← Back to list

How Harvey Is Implemented in a Law Firm

From decision to governed operation, in five phases

José Luis Caresani · 2026-07-01 19:14 · 0 claps · 5.7 min read
#eu-ai-act #conversation-intelligence #harvey #legal-ai #legal-technology
Open on Medium ↗
Wiki topics: ⚖️ · Law & Justice

How Harvey Is Implemented in a Law Firm

From decision to governed operation, in five phases

By José Luis Caresani · Senior Solutions Architect, Rational Core LLC

When a firm decides to adopt Harvey, its IT lead’s first question is usually the most practical one: what do I have to install on my servers? The answer is surprising, and worth giving without ambiguity: practically nothing.

But that answer opens a deeper question — the one that actually decides whether the investment pays off. This guide walks through it in five phases, articulating what Harvey documents publicly with the UCIF transformation model, which provides the governance layer transversal to the whole process.

One clarification upfront: Harvey’s technical installation is the easy and fast part. What defines success is the governance and change management around it — and that is where an implementation consultant adds the value that neither the platform nor the firm resolves alone.

Before the phases: what actually gets installed

Harvey is a cloud-native SaaS built on Microsoft Azure. All the heavy compute — the models, the agent orchestration, the retrieval systems, the document processing — lives in Harvey’s infrastructure on Azure, in the region corresponding to the client’s regulatory regime. For a European firm, that region is the EU.

What is NOT installed: there are no model servers, no inference engines, no vector databases, no agent runtime running in the firm’s datacenter. It is an architectural decision, not a limitation.

What DOES happen on the client side is configuration and integration: connecting the identity provider (SSO), linking the existing document management system (iManage, NetDocuments, SharePoint) via connectors and add-ins, installing lightweight client extensions (the Word Add-in, Harvey in iManage), configuring IP allow-listing, and exporting audit logs to the firm’s SIEM. None of this is compute infrastructure — it is integration plumbing and access policy.

A point relevant to governance: Harvey designs its agent runtime with Zero Data Retention. Client data is not written to durable storage by default; the agent uses a transient working disk tied to the sandbox lifecycle, automatically wiped when the task ends. Harvey maintains SOC 2 Type II, ISO 27001 certification and GDPR compliance.

The Phases

The strategic consequence is key: since there is nothing to install on-premises, governance cannot be about servers. It is about what data leaves the firm’s perimeter, where to, with what purpose, with what retention and what traceability.

Phase 1 · Contracting and security

Before touching the platform, the contractual and security framework is defined. For a law firm this is not paperwork — it is the foundation on which professional privilege rests.

  • Signing the DPA and Security Addendum, with terms aligned to SOC 2 Type II, ISO 27001 and GDPR.
  • Configuration annex: documenting the activated privacy toggles — retention, regional residency, and the guarantee that client data is not used to train the base model.
  • Choice of processing region: EU for a European firm.
  • IP allow-listing and incident notification window.

Closing milestone: signed contract with an annex listing which privacy and security controls are active.

Phase 2 · Identity and access

Who enters, with what permissions, and how it is logged.

  • SAML SSO integrated with the firm’s identity provider, plus SCIM provisioning and FIDO2 MFA.
  • Granular RBAC on the least-privilege principle. Set the sharing policy early, because disabling it later can reset existing items to private.
  • Audit logs exported to the firm’s SIEM from day one.

Closing milestone: users authenticated via SSO, role permissions active, access traceability operational.

Phase 3 · Data and sources

Connecting Harvey with the documents and legal sources the firm uses every day.

  • Document ingestion from iManage, NetDocuments, SharePoint.
  • Vault configuration: repositories for bulk review and knowledge bases analysable from the Assistant.
  • Activation of legal sources by jurisdiction — Harvey integrated Spain as a national source in 2025.

Closing milestone: users can send documents to Assistant, Vault, or the workflow agents.

Phase 4 · Agents and workflows

Here Harvey stops being an assistant and starts executing work.

  • Activation of the 500+ pre-built agents, vetted by lawyers, organised by practice area.
  • Workflow Builder: the no-code tool to turn the firm’s templates, standards and review steps into reusable own agents.
  • Client Matter (CM#) for per-matter usage tracking.

Closing milestone: the firm’s first own workflow running on a real matter.

Phase 5 · Adoption, governance and continuous improvement

The longest phase and the one that decides the return on investment. It is not technical — it is change management.

  • Pilot with a single practice group: a high-volume, well-bounded case with a genuinely interested responsible partner.
  • Building internal champions: two or three lawyers per group who become the reference points. Adoption happens lawyer to lawyer.
  • Measuring in lawyer terms, not platform terms: output quality, hours redirected to higher-value work, partner satisfaction.
  • HITL++ capture: every senior-lawyer correction, rejection or reformulation is logged with its rationale, feeding agent refinement and building institutional memory that persists beyond rotating professionals.

Closing milestone: measured adoption and an institutional memory that makes the agents progressively more accurate for that firm.

The questions every firm asks

Beyond the phases, there are questions a managing partner always raises in the second meeting. Answering them honestly — including where Harvey doesn’t reach on its own — is what distinguishes a consultant from a salesperson.

Where do our database, legacy CRM and client history live? They stay where they are. Harvey is not a document manager or a CRM, and the historical archive is not migrated. The master repository remains the firm’s; Harvey accesses it via connectors and only processes what each task requires.

And if our legacy system has no native connector? Harvey exposes its capabilities via the Model Context Protocol (MCP). That opens three paths for the legacy: expose an integration layer (API/MCP), export to a format the Vault ingests, or build a bridging middleware. That work is, literally, implementation consulting.

When we want to leave Harvey, where is the backup? Since Harvey operates with Zero Data Retention, Harvey is not your backup. That is reassuring (your data isn’t held hostage) and demanding (the accumulated knowledge needs a persistence strategy the firm controls). That is why the Case Trace and the HITL++ corpus must live in the firm’s infrastructure, not the vendor’s. This is exit strategy and data sovereignty.

How does a new associate pick up a matter? What they need is not just the documents — it is why what was decided was decided: what case law was discarded and why, what strategy was chosen. That “living matter file” — documents plus reasoning plus human interventions plus strategic rationale — is what the Case Trace captures and no platform delivers by default. It is the difference between inheriting a file and inheriting the judgement.

The transversal layer: UCIF governance

The five phases describe the technical-operational “how”. But there is a layer that runs across all of them and that distinguishes an implementation that survives an audit from one that only works in the demo:

  • Owner Schemas: each data channel declares its legal basis, visibility, retention and authorised purpose.
  • CIP (Purpose-Based Inference Confinement): the system permits inferences within the declared purpose and blocks by design those that fall outside it.
  • Case Trace: each execution documents inputs, plan, steps, sources, output and human interventions. It is the evidentiary basis for AI Act Article 14.
  • AI Governance Authority: the C-level committee constituted from Phase 1, not added after the first incident.

The platform installs in weeks. Governance and adoption are built in months. The implementation consultant is the one who makes the two meet — and is the piece that neither Harvey nor the firm resolves alone.

Resources

José Luis Caresani is an electronic engineer and Senior Solutions Architect at Rational Core LLC. Co-editor of the ITU-T Z410 standard, author of the Unified Conversational Intelligence Framework (UCIF). Independent consultant in Madrid, specialising in conversational governance and AI-First transformation. Guidance document based on Harvey’s public information; the author is not affiliated with Harvey AI.

Contact: joseluis.caresani@rationalcore.com · linkedin.com/in/josé-luis-caresani-127172


메타데이터
post_id
aa0c42fada7a
slug
how-harvey-is-implemented-in-a-law-firm-aa0c42fada7a
url
https://medium.com/@caresanijose/how-harvey-is-implemented-in-a-law-firm-aa0c42fada7a
canonical_url
https://medium.com/@caresanijose/how-harvey-is-implemented-in-a-law-firm-aa0c42fada7a
author_url
https://medium.com/@caresanijose
status
ok
fetched_at
2026-08-01 02:42:01