unchanged, and most off-the-shelf tools still cannot export the record.
The record is the deliverable
When an inspection comes, the question is the same: can you prove this output was governed? A signed, reproducible audit record is the answer, written as the work happens rather than assembled the night before.
From the blog
Governance, built in
Why a policy document is not a control, what a governance framework has to cover, and what an SRA-ready audit report must prove.
Governance Core, answered.
What it covers, how it differs from generic compliance tooling, and what it takes to stand up.
Still have questions? Talk to the founderGovernance, before the regulator asks for it.
Start with the free readiness check, or tell us what your firm is running and we will show you what the record would look like.