11 · Chambers
Ask the matter a question. Work in what comes back.
Ask about the calendar and the calendar opens beside the thread. Ask about risk and the risk board does. Ask for a workflow and a proposal you can edit arrives. Chambers answers in the working surface rather than in prose, and one gate stack sits behind every one of them.
Nothing left the firm. What it drafts is work product for your review.
The question in the room
“I have forty minutes before a call. What moved on this matter, and what actually needs me rather than my paralegal?”
How it works
The mechanism, not the promise.
One surface, many answers
The conversation is the room; the second pane is earned
At rest the cockpit is an editorial brief over the conversation: a serif greeting, one co-counsel sentence carrying urgency without a wall of alarm chips. Valuation, the calendar, discovery, billing and the case map summon beside the chat; closing the last returns the resting pane.
Twenty surface kinds, and a renderer for each or the build fails
The artifact registry is a typed switch over twenty kinds: sixteen have a panel renderer, and the rest render through the same component their standalone route uses, so the two cannot show different things. The default branch is an exhaustiveness check rather than a placeholder.
A summon is keyed to the matter and the surface, not to the click
The identifier for an open surface is derived from the matter, the kind and the view as a name-based UUID, in one module shared by the launcher's click and the assistant's own capability. An already-open calendar dedupes and refreshes instead of spawning a second copy.
It renders the thing, not a description of it
Every action opens the surface that shows what it changed
When an action succeeds, the matter surface it touched opens beside the chat and re-pulls if already up. A capability is mapped only where that renderer displays its result: a reply to opposing counsel is unmapped, because the thread surface renders the client portal conversation.
A deliverable needs a door, or a written reason it has none
A capability whose workflow contract is a durable artifact must name the surface rendering it. A census fails on any naming neither a surface nor a written exemption, or on one under forty characters. The ten name identities a blind matter pane could not carry.
The document beside the chat has one pen and a version fence
The co-edit surface has one author at a time, arbitrated by a server lock, not merge. Taking over grabs the lock; every change is fenced by a monotonic version. Handing back persists a tracked-change draft and nothing else: no send, no signature, no phase change.
One valuation, one research console, one ledger
Three of these panes were once separate implementations, which is how the cockpit listed a matter's expenses while its billing page showed none. Each now renders the same component in an embedded variant, so the panel and the matter tab cannot disagree about the number.
A cited brief you can click into without leaving it
The linked-authorities memo renders in the split-pane reader the standalone brief route and the document surface also use, so the three cannot drift. A citation click opens the cited case or record on the right at the pincite; its own tab is the secondary move.
What it may do without asking
A conversation cannot do what a button could not
ShippedSending, signing, moving trust money and changing a matter's phase stop for a confirmation whatever the autonomy settings say, and an evaluation may lower a different capability to draft-to-review at most. The floor is clamped again at the registry.
The same stack behind the chat and behind the button
ShippedAn action taken from a warm panel runs the same role check, conflict block, single-use token, idempotency and audit chain the chat path runs; the surface route adds owner scope and a token re-bind and reimplements nothing.
The approval token is minted for you and never shown to the model
A gated capability refuses to act until a server-minted, single-use token bound to the exact action, matter, user and arguments comes back. The token routes to the interface only, and your approve click re-runs the action with it injected server-side.
A batch approval moves the friction, not the gate
Nine approvals once cost eighteen clicks across nine contexts. The review sends ids only: the first pass executes nothing gated and returns each item's summary, structured proof and a fresh token. Every item renders an unticked box; the second pass confirms only what is ticked.
Chambers proposes a run; it does not start one
The two capabilities that launch a run are removed from this surface, held by two contract tests. Staging happens on its own route, and the thread learns through a persisted event carrying identity alone, so the row survives a reload and reaches the phone.
It audits its own claim of having acted
A reply that says it sent, calendared or filed something is checked against the exact ledger of capability calls that turn. An action waiting behind the confirm gate is not a performed action. The check is advisory, silent when clean and when it fails itself.
What it says when it cannot read the record
The all-clear is the last thing it is allowed to say
The resting pulse carries three states per input, and the sentence saying nothing is pressing is reachable only once both reads have succeeded. A failed deadline read is unavailable, never an empty list, and a rejected contradiction read keeps the last verified cards.
Refreshing a board re-reads it; re-scanning re-runs it
The detectors fire on a schedule and on ingest, so a board can show a verdict formed before the thing the attorney just did. The re-scan control runs a fresh matter-scoped pass and re-reads the board after it returns. A scan that failed says so.
An attorney's call, a model's proposal and an unknown source stay three things
Review rows label responsiveness and coding by where the value came from, and missing provenance reads unknown, not reviewed. A total from a bounded page walk prints as at least that many. A section nobody could read is a stated gap, not empty.
Finding anything
The keyboard front door, and the room list behind it
One shortcut fuses a free-form ask, fuzzy matter search and navigation; a second summons the cockpit with your scope and no question. The destinations derive from the one route index the rail and launcher use, after a hand-synced copy re-diverged: six routes double-keyed, badges dropped.
A standing brief with a floor under the model
Each matter keeps one authored narrative and a ranked agenda. The deterministic composition always runs, and the model polish falls back to it on any failure, with the author recorded. Agenda items derive live from the task ledger at compose time, never copied into storage.
Where a row lands is written down, not built at the call site
A finding resolves to its destination through one table naming the surface and the subject key. Precedence is explicit: a safe app-relative link, the canonical destination, a client mirror for an older server, a recorded platform gap, the matter door. The phone mirrors that table.
Refusals
What it will not do, and why.
- Let a step table stand in for a plan.
- A deterministic gate with no model in it reads the answer rather than the request: a step axis plus an owner, deliverable or timing column, plus an offer to begin, while the turn's ledger shows no proposal was created, means the reply is impersonating the proposal surface. A phrasing detector always has a tail, and the tail once shipped a clipped step table and an offer to start with no snapshot, no plan version and no run behind it.
- Take a confirmation from the model.
- A confirmed flag the model can set could be planted by injection in an ingested document and satisfied by the model itself, with the attorney never in the loop. Retrieved text is delimited and treated as data throughout, and a confirmation counts only when it is a server-minted token bound to the exact act and returned by a human click the model can neither read nor forge.
- Prepare a deadline approval for someone who cannot calendar one.
- Calendaring a litigation deadline is legal judgment, so the chat seam is bound to the same licensed-attorney floor as the dedicated routes, and the check runs before a card is minted. A paralegal with write access to the matter never receives an approval prompt for an act they are not permitted to take.
- Open a surface that would not show what just happened.
- A capability opens a room only where that renderer verifiably displays its result. Pulling up a coding grid that never shows action items would read as a failure of the work rather than of the mapping, so those capabilities open nothing and their reply states the outcome instead.
- Put your client's question in the address bar.
- A question typed into the palette would reach server access logs, referrer headers and browser history as a query string. It travels in a read-once envelope with a sixty-second life instead, and the opaque matter id is the single thing that rides the URL.
- Fold the approval token into the arguments.
- The token lives only in the pending confirmation and returns only in its own field. A confirm is re-carded only on a clean requires-confirmation response from the server, never on an ambiguous transport failure, so a flaky network cannot turn one approval into several executions.
- Invent a date to make the greeting feel urgent.
- Where no dated deadline exists the resting sentence omits the time phrase, and an undated agenda item carries no date phrase at all. A litigation deadline runs from a real trigger event that an attorney confirms, so a date counted from today is worse than no date.
- Print a board count that disagrees with the list beneath it.
- The denominator comes from the one triage pass that produced the rows, over a read that throws rather than truncating. Pairing it with a differently filtered, display-capped query joins two populations, and a board of eleven rows once announced two hundred and seventy items.
- Swallow a failed write because the write was allowed to fail.
- The database client returns an error rather than throwing, so a bare await inside a try block made its catch dead code. A dropped surface kind then survived three migrations unnoticed, one board could not persist a session at all, and nothing anywhere said a word. Persisting a summoned tab is still allowed to fail; failing quietly is not.
One record
Nothing here stands on its own.
What feeds it
- The matter record and its citations
- The proactive task ledger
- Deadlines, discovery, trust and the client thread
- The firm's workflow library
- Whichever surface you were standing on
What it feeds
- Every matter surface it summons
- The approvals queue
- Workflow proposals
- Drafting and the citation gate
- The audit trail
Limits
What this does not establish.
- What Chambers drafts, proposes or summarizes is attorney work product subject to your review. BRON is software, not a law firm, and nothing it produces is legal advice.
- A board that failed to refresh keeps the rows it last verified and labels that section unavailable, so what is on screen may be older than this minute.
- The rolling history window that folds older turns into a running summary is off by default. Until it passes a transcript replay, a long thread is sent in full each turn.
- Draft-ahead, which pre-stages an obvious next step as a reviewable draft, is off by default and inert without its flag.
- Three surface kinds still render and persist but are no longer offered in the summon menu: two are opened by workflow capabilities, and one is kept so that a session saved before the menu changed rehydrates rather than failing on reload.
Check the work before you believe it.
Run a sample manifest in your own browser, or read where publication refuses for want of evidence.