Enterprise DNA

Omni by Enterprise DNA

Enterprise DNA Resources

Thought leadership & research. Practical AI operating-system thinking for owners, operators, and teams doing real work.

220k+

Data professionals

Omni

AI agents and apps

Audit

Map the manual work

Key Findings

OpenAI's Presence tool adds strict data permissions for AI agents. Here's what that means for intake, review, and compliance at your firm.

New OpenAI Permissions Let Law Firms Automate Safely
Insight ai

New OpenAI Permissions Let Law Firms Automate Safely

Sam McKay

Most managing partners I talk to have a version of the same objection to AI. It’s not “does it work.” It’s “what happens when it touches a client file it shouldn’t.”

That objection just got a lot harder to justify. OpenAI’s Presence tool introduces granular permission controls for AI agents, letting a firm define exactly what data an agent can see, what it can act on, and what stays locked behind a human review step. For a law firm, that’s the difference between “we can’t automate intake because of confidentiality” and “we can automate intake because we control the boundary.”

This matters because the actual bottleneck at most firms doing $1M to $25M in revenue has never been ambition. It’s risk tolerance. Partners have wanted to automate intake, triage, and first-pass document review for years. What stopped them was a reasonable fear that an AI tool with broad access to client data was one misconfiguration away from a conflict-of-interest problem or a privilege breach. Presence-style guardrails don’t remove that risk entirely, but they shrink it to something a firm can actually govern, document, and defend to a bar association if asked.

The real cost of doing this manually

Before we get to what changes, it helps to be honest about what the manual version of this work actually costs you.

Attorneys at firms this size lose roughly 4 to 6 hours a week to document review, intake admin, and matter housekeeping that never shows up on an invoice. That’s not a training problem. It’s structural. Someone has to read the contract, log the call, chase the missing exhibit, and none of that is billable no matter how efficient the associate is.

Intake is worse in a different way. Industry ranges we usually see put after-hours and weekend intake conversion somewhere between 30% and 40% below business-hours conversion, and a meaningful chunk of that gap is just speed. A prospective client with an employment dispute or a personal injury claim calls three firms on a Tuesday night. Whoever calls back first, usually within the hour, tends to win the matter. If your intake process routes to voicemail until 9am, you’re not losing on quality. You’re losing on response time.

Document review carries its own math. First-pass review on contracts or discovery batches runs $200 to $400 an hour in associate time, and a lot of that hour is spent on work that’s genuinely mechanical: flagging non-standard clauses, summarizing positions across a document set, checking dates and defined terms against the rest of the file. It’s necessary work. It’s just not work that requires seven years of law school to execute on the first pass.

Add it up across a 15 to 30 attorney firm and you’re typically looking at $80,000 to $250,000 a year in leakage. Not fraud, not waste in the traditional sense. Just hours that should have been billed, matters that should have been won, and review cycles that should have taken a day instead of a week.

Reality check: Firms in the $1M-$25M range typically see $80K-$250K a year in unbilled hours and missed intake, before you even count the discovery-review drag on junior associates.

What Presence-style permissions actually change

Here’s the practical shift. Up to now, giving an AI agent access to your intake pipeline or your document management system meant an all-or-nothing decision. Either the agent could read client files, case notes, and calendar data, or it couldn’t do the job at all. Firms understandably chose “it can’t do the job.”

Granular permissioning breaks that binary. You can now define, at the field and action level, what an agent is allowed to touch. An intake agent might be permitted to read a caller’s stated matter type and check it against your existing client list for conflicts, but not permitted to see settlement figures on unrelated files. A document review agent might be allowed to read and annotate a discovery batch, but any action that would send something outside the firm, like an email or a filing, requires a named human to approve it first.

That’s a meaningfully different conversation with your risk committee or your malpractice carrier than “we’re giving an AI tool general access to our case management system.” It’s also the same logic your firm already applies to junior staff. You don’t hand a first-year associate root access to every client matter on day one. You scope their access to what the job requires. Presence just lets you apply that same discipline to software.

If you want a deeper look at how this plays out across specific workflows, our guides walk through permission scoping in more detail, and the insights section tracks how AI vendors are responding to compliance concerns as they roll out these controls industry-wide.

Where this shows up first, in practice

Three workflows tend to move first once a firm decides the data-access problem is solved.

Intake. An Intake Voice Agent answers every call, including the ones that come in at 9pm or on a Saturday. It runs a conflict check against your existing client list using only the permissions you’ve granted, captures the matter details, and books a consultation straight into the right partner’s calendar. It doesn’t see unrelated case files. It doesn’t have access to billing history. It has exactly the slice of data it needs to do the job, and nothing else. The firm stops losing after-hours leads to whichever competitor happened to pick up the phone first.

Triage. A Matter Triage Agent reviews incoming form submissions and emails as they land, classifies the practice area, scores how well the inquiry fits your firm’s focus, and routes it to the right partner with a one-paragraph brief attached. Instead of a paralegal manually sorting a shared inbox once a day, the routing happens within minutes, and it happens with a documented, permission-scoped audit trail behind it.

Document review. A Document Review Agent runs first-pass review on contracts or discovery batches. It flags non-standard clauses, summarizes positions, and produces a memo written at roughly the level you’d expect from a mid-level associate. A human still signs off before anything goes to a client or a court. The associate’s time shifts from reading every page cold to reviewing a structured summary and checking the agent’s flags against the source. That’s the part of the job that actually needs a law degree.

None of these workflows require giving an AI system the keys to your entire practice management platform. That’s the point. The permission model is what makes the automation defensible, not just efficient.

What it looks like end-to-end

Take the intake example through a full cycle. A prospective client calls at 8:40pm about a wrongful termination matter. The Intake Voice Agent answers on the second ring, confirms the caller isn’t already a client on an adverse matter, and asks the standard qualifying questions your firm has already approved. It logs the call, drafts a short summary, and books a 30-minute consultation for Thursday at 10am directly into the employment law partner’s calendar. By 8am the next morning, the partner has a transcript, a summary, and a calendar invite waiting. Nobody on staff touched the call. Nobody had to check a shared inbox first thing in the morning wondering if a good lead sat overnight.

Now take document review through a similar cycle. A discovery batch of 400 documents comes in on a Friday afternoon. The Document Review Agent processes the batch over the weekend, flags 38 documents with potentially privileged content for human review, summarizes the remaining 362 into a structured memo grouped by relevance, and hands the whole package to the supervising associate Monday morning. What used to take three associates most of a week now takes one associate a day, and that associate is reviewing flagged items and reading a summary, not starting from page one.

This is the shape of the work our Omni platform builds for firms already. The voice agent product handles the intake side, the ops agents handle triage and document work, and the broader Omni platform ties them together with the permission scoping this whole approach depends on.

The audit is the actual next step

None of this is worth doing on faith. Every firm’s data environment, case management system, and risk tolerance is different, and the honest first step isn’t buying software. It’s finding out where your specific leakage actually sits.

That’s what the Omni Audit is for. It’s a 60-minute session, no deck, no sales pitch dressed up as a workshop. We walk through your intake process, your document review workload, and your current systems, and you walk away with three things: a dollar estimate of what your firm is currently leaking in unbilled hours and missed intake, a short list of the two or three workflows where an agent would pay for itself fastest, and a plain-language rundown of what data access each of those agents would actually need. No commitment, no obligation to move forward.

If you want to see how this maps specifically to legal practices before you book anything, the AI audit for law firms walks through the same framework we use in the live session. It’s worth ten minutes if you’re on the fence.

For most firms, the conversation is worth having simply because the numbers are big enough to matter. If your firm is losing $80,000 to $250,000 a year to unbilled hours, slow intake response, and associate time spent on first-pass review, an hour spent finding out exactly where that number comes from is a reasonable use of a Tuesday afternoon. Book a 60-min Omni Audit and we’ll walk through your specific numbers together.

Before you book, get your intake process on paper

If you’re not ready for the audit yet, start smaller. We put together an AI Client Intake Checklist for Law Firms that walks through the specific questions to ask before you automate any part of your intake pipeline, including the data-access questions this article has been circling around. It’s a practical worksheet, not a sales document, and it’s a reasonable starting point if you want to map your current process before you talk to anyone about changing it. You can grab the checklist here and work through it with whoever currently owns intake at your firm.

Where this goes next

Permission controls like the ones OpenAI just shipped with Presence are going to become table stakes across every AI vendor serving regulated industries, not just legal. Firms that wait for a fully mature, zero-risk version of this technology will keep waiting. Firms that move now, with proper scoping and a human still in the loop on anything client-facing, are the ones who’ll have already worked out the kinks by the time it becomes standard practice across the profession.

The math hasn’t changed. Your associates’ time is still worth $200 to $400 an hour and most of that value is wasted on mechanical first-pass work. Your after-hours intake is still converting 30% to 40% worse than it should. The only thing that’s changed is that the compliance objection just got a lot weaker.

If you want a second opinion on whether your firm is a good fit for this before committing to anything, see Omni for law firms or go straight to booking your audit. Either way, you’ll know within an hour whether this is worth pursuing for your firm specifically, and you’ll have real numbers instead of a general sense that “we should probably look into AI at some point.” For more on how firms in adjacent industries are approaching this same problem, our blog covers a handful of recent examples worth reading before your call.