Skip to content
BRONLitigation.Held together.

Public information

Workflows: capabilities and limits

Product reference. Read the supported work alongside its review requirements and limits.

Last updated September 22, 2026.

Return to workflows

Capabilities

It proposes, you approve

  • A proposal that cannot act

    Planning freezes the accessible matter snapshot and writes a proposal draft. It never approves a plan, stages a run, executes a tool, or produces an external effect.

  • The questions come before the plan

    A pass with no model in it asks about route, scope, audience, evidence handling and where the gates fall, and only where two choices grounded in this matter would change the plan. Your answer is read out of the frozen packet, never the request.

  • A token bound to the exact act

    Approval mints a random token with a ten-minute life, stored only as its hash and bound to the action, the matter, the user and the exact arguments. One conditional update spends it, so concurrent approvals resolve to one winner and a database error fails closed.

  • A card that is a receipt, not a preview

    The confirmation card carries ids, versions, digests and counts. Never document text, never client-facing copy, never a recipient's address.

What you are approving

  • The answer has to be visible in the plan

    Each choice is re-proved against the finished graph under a named proof code: the scope boundary it moved, the question boundary it set, the dependency order fixed. A model is not trusted to remember it applied your answer, so a proposal lacking it fails closed.

  • What it would spend, whom it would contact, whose records it writes

    Three roll-ups, each projected from what a capability declares. An underivable cost reads as not determinable, never zero and never a typical figure; a capability declaring nothing counts unknown in all three. You see the declared recipient scope, not an address in a step's arguments.

  • What this route has cost this firm before

    Low, median and high across your firm's terminal runs of this exact frozen version, naming the ledger column read. One or two runs read as thin evidence, not a forecast. A run the ledger cannot attribute is counted and named, never folded in as free.

  • A missing fact becomes a step, not a footnote

    A second compiler projects the frozen snapshot's gaps into nodes: a bounded research assignment, a question packet to a client or third party, or an attorney verification gate where facts conflict or go stale. A fact that cannot self-certify is a caveat, not a stop.

  • The failure policy is frozen with the plan

    A failed step halts the run and routes to the responsible attorney. Nothing retries, nothing continues past it, cancelling reaches only unstarted steps. The policy is hashed into the plan and re-derived at start, so a capability newly declaring an outside effect refuses to resume.

What a run is allowed to do

  • A floor no policy can lower

    Shipped

    Sixty-eight capabilities stop for a confirmation whatever the settings say. An evaluation can lower a different capability to draft-to-review at most, and the floor is clamped again at the registry so a second path cannot reach beneath it.

  • Six safety sources, and what one unreadable source costs

    Authorization, conflict, exact version, exposure, litigation hold, recipient audience: a drafting step needs five readable, anything leaving the firm all six. A partial source costs a warning, an acknowledgement, the draft or the outside effect, and the receipt is re-proved before every step.

  • One gate stack behind every surface

    Shipped

    The board, the brief and the assistant run the same gate stack rather than three that drift apart.

When it needs you or your client

  • It will not ask your client twice without saying why

    A repeat has to name one of four reasons: the answer conflicts, is stale, is partial, or the entity or matter does not match. That vocabulary is closed, so a repeat with no statable reason is refused. Unproven sufficiency asks; unproven warrant stays quiet.

  • An answer resumes the run; it does not approve anything

    One transaction records the answer and closes the bound wait. An already-approved run then gets a single compare-and-swap drive forward, re-running matter scope, autonomy and the per-step gates; a plan in review stays in review. No answer or question text reaches a log.

  • A document the run wrote stops before the run can finish

    A run that generated documents does not reach completion on its own. It pauses at a review checkpoint naming the generation jobs, and the terminal transition is one transaction that carries a review receipt per document: the version reviewed, who reviewed it, and when.

When something goes wrong

  • A retry has to prove that nothing happened

    Exactly two outcomes make a step retryable, both positive proof of no effect: a stop for confirmation, or a tool refusing before acting. A checkpoint carries five states, and one holding an effect receipt, a changed binding or a stale subject is refused by name.

  • A run that died looks exactly like a run that is waiting

    A plan nobody reviewed and a wait nobody will resolve both reach every surface as silence, and neither expires. One detector raises one item per matter however many runs are stopped, and closes it when the stall clears. It mints no date and sends nothing.

What the firm learns

  • Repetition noticed by route, not by title

    Two matters that ran the same four capabilities in the same order are the same route, whatever each was called, because the identity is a digest of the graph's ordered capability sequence. Promotion into a playbook stays a separate act, and one declined stays declined.

  • One triage brain

    Shipped

    The board, the daily brief and the email read the same triage rather than each ranking the day its own way.

  • Autonomy promoted on evidence, failing closed

    Shipped

    A capability is promoted only by an evaluation run carrying the decision fields, and a missing field fails the gate.

Limits

  • Blocking while a conflict is flagged is a smaller, deliberate list than the confirm list. Logging time already spent is not a binding act; issuing a litigation hold must never be blocked by a flagged conflict.
  • No agent capability has been promoted on evidence, because no evaluation run yet carries the required fields.
  • A cost range is your firm's own prior runs of the same frozen plan, and per-run cost recording began on 2026-09-09. Runs older than that are reported as unattributed rather than as free.
  • Automatic launch is off on every workflow definition. The single route that could turn it on is keyed to one firm and re-proves the eligibility test first, so a run starts because a person started it.

What BRON refuses

  • Treat a detector that crashed as a detector that found nothing.

    The pass that closes stale items runs only when every detector succeeded. A detector that threw contributes no candidates, and absence because it threw means unknown. Missing a cycle of auto-close is free. Missing a deadline is not.

  • Undo a step that already left the firm.

    A sent email was sent and a served production was served. Nothing in this system erases a receipt, an audit row or an artifact to make a step un-happen, so the field that would say a step is reversible is a literal false that cannot hold anything else. What is owed after a failure is a new recorded correction, retraction or notice that a person writes and approves, laid on top of a record that is retained.

  • Read free text as an answer to a question your client was asked.

    The communications log, case notes and extracted document text record no gap they answer, so mapping them onto one is inference. A wrong inference here suppresses the ask and tells counsel a gap is filled, which loses the fact. Waived and dismissed are not answers either: they are a decision to proceed without one.

  • Count an answer recorded under another firm.

    The tenant floor comes first and is absolute. Such an answer is discarded outright, never counted, never cited, and never surfaced even as a reason for a mismatch, because the decision must not disclose that another firm's matter holds anything at all.

  • Re-raise something you dismissed.

    A dismissed item is left alone, and an item a person resolved is left alone. Only an item the system itself auto-closed can reopen.

  • Auto-wipe a proposal to move a calendared date.

    Deadline drift is deliberately outside the set the reconcile pass may close, so one scan that failed to re-derive a date cannot erase the proposal to move it.

  • Let a surface smuggle an override through.

    The action route strips every override flag at the boundary, and when one was present it says so in the confirmation summary rather than dropping it quietly.

  • Let an unaccepted task look like finished work.

    Work handed to a colleague sits assigned, on nobody's board, until they accept. The window is forty-eight hours, shortened so it never runs past the work's own due date, with a floor of one hour so an already-late delegation still gets a real decision; past it with no answer the item is raised again to the owner. A decline returns the work without ever reading as a resolution.

  • Score a signal it could not read as a zero.

    A reusable route is ranked on eleven signals, each recorded as known, absent or unknown. Absent and unreadable sources stay named in the receipt and their weight stays at a neutral prior, so a route is never ranked up by the silence of the evidence against it.

  • Fan a step out over more items than the run can carry.

    A run's budget is fifty steps and the fan-out ceiling is the same fifty, taken from that budget rather than typed beside it. An assertion runs as the module loads and refuses to start if the two ever disagree.

If I approve this, what exactly have I authorized?

Chase a production, gather a missing answer or revisit the evidence behind a draft. Review the proposed steps, approve their scope and follow the work until it returns for a consequential decision.

Inputs

  • The matter record
  • Discovery findings
  • Deadlines and obligations
  • The firm's own prior runs

Outputs

  • Client requests
  • Drafting
  • The daily board
  • Firm playbooks
  • The audit trail