What is MCP for a law firm?
MCP is how a firm brain safely reaches the firm's real tools — Clio, email, files — instead of pasting secrets into a chat window.
Jonathan Mahler
Non-Attorney Partner & COO, Conduit Law
One workflow
Request demo
Bring one recurring bottleneck. If it is a good first firm-brain build, the next step is a live demo — not a pitch deck.
MCP is how a firm brain safely reaches the firm's real tools — Clio, email, files — instead of pasting secrets into a chat window.
Last updated: August 26, 2026
TL;DR
- MCP is a plug. It attaches permissioned tools to a model so the model can read the firm's systems.
- The plain job: a firm brain can look up a matter, a folder, or a thread without someone pasting it.
- Copy-paste chatbots put secrets and client facts into a window. An MCP-connected brain uses a short, approved menu.
- MCP is not a product you buy. It is not a FirmOps SKU. It is how the layer connects.
- The sticker guide for agents, tools, skills, and MCP is AI agents, tools, skills, and MCP.
- Request demo if you want that plug mapped against one job on your stack.
What is MCP, in plain language?
MCP is a plug that lets a model use a short menu of permissioned tools on the firm's real systems, instead of waiting for someone to paste the file into chat. The letters stand for Model Context Protocol. You do not need the protocol spec. You need the job: the brain can ask Clio, email, or the document store a question the way a well-trained staff member would, inside limits you set.
Without a plug, every AI window is a copy-paste machine. Staff copy a matter note, paste it, get a draft, copy the draft back. Client names, claim numbers, medical facts, and sometimes credentials travel through a chat box that was never the system of record. That is slow, sloppy, and a bad habit to teach a firm.
With MCP, the model does not get the keys to the firm. It gets a curated list: look up this matter, read this timeline, find this folder, draft this email into the staff member's own drafts. Read first. Draft second. A person approves anything that leaves. That is the same safety model as the Managed Firm Brain. MCP is the attachment point, not the offer.
Vendors will keep renaming the plug. Claude says MCP. ChatGPT has said plugins, then GPTs, then connectors. Other people say integration. The sticker map — prompt, skill, tool, plug, agent, firm brain — is in AI agents, tools, skills, and MCP mean the same thing. This post is the law-firm version of the plug itself: why a firm wants it, what it must not do, and how it differs from a chatbot.
If you want the staff-window walkthrough, Claude Desktop plus MCP as a company brain is the operator tour. This page stays non-technical on purpose. Owners should be able to read it without an IT committee.
Why does a law firm need a plug instead of a chatbot?
A law firm needs a plug because the useful facts already live in Clio, email, and files, and a chatbot cannot see them unless a person pastes. Pasting does not scale, and it is a poor place to put client data.
Take a normal question: what is stuck on this matter? The answer is usually split. The CMS has the stage and the last note. The folder has the missing record. The inbox has the provider's delay. A chatbot will invent a tidy status if you only paste one of those. An MCP-connected brain can be allowed to look at the approved sources and cite which system it read. That is the difference between a writing toy and an operating layer.
The same is true for drafting support. A letter of representation drafted from a blank prompt is generic. A letter drafted after the brain is allowed to read the matter, the retainer status, and the incident facts in the file is something a case manager can actually review. Follow-up is the same pattern. The plug does not send. It prepares. Humans keep the phones and the send button.
This is also why MCP is not a reason to rip out Clio or Filevine. The CMS stays the system of record. The plug is how the brain reads it and the systems around it. See Clio Work vs Filevine vs a purpose-built firm brain, plus the CMS pages for Clio and Filevine. Intake that should land in Clio still belongs in the CMS path — Clio intake workflow — with the brain reading and staging, not replacing the record.
Buying legal AI software without a plug puts you back in the paste loop. That comparison is legal AI software vs a purpose-built firm brain. A CMS AI feature without a plug is the same loop inside one app: CMS AI vs a firm brain.
How is a copy-paste chatbot different from an MCP-connected brain?
A copy-paste chatbot only knows what someone typed. An MCP-connected brain can call a permissioned menu of tools on the firm's real systems, then wait for a human before anything is sent. That is the whole distinction.
| Copy-paste chatbot | MCP-connected firm brain | |
|---|---|---|
| How it gets the file | Someone copies notes, emails, or PDFs into the window. | Permissioned tools look up the matter, folder, or thread. |
| What it can see | This paste, this session. | Approved systems only: Clio or Filevine, email, docs, and whatever that job is allowed to read. |
| Secrets and credentials | Easy to paste an API key, a password, or a full client file into chat. Bad habit. Hard to audit. | No paste of secrets. The plug is configured. The menu is short. Access is logged. |
| What it can do | Talk. Draft from the paste. Staff copy the output back by hand. | Read, then draft into a review path. A person releases the send, the file, or the publish. |
| Who sets the limits | Whoever is typing, plus the vendor's terms. | The firm, in partnership. Role-aware tools. Approval gates. Phones stay human. |
| Failure mode | Confident answer, wrong file, leaked paste, no audit trail. | Wrong if the menu is too wide, writes are unsupervised, or people treat MCP as a product SKU. |
The plug is only as safe as the menu. A good company-brain connector is not a giant admin key. It is lookup-first, draft-gated, and boring on purpose. The operator version of that menu in a staff window is Claude Desktop plus MCP. Managed AI agents are the jobs that run through that plug under supervision. This still sits under law firm operations, not under a new protocol to shop.
What should an owner ask before anyone "adds MCP"?
Ask which tools it can call, what it can write, and who approves the send. The acronym is not the product. Those three questions are.
Which tools: can it look up a matter in Clio or Filevine? Can it see the document folder? Can it search the mailbox that actually holds follow-up? If the honest answer is “it can chat,” you do not have MCP in any sense that matters to the firm. You have a window.
What it can write: draft-only is the default we take seriously. Emails land in the requesting staff member's drafts. Letters wait for review. The brain does not silently update the CMS, send to a client, or publish. Live client calls stay with people. If a vendor says the agent “just handles it,” that is a no.
Who approves: a named person, a visible approve / reject / retry control, an audit trail. Not a hope that staff will notice. FirmOps builds and runs this as the Managed Firm Brain — custom, in partnership, then operated — rather than handing the firm a protocol to install. MCP is how the brain reaches the stack. It is not something we sell as a line item.
If you want those three questions answered against one job on your stack, Request demo. Bring the system of record and the bottleneck. We will tell you whether a plug on that job is a first build.
Questions owners actually ask
What is MCP for law firms?
A plug that lets a firm brain use permissioned tools on Clio, email, files, and other approved systems, instead of pasting the file into a chat window. Details of the sticker versus agents and skills: AI agents, tools, skills, and MCP.
Is MCP a product FirmOps sells?
No. MCP is a connection method. The offer is the Managed Firm Brain. Do not treat MCP as a SKU.
Is this the same as ChatGPT plugins?
Same job, different sticker. Plugins, connectors, and MCP all attach tools to a model. Ask what it can read, what it can draft, and who releases the send.
Does MCP mean the AI can send email or answer the phone?
No. Drafts wait for a person. Phones stay human. A wide-open plug that can send unsupervised is a design failure, not a feature.
How do I start?
Request demo. One job, one short menu, read-first.
Keep moving up the operating system
Get the Managed Firm Brain Notes
Follow the practical path: live workflow builds, CRM-aware automation when the data is ready, and supervised work after approval.
Demo Context
What to watch for in the Managed Firm Brain walkthrough
Live-Lab Proof
How Conduit informs the first external deployments
Fit Criteria
API-ready systems, workflow scope, and approval gates
About Jonathan Mahler
Jonathan Mahler is the non-attorney partner and COO of Conduit Law and the operator behind FirmOps. He runs the systems of a live PI firm every day, then turns reusable patterns into practical Managed Firm Brain workflows: approved context, supervised drafts, approval gates, and a path into deeper automation when the first workflow proves value.
Related Articles
What is a firm brain?
A firm brain is a purpose-built operating layer for one law firm, implemented in partnership, then run for that firm. Not a chatbot. Not a boxed product.
Legal AI software vs a purpose-built firm brain
Buying legal AI software gives you a tool. A firm brain is a custom implementation built with the firm, then operated for them.
AI Agents, Tools, Skills, and MCP Mean the Same Thing
Vendors keep renaming the same AI stack. A PI-firm COO maps prompts, skills, tools, MCP, plugins, and agents, then points them at one firm brain.
Request demo
Bring one recurring bottleneck and see whether it is a good first firm-brain build. If the first workflow is concrete, the next step is a live build session, not a broad advisory project.
30-minute live demo | One workflow | Human approval before external action