Skip to content
← All of the product

14 · Where BRON runs

Work where the work already is. Take the gates with you.

A litigator does not live in one tab. The record has to reach the phone on the way to court, the document already open in Word, the inbox where the matter actually arrives, and whatever AI the firm has already bought. The surfaces change; the refusals do not.

BISCAYNE BLUE v. ACME COMPOSITEFIRM AGENT · MCP
Their own AI read the docket and wants the answer date calendared.
01 · READGrounded, dated to the datagrounded
02 · ONE SOURCEUnreadable, so the roll-up is unknownreview
03 · WRITE VERBProposal filed, executed falsereview
04 · TOKENNone minted, none returnedblocked

A person at the firm approves it in BRON. The API cannot.

The question in the room

I draft in Word, the case arrives in my inbox, and I am usually holding a phone. Does any of that reach the record?

How it works

The mechanism, not the promise.

On your phone

  • A native app held to the same action set by test

    Shipped

    The SwiftUI app shares one networking core with the web app, and a parity test reads the server's own tool registry and requires every confirm-gated action to decode through the phone's confirm envelope. There is no phone-side allowlist that could drift from the server.

  • The approval token never rides in the arguments

    The single-use token lives on the pending card and returns only in the confirmation field. The phone returns the arguments it sent, not the server's echoed copy, so the binding matches. A frame with no token, or one planted in the arguments, produces no card.

  • A second check for the acts that leave the firm

    An act that puts anything before somebody outside the firm, or moves money out, asks the device owner for Face ID, Touch ID or the passcode; a time entry does not. A phone with no biometry and no passcode proceeds, and the card says so.

  • Pages hashed before the first write, and a capture that has not landed is still yours

    Every page's raw bytes and the assembled artifact are SHA-256 hashed the instant they arrive, before any write, and wrapped with the device clock, build, attitude and an opted-in location. No string built on it says a document is genuine. A sealed draft survives relaunch.

A phone is read by the room

  • The lock is presentation, and never a sign-out

    Content is obscured the moment the scene stops being active, the frame the app switcher snapshots. Return after the grace window asks for biometry falling back to the passcode, never a BRON PIN. The window caps at sixty seconds; a firm may only shorten it.

  • Where the pixels are actually going

    Screen recording, AirPlay mirroring, a capture cable, a shared meeting window and an external display all put privileged material in front of people the attorney did not choose, and none change how the app looks. A reading that cannot be determined is treated as exposed.

  • The lock screen names nothing

    The client's widget carries no matter, party, document title or figure, only whether anything is needed and where things stand. The deposition record light carries no string at all in its attributes. Past its stale bound the dot goes hollow and the clock is withdrawn.

Inside the document you are already writing

  • The same server core, and no second gate

    Shipped

    The Word taskpane runs the citation gate, the Table of Authorities, authority linking and the pre-file checklist against the same server the in-app drafting page calls, so Word and Chambers cannot disagree. The verdict vocabulary is imported from the module the in-app panel renders.

  • Edits land as tracked changes, with tracking turned on first

    The panel sets the document into track-all before any find and replace, so a suggested edit arrives as a real insertion or deletion to accept in Word's review pane. Nothing is written into a filing as a silent edit, and the count applied is reported.

  • One sign-in gate behind both panels

    A password sign-in where a second factor is verified sits at the lower assurance level the backend rejects, so the panel routes them to the challenge. The session read is bounded. Both panels share that gate and fall back to a browser paste box.

Where the case actually arrives

  • ReadItem, and nothing beyond it

    Shipped

    The Outlook manifest requests the read permission for the item in front of the attorney and does not request mailbox read and write. The panel inspects the message; it has no authority to edit or send mail on anyone's behalf.

  • The block arrives before the send, not after it

    Citations, unfilled placeholders and FRCP 5.2 personal identifiers are checked against the message being composed, using the same outbound checks BRON applies to its own email. An attorney drafting in the inbox sees the block where the decision is made.

  • The cites in what they sent you, checked in the same place

    The panel mounts on a message being read as well as written, so an authority cited at you by opposing counsel meets the same verifier as one you are about to cite. The body comes through the host, and the panel keeps its own session.

Your own AI, reading the record

  • Every read carries provenance, a status and the timestamp of the data

    Shipped

    An answer returns the row ids behind it, an honest statement of how far those rows were checked, and the moment the data was true. Every entity, passage and deadline carries its own ids and status, and the roll-up is its weakest member.

  • Read, empty and unreadable are three different answers

    A collection queried that matched nothing is a checked observation. A collection that could not be read is unknown, and comes back as a null with a null count, not an empty list and zero. An empty result is never offered as proof of absence.

  • The verb that proposes, and the three that cannot reach outside

    Shipped

    Arguments are validated against the firm's tool schema, stripped of any override flag or planted token, written to the approvals ledger and read back. It is capped at the suggest rung and answers executed false. The other three write verbs reach nothing outside the firm.

  • Privilege bound to the key, decided at consent

    Shipped

    A credential is attorney-grade or client-safe, fixed on the key when the attorney consents. The matters chosen at consent are re-proved against what that attorney can reach and written onto the key, so the grant can only narrow. Work-product tools refuse a client-safe key.

  • A grant that names its reach, and a task id that is not a key

    Shipped

    An external agent's grant names its firm, its matters, its capabilities and its expiry, the allowed set derived from the tool registry rather than hand-listed, and a database constraint refuses the consequential verbs. Long-running work reuses the firm's run engine, not a second task store.

Refusals

What it will not do, and why.

Approve its own proposal.
The write verb executes nothing and the executor is not reachable from that code path. No confirmation nonce is minted, injected or returned to the caller. The written row is read back before anything is reported, because reporting pending for a row that was never written would be a fabricated receipt. The nonce is minted later, inside the gate, when a person clicks, bound to the action, the matter, the user and the exact arguments, because an agent holding one would be the person as far as the gate is concerned.
Take the privilege level a caller asks for.
The credential class is per-key governance rather than a request argument. A model is exactly the caller that cannot be trusted to set a privilege flag correctly, so on that surface the key decides and the arguments do not. A document an agent uploads lands with no classification and waits for privilege review, so it cannot read back what it just put in.
Treat a task id as a key to a matter's work product.
Possession of an identifier is not authorization. Every task stores the credential that created it and every read of it rechecks that binding after the query, so a leaked id opens nothing that the key behind it could not already reach.
Report a table it could not read as an empty one.
A matter with no undisputed facts and a fact table that would not answer are opposite statements about the record, and the more dangerous one is the one that looks tidier. The unreadable case is a null rather than an empty list, so it cannot be silently added up.
Average a roll-up.
One ungrounded item among hundreds of grounded ones makes the whole answer ungrounded, with the counts printed beside it. An average would let a large number of sound facts launder a single invented one.
Forward a log line to an outside agent.
Logging is an egress surface. Existing prose logs may carry document text, a client's name, a matter caption or a credential, so none of them are forwarded and none are scrubbed by guesswork. A caller supplies one of a fixed set of event shapes, and an unrecognized field is refused without reflecting its contents back in the error.
Hand a document's bytes to the system share sheet.
Bytes leave the reader through one path that can name the exact version and pass the server's audience gate. A source-text contract test fails on the share and item-provider APIs appearing anywhere in the reader, because the compiler cannot see this class of defect and a local preview URL is one modifier away from being an export.
Put a matter's name on a lock screen.
A lock screen is the most public surface this product touches. The client widget and the deposition record light carry no caption, party, filename or figure at all, so a glance from across the table returns state and nothing else.
Let a filing that died disappear quietly.
A progress strip that simply vanished would read as one that finished. A failed transfer ends on the failure and stays on the lock screen until it is dismissed, saying plainly that nothing was filed and how to get back in. A capture is written as a durable draft the moment its attestation is sealed, before any upload is attempted, removed only on a confirmed acceptance, and resumed at the storage server's acknowledged offset.
Send mail, or read the mailbox.
The Outlook manifest asks for the item being read and does not request mailbox read and write. Least privilege is stated in the manifest itself rather than promised in a panel.

One record

Nothing here stands on its own.

What feeds it

  • The matter record
  • The citation gate
  • The confirm gate and its tokens
  • Classification and the client-visibility rules
  • The scopes and matters on a firm's own credentials

What it feeds

  • The approvals ledger
  • Drafting and the send gate
  • The daily board
  • The audit trail
  • A firm's own agents

Limits

What this does not establish.

  • This page describes the native app as code, not as a listing. Nothing here states how a firm obtains or installs it.
  • A device-owner check proves the person holding the phone unlocked it. It is a second lock on the same door, not evidence of who wrote what was sent.
  • The Office panels check the text the host hands them. A tracked change nobody accepted, and a region the host did not return, are outside what a check can see.
  • Published prompts on the MCP surface are advisory and a client may ignore them. When a firm holds the inference, careful drafting instructions cannot bind another model; access, non-execution and checkability stay mechanical.
  • A grounded read is a custody claim: this sentence came from that document at that page. It is not an independent check of the underlying fact, and no read on that surface reports one today.
  • Moving the whole record out of BRON is a server route today. No screen drives it yet.

Check the work before you believe it.

Run a sample manifest in your own browser, or read where publication refuses for want of evidence.