Home › Use cases › Legal
Customer contracts, vendor contracts, M&A

Legal agents: 5 use cases

Legal agents need broad read and narrow write. Shared bot identities and deletion rights are where evidence gets lost.

ServiceNowSalesforceHubSpotAtlassian Each step lists the resource and the exact permission or role the agent uses.

L1

Contract intake & redline tracking

  1. TriggerSales files a request in Legal’s service desk
  2. Atlassian1Intake requestJsmRequest: read:request:jira-service-management
  3. Salesforce2Read draftContract: PermissionsRead
  4. Atlassian3Track redlineswrite:issue:jira, write:comment:jira, write:attachment:jira
  5. Atlassian4Return statuswrite:request.status:jira-service-management
  6. ParapetDelete blocked on contract-review issues.Deny excess
Why Parapet

The redline agent needs write:attachment:jira to post drafts but never delete:attachment:jira, which would destroy legal-hold-relevant prior versions. Parapet blocks delete on contract-review issues.

− granted: delete:attachment:jira available
+ needed: write:attachment only
L2

Vendor contract lifecycle management

  1. TriggerNew ServiceNow ast_contract from Finance onboarding (F4)
  2. ServiceNow1Read new contractast_contract · role:public
  3. ServiceNow2Attach standard clausesclm_terms_and_conditions, clm_m2m_contract_and_terms · role:public
  4. ServiceNow3Run compliance validationclm_condition_check · role:contract_system_admin
  5. ServiceNow4Log outcomeclm_contract_history · role:public
  6. ParapetOver-provisioned role flagged; scoped role recommended.Gate / review
Why Parapet

clm_condition_check requires contract_system_admin — far above the role:public used by the other CLM tables. Routine checks are over-provisioned; a scoped “clm-compliance-check” role would shrink blast radius if the identity is compromised.

− granted: role:contract_system_admin
+ needed: Scoped clm-compliance-check role
L3

M&A due-diligence document assembly

  1. TriggerM&A workstream kickoff
  2. Salesforce1Read target’s customer contractsContract: PermissionsRead, PermissionsViewAllRecords
  3. ServiceNow2Read vendor contractsast_contract_instance · role:public
  4. Atlassian3Assemble locked-down data roomConfluenceSpace: write:space.permission:confluence
  5. Atlassian4Per-category pages, restrictedwrite:page:confluence, write:content.restriction:confluence
  6. ParapetTime-boxed; revoked with the space permission at close.Allow, time-boxed
Why Parapet

ViewAllRecords on Contract is the most powerful — and during M&A the most dangerous — grant in the inventory. Parapet time-boxes it, requires the space lock-down to actually be exercised, and revokes both together when diligence closes.

− granted: Standing ViewAllRecords on Contract
+ needed: Diligence-window grant, paired with data-room lock
L4

Contract renewal & obligation tracking

  1. TriggerScheduled scan for contracts nearing expiry
  2. Salesforce1Read expiration datesContract: PermissionsRead
  3. ServiceNow2Cross-reference amendments & entitlementsclm_contract_history, clm_m2m_contract_asset · role:public
  4. Atlassian3Open renewal issuewrite:issue:jira, write:comment:jira
  5. ParapetInherited write scopes stripped; identity split per use case.Deny excess
Why Parapet

The agent only needs read, but discovery finds PermissionsEdit and PermissionsModifyAllRecords on Contract inherited from a shared “Contract-Bot” identity reused by L1, L2 and S3. Only a cross-use-case inventory surfaces that.

− granted: Edit + ModifyAllRecords via shared Contract-Bot
+ needed: Read on the four contract resources
L5

Legal hold & litigation response

  1. TriggerLitigation-hold notice issued
  2. Salesforce1Read every related contractContract: PermissionsRead, PermissionsViewAllRecords
  3. Atlassian2Search correspondenceread:content:confluence, search:confluence · read:issue:jira, search:jira:agent-interface
  4. Atlassian3Lock everything downwrite:content.restriction:confluence, write:permission:jira
  5. ParapetHold propagated as deny across every agent identity.Deny excess
Why Parapet

A hold needs negative enforcement. Parapet propagates a hard deny-list across every other agent identity — HR’s offboarding bot (HR2), Sales’ redline bot (L1) — that would still hold delete:attachment:jira or write:content:confluence on held items.

− granted: Other agents can still edit or delete held items
+ needed: Hard deny-list across all agent identities

See what your agents actually hold.

Discover, inventory and enforce across every connected SaaS system.