Legal agents: 5 use cases
Legal agents need broad read and narrow write. Shared bot identities and deletion rights are where evidence gets lost.
ServiceNowSalesforceHubSpotAtlassian Each step lists the resource and the exact permission or role the agent uses.
Contract intake & redline tracking
- TriggerSales files a request in Legal’s service desk
- Atlassian1Intake request
JsmRequest: read:request:jira-service-management - Salesforce2Read draft
Contract: PermissionsRead - Atlassian3Track redlines
write:issue:jira, write:comment:jira, write:attachment:jira - Atlassian4Return status
write:request.status:jira-service-management - ParapetDelete blocked on contract-review issues.Deny excess
The redline agent needs write:attachment:jira to post drafts but never delete:attachment:jira, which would destroy legal-hold-relevant prior versions. Parapet blocks delete on contract-review issues.
Vendor contract lifecycle management
- TriggerNew ServiceNow ast_contract from Finance onboarding (F4)
- ServiceNow1Read new contract
ast_contract · role:public - ServiceNow2Attach standard clauses
clm_terms_and_conditions, clm_m2m_contract_and_terms · role:public - ServiceNow3Run compliance validation
clm_condition_check · role:contract_system_admin - ServiceNow4Log outcome
clm_contract_history · role:public - ParapetOver-provisioned role flagged; scoped role recommended.Gate / review
clm_condition_check requires contract_system_admin — far above the role:public used by the other CLM tables. Routine checks are over-provisioned; a scoped “clm-compliance-check” role would shrink blast radius if the identity is compromised.
M&A due-diligence document assembly
- TriggerM&A workstream kickoff
- Salesforce1Read target’s customer contracts
Contract: PermissionsRead, PermissionsViewAllRecords - ServiceNow2Read vendor contracts
ast_contract_instance · role:public - Atlassian3Assemble locked-down data room
ConfluenceSpace: write:space.permission:confluence - Atlassian4Per-category pages, restricted
write:page:confluence, write:content.restriction:confluence - ParapetTime-boxed; revoked with the space permission at close.Allow, time-boxed
ViewAllRecords on Contract is the most powerful — and during M&A the most dangerous — grant in the inventory. Parapet time-boxes it, requires the space lock-down to actually be exercised, and revokes both together when diligence closes.
Contract renewal & obligation tracking
- TriggerScheduled scan for contracts nearing expiry
- Salesforce1Read expiration dates
Contract: PermissionsRead - ServiceNow2Cross-reference amendments & entitlements
clm_contract_history, clm_m2m_contract_asset · role:public - Atlassian3Open renewal issue
write:issue:jira, write:comment:jira - ParapetInherited write scopes stripped; identity split per use case.Deny excess
The agent only needs read, but discovery finds PermissionsEdit and PermissionsModifyAllRecords on Contract inherited from a shared “Contract-Bot” identity reused by L1, L2 and S3. Only a cross-use-case inventory surfaces that.
Legal hold & litigation response
- TriggerLitigation-hold notice issued
- Salesforce1Read every related contract
Contract: PermissionsRead, PermissionsViewAllRecords - Atlassian2Search correspondence
read:content:confluence, search:confluence · read:issue:jira, search:jira:agent-interface - Atlassian3Lock everything down
write:content.restriction:confluence, write:permission:jira - ParapetHold propagated as deny across every agent identity.Deny excess
A hold needs negative enforcement. Parapet propagates a hard deny-list across every other agent identity — HR’s offboarding bot (HR2), Sales’ redline bot (L1) — that would still hold delete:attachment:jira or write:content:confluence on held items.
See what your agents actually hold.
Discover, inventory and enforce across every connected SaaS system.