AI Approval Gates for Law Firms: What Stays Human
Firms buy AI and skip the approval layer. A PI firm operator maps the two gates that run in production, who holds each one, and the minimum version to retrofit.
Founder of Conduit Law (non-attorney), COO · Co-Founder, FirmOps
One workflow
Request demo
Bring one recurring bottleneck. If it is a good first firm-brain build, the next step is a live demo — not a pitch deck.
Most firms buy AI and stop at the model. They pick a tool, switch it on, and hope the people using it remember to read the output before it goes anywhere. The part that rarely gets built is the approval layer: who reviews what, in what order, and how anyone proves later that a human signed off.
This is the operator view from inside a working firm, not a bar opinion and not vendor copy. I run the business side of Conduit Law, a Denver personal injury firm operating in four states, and I am not an attorney. Approval gates are the control I care about most, because they decide whether AI is a drafting toy on someone's laptop or an actual part of how the firm runs.
Nothing ships ungated
At Conduit, no AI output reaches a client, a file, or the public on its own authority. So the question is never gated versus ungated. It is which kind of gate.
There are two.
The approval button. The request arrives as a message with a short summary and three choices: approve, reject, or send back for rework. Nothing moves until a person with authority over that decision taps one. Payments. Settlement and stage approvals. New articles. Google Business Profile posts. LinkedIn.
The held draft. The AI writes the email and stops. It sits as a draft. A person reads it, edits it, and sends it. The model never holds the send button.
Both are gates. They ask the human for different things.
The sorting rule is permission or wording
Here is the test a firm can apply to its own workflow list without hiring anyone.
If the action is irreversible or carries authority, it gets the button. Money leaving the firm. A case stage or settlement posture changing. Anything published under the firm's name. In those, the human is not editing prose. The human is granting permission, and permission is the thing you cannot take back after the fact.
If the action is a communication, it gets the held draft. The human is deciding whether the words are right and then owning the send. That is a different job, it belongs to a different moment, and it does not need a formal approval record to be safe. It needs a person reading before dispatch.
One line sits above both. If the output is legal advice, it goes to an attorney approval gate. Not to me. Not to a case manager. The authority required is a lawyer's judgment, so the gate routes to a lawyer. That is not a policy we argue about each time. It is wired into where the request goes.
Prepare and approve are two different jobs
The gate that works is not one person doing everything more carefully. It is a split.
Paralegals enter approval requests. A partner approves them. The person assembling the request and the person holding the authority are never the same person, and the system enforces that rather than trusting anyone to remember it.
Each approval type routes to a single person, chosen by the authority the decision requires. Not a round robin. Not a committee. Not a channel where four people assume one of the others will handle it. One decision type, one owner, every time.
That last part is what most firms get wrong when they try this on their own. They build a review step and then leave the reviewer unnamed, which means the review is really a queue that fills up until somebody clears it in a hurry.
Automation runs on both sides of the decision, never through it
The gate is not a stop sign in the middle of a manual process. It is the only manual moment in an automated one.
Everything upstream of the decision is automatic. The draft is written, the facts are pulled from the file, the summary is composed, the request is routed to the right approver. Everything downstream is automatic too. Once a partner approves, the internal staff confirmations go out on their own. Nobody hand types "approved, go ahead" to three people.
Every action is logged, approved or not. That matters less for catching mistakes than for a simpler reason: an approval that leaves no record is a conversation, and a conversation is not a control.
The design goal is narrow. AI does the work up to the decision and the work after it, and never the decision itself.
What the boxed AI tool leaves out
A firm can buy ChatGPT, Claude, or an AI feature bolted onto its case management system tomorrow. What it still will not have is the layer this article is about, and the reason is not that the models are weak. The models are fine.
Two things are missing.
The first is the wiring. A boxed AI tool sees one system, the one it ships inside. It cannot read the case management system, the inbox, the document store, the accounting system, and the phone system at the same time. A gate cannot route to the right approver if the tool does not know your roles, and it cannot act on an approval if it cannot reach the systems where the work actually lives.
The second is your business logic. Out of the box, every firm gets the same generic assistant, with no saved skills, no encoded rules, and no idea how this firm does anything. So the firm re-explains itself in every prompt, and the rules live in the heads of whoever happens to be typing.
The integrations and the saved firm logic are the product. The approval gate is what sits on top of them. That is the work FirmOps does as a managed layer, and it is the same work described in what a firm brain actually is and in the glossary of agents, tools, skills, and MCP.
The gate is not the friction. A badly built gate is.
Attorneys push back on approval layers because they read as delay. Now I am the bottleneck. Now everything waits on me.
That objection is usually right about the gates they have seen. If approving means opening another system, hunting for context, and reconstructing what is being asked, of course it is a bottleneck. The delay is not the approval. It is the archaeology.
A good gate is self contained. The summary travels with the request. The decision is a tap. Approve, reject, or send back for rework, all three in the same place the request arrived, without leaving the phone.
And the channel is a preference, not the architecture. Telegram is what we use. Slack works. Email works. Asana works. The rule is to deliver the request into the platform the owner already reads all day, because the gate someone has to remember to visit is the gate that gets skipped.
If you are retrofitting, start here
A firm already running AI with no approval infrastructure does not need to rebuild its stack. It needs the smallest layer that actually reduces risk.
Start with the two categories where the firm's name is on the output. All client communications, and all marketing and social output. Every outbound word to a client passes a human first, and nothing gets published under the firm's name without one. In this niche that is not a nice to have. A human voice sits on top of the AI, always.
The minimum viable version is four moves.
- Every client facing AI output lands as a draft, never a send.
- Name one approver per decision type, chosen by the authority that decision needs.
- Log every action from day one, so approval is a record and not a memory.
- Deliver approval requests into the platform your approvers already live in.
None of that requires new case management software. It requires deciding what stays human and then wiring the path so the human is unavoidable rather than optional.
Where the risk actually lives
The failure mode people picture is an AI writing something wrong. That is the easy one, because a person reading the draft catches it.
The real exposure is structural: a workflow with no gate in it, running quietly, because nobody decided who owned that output. A firm cannot audit its way out of that with a log. The log tells you what happened. Only the architecture decides what is possible.
The goal is not a firm where bypassing the gate is discouraged. It is a firm where bypassing the gate is not a route that exists.
Where this fits
Approval gates are the operating half of an AI policy. They sit inside the wider law firm operations work, next to intake, billing, and the rest of the running of the firm. The policy says what the firm allows. The gates are what makes the policy true on a Tuesday afternoon when someone is behind on a demand. If you are writing the document first, start with the law firm AI policy outline, then come back and wire the gates, because a policy no system enforces is a memo.
FirmOps operates this layer for firms as a managed service. The Managed Firm Brain is the wiring and the firm logic. Managed AI Agents is how work gets done on top of it, under supervision. Conduit Law is where it runs in production, and the Conduit case study is the detail.
Bring one workflow you have already pointed AI at, and we will map where the gate belongs, who should hold it, and what it takes to wire it. Book a demo or email hello@firmops.io.
Questions owners actually ask
What is an AI approval gate?
A required human decision between an AI output and the outside world. It comes in two forms: an approve, reject, or rework button for actions that carry authority, and a held draft for communications where a person edits and sends. Both stop the model from acting on its own.
Which AI outputs should a law firm gate first?
Client communications and anything published under the firm's name, including marketing and social posts. Those are the outputs where the firm's voice and reputation are on the line, and they are also the ones partners worry about most, so gating them first buys trust for everything after.
Who should approve AI output at a law firm?
Route by the authority the decision requires. Legal advice goes to an attorney. Money out and case posture changes go to the partner who owns that call. Preparation is a separate job from approval, so the person assembling the request should not be the person approving it.
Do approval gates slow down turnaround?
A well built gate costs seconds. The summary arrives with the request and the decision is a tap in a tool the approver already uses. What slows firms down is an approval that forces the reviewer to open another system and reconstruct the context before deciding.
Can we add approval gates without replacing our case management system?
Yes. Gates sit above the systems you already run. The work is connecting those systems so requests can be routed and acted on, and encoding your firm's rules so the routing knows who holds which authority. Clio, Filevine, or SmartAdvocate stay where they are.
Is an AI policy enough on its own?
A policy states intent. A gate enforces it. Without the wiring, compliance depends on every person remembering the rule while under deadline pressure, which is exactly when the rule gets skipped.
Keep moving up the operating system
Get the Managed Firm Brain Notes
Follow the practical path: live workflow builds, CRM-aware automation when the data is ready, and supervised work after approval.
Demo Context
What to watch for in the Managed Firm Brain walkthrough
Live-Lab Proof
How Conduit informs the first external deployments
Fit Criteria
API-ready systems, workflow scope, and approval gates
About Jonathan Mahler
Jonathan Mahler is the founder of Conduit Law (non-attorney) and COO, and co-founder of FirmOps. He runs the systems of a live PI firm every day, then turns reusable patterns into practical Managed Firm Brain workflows: approved context, supervised drafts, approval gates, and a path into deeper automation when the first workflow proves value. Meet Jon and Elliot.
Related Articles
What is a firm brain?
A firm brain is a purpose-built operating layer for one law firm, implemented in partnership, then run for that firm. Not a chatbot. Not a boxed product.
AI Agents, Tools, Skills, and MCP Mean the Same Thing
Vendors keep renaming the same AI stack. A PI-firm COO maps prompts, skills, tools, MCP, plugins, and agents, then points them at one firm brain.
Live in Claude Cowork or ChatGPT, or get left behind
Staff must live in Claude Cowork or ChatGPT. A legal AI browser app leaves the firm behind. A firm brain (MCP) is how they stay there with the file.
Request demo
Bring one recurring bottleneck and see whether it is a good first firm-brain build. If the first workflow is concrete, the next step is a live build session, not a broad advisory project.
Live demo | Human approval before external action