← Selected work
github.com/scadam/digital-lawyer · Agent · Foundry · Legal

Digital Lawyer — AI Associate Solicitor

A Digital Worker — an AI Associate Solicitor named Alex Morgan (agent:A-45219) — built with the Microsoft Agent Framework and the Agent 365 SDK. Alex reviews supplier agreements, identifies policy deviations, produces structured redlines, logs risk decisions, and escalates when approval authority is exceeded — every action recorded in an immutable audit trail.

5File-backed MCP servers
18Step autonomous review
2A365 tooling servers
0API keys — MI only

An Entra-backed digital employee

Not a traditional bot — a governed digital worker with its own identity, lifecycle and risk footprint, appearing in Teams like a person.

Five systems

The systems a firm runs on

Document management (DMS), practice management (PMS), a policy & governance store, a risk register, and time & billing — each a file-backed MCP server locally, each a thin REST wrapper (iManage, Clio, ServiceNow GRC, Elite 3E…) in production.

Contract review

Clause-by-clause, with escalation

Runs a 13-step review of a supplier agreement, identifies deviations by severity, and writes a structured escalation pack when — for example — a 3× liability cap exceeds the firm's 1× policy maximum.

Word + Mail

Marks up documents over email

Listens on the email channel, generates a real .docx, inserts tracked changes and comments via the Agent 365 Word MCP Server, and replies with findings via the Mail MCP Server — a fully autonomous 18-step workflow.

Governance

Managed Identity, end to end

Authenticates to every Azure service via Managed Identity — no API keys anywhere. Every tool call is logged with actor identity, inputs, result summary and UTC timestamp in an immutable audit trail.

Activity & Billing dashboard

A Teams-styled tab on Alex's profile — in production it sits alongside Chat, Files and Storyline, giving supervisors an at-a-glance view of the agent's work, billed time and risk decisions.

In Alex's words

"I act only within the scope of the matter assigned to me — no cross-matter access without explicit assignment. I cannot approve deviations from firm risk policy that exceed my delegated authority; anything requiring Partner approval or above triggers a structured escalation pack."

"Every tool call I make is recorded in an immutable audit trail — actor identity, tool name, parameters, result summary and UTC timestamp. I authenticate to all Azure services via Managed Identity; no API keys are used anywhere in my stack. My sponsor is Scott Adams — all escalations go to him first."