Frontier Tech

What Enterprise-Managed Authorization Means for Law Firms

Jul 20, 2026

A firm can only supervise what it can see. The change worth your attention is not that AI tools got better — it is that, as of June 2026, a firm can finally produce one list of which AI tools reach which client data, and revoke any of them from a single console.

That capability arrived through Enterprise-Managed Authorization, a Model Context Protocol extension marked stable on June 18, 2026. It lets an administrator enable a tool for the whole organization once, scoped to the groups and roles staff already hold, instead of every attorney and paralegal clicking through a separate consent screen per tool.

This piece is about the operational consequences for the people running a firm — intake, billing, staffing, offboarding. It is not guidance on your professional or ethical obligations, which belong with your bar association and your own counsel.

Who should care

This matters most to a firm administrator, managing partner, or operations lead at a practice of roughly 5 to 150 people that already runs single sign-on, already has staff using AI assistants, and cannot currently answer "which tools can reach our matter files?" without asking around. The pain it touches is supervision and offboarding: knowing what was authorized, and making it stop when someone leaves.

Red flags: (1) You do not run an identity provider — this extension inherits your groups, so it is a prerequisite, not an outcome. (2) Your groups are stale or everyone is effectively an admin; central authorization will faithfully propagate that. (3) Your critical system of record is a vertical practice-management suite that has not implemented the extension, in which case your highest-risk connection is the one this does not yet cover.

The problem this addresses is already measurable

The adoption question is settled; the governance question is not. According to 2Civility's summary of Clio's 2025 Legal Trends Report, 79% of legal professionals use AI, and 87% of large-firm professionals and 71% of solo practitioners report using it. 79% of legal professionals use AI in their work. Those tools are connected to something, and until now that connection was granted personally.

The oversight gap is the striking number. According to 2Civility, 53% say their firm has no AI policy or that they are unaware of one, and only 40% of legal professionals use legal-specific AI solutions, down from 58% the prior year. 53% report no AI policy, or are unaware of one. A majority of firms are supervising tool use they have not defined and cannot enumerate.

Meanwhile the identity estate underneath is expanding faster than manual approval can track. According to Okta, average access requests per company rose 1,140% over two years, while centrally managed service accounts grew 650% year over year. Access requests per company rose 1,140% over two years.

Legal AI adoption metricFigure
Legal professionals using AI79%
Large-firm adoption87%
Solo-practitioner adoption71%
Firms with no AI policy or unaware of one53%
Using legal-specific AI tools40%
Planning to increase AI use in 12 months82%

Sources: 2Civility, reporting Clio's 2025 Legal Trends Report.

The risk side is not abstract either. According to Help Net Security's reporting on the 2026 Verizon DBIR, third-party involvement in breaches rose 60% year on year to account for nearly half of all breaches, and just 23% of third-party organizations had fully remediated their MFA issues. Third-party breach involvement rose 60% to nearly half of breaches. Every tool a staff member connects to matter data is a third-party relationship the firm did not record.

What changes in the daily operation

Three workflows change materially.

Onboarding. A new associate or paralegal currently gets a checklist of tools to connect themselves, which means the firm's access posture depends on an individual completing a task correctly. Under central entitlement, group assignment does it — the person inherits the tool set attached to their role at first login.

Offboarding. This is the largest practical gain. Today, revoking a departing employee's AI tool access means finding every tool they personally authorized. Deactivating the identity provider account now withdraws the entitlements with it. Firms that already trigger a departure checklist automatically — the pattern US Tech Automations wires into onboarding and offboarding workflows — can attach the deactivation step to the same trigger rather than maintaining a parallel list of tool consents.

Supervision and audit. Instead of a survey, the firm has a console. Access decisions live in the identity provider admin console with one auditable trail across every connector, per the Model Context Protocol announcement.

Firm workflowBefore central entitlementAfter central entitlement
New-hire tool setup8-15 individual consents1 group assignment
Offboarding checks8-15 separate consoles1 console
Answering "what can reach matter data?"0 authoritative lists1 audit trail
Approval ownerUndefined in most firms1 named administrator

Counts are illustrative of a typical small-firm tool estate, not measured figures; mechanism per Model Context Protocol.

A worked example

Take a 30-attorney firm where, per the adoption rates above, roughly 79% of staff use AI tools — call it 24 people — each having personally authorized around 10 connections, for approximately 240 individual grants nobody has catalogued. When a litigation paralegal transfers to the corporate group, the administrator changes one group membership; the identity provider writes an application.user_membership.add event for each newly entitled server and the previous entitlements lapse with the old group, replacing what used to be a 10-tool manual reauthorization. The arithmetic that matters is the offboarding case: at 240 grants across 24 people, a departure that previously required checking 10 consoles now requires deactivating 1 account. The 240 figure is illustrative arithmetic derived from the 79% adoption rate reported by 2Civility; application.user_membership.add is a documented event type in the Okta system log catalog.

Cost and effort, honestly

The extension itself is a protocol capability, not a product with a price. What it costs a firm is setup attention and, for most, an identity provider subscription they may already hold.

Effort areaWhere the time goesRelative load
Identity provider in placePrerequisiteHigh if absent, 0 if present
Group and role cleanupDeciding who gets whatHighest single cost
Vendor support verificationChecking each core tool1 call per vendor
Ongoing per-hire setupGroup assignment onlyNear 0

Qualitative; no per-firm cost figures are published for this extension.

Note what is absent from that table: a dollar figure. No credible per-firm cost data exists for an extension this new, and inventing one would be worse than leaving the cell qualitative.

The firms that operationalize this first will be the ones that already treat provisioning as a workflow rather than a favor. Where a matter-intake process already routes documents and triggers downstream steps — the pattern US Tech Automations builds for document-heavy legal operations — attaching group entitlement to the same trigger is a configuration change, not a new system.

The staffing question

Firm administrators keep asking whether this creates a job or removes one. In practice it moves work rather than eliminating it, and the direction of the move is toward fewer, better-documented decisions.

The recurring per-hire and per-departure work shrinks toward zero, because entitlement follows group membership. What replaces it is a smaller amount of periodic work: reviewing which groups map to which tools, and re-checking when a vendor adds or changes support. For most firms under 150 people, that is a quarterly review, not a role.

There is a second-order effect worth naming. Once entitlement is centralized, the approval decision becomes visible — and someone has to own it. According to Okta, 91% of organizations already use AI agents while only 10% have a well-developed strategy to manage them, and just 32% secure AI agents with the same rigor applied to human employees. Only 32% secure AI agents as rigorously as human employees. Central entitlement does not close that gap on its own; it just makes the gap legible enough to assign.

Staffing dimensionPer-user consent modelCentral entitlement model
Setup touches per new hire8-151
Consoles checked per departure8-151
Recurring governance reviews0 per year4 per year
Named approval owners0 in most firms1

Illustrative of a typical small-firm tool estate; governance figures per Okta.

This is also where the workflow layer earns its place. A quarterly entitlement review is exactly the kind of recurring, evidence-producing task that decays when it lives in someone's calendar — the firms that operationalize this first tend to attach it to the same scheduled review steps US Tech Automations already runs against matter and billing data, so the artifact gets produced whether or not anyone remembers.

Signal vs Speculation

What is sourced fact (as of June 2026): the extension is stable as of June 18, 2026; it works by exchanging an identity-provider-issued ID-JAG for an access token; Okta is the first supported identity provider; and the adoption and breach figures cited above come from the linked reports.

Our read: the binding constraint for law firms was never the technology, it was the absence of an artifact. A firm asked "which AI tools touch client data?" had no way to produce an answer that was not a survey. Central entitlement produces a list. We expect that list — not efficiency — to be what drives adoption in legal, because it is the thing clients and insurers ask for.

Our read: if 53% of firms genuinely lack an AI policy, the sequencing risk is real. Central authorization makes it fast to grant broad access, and a firm that adopts it before deciding which roles should reach which matter data will simply encode the current sprawl more durably. We would expect the firms that benefit most to spend more time on group definition than on the technical rollout.

Our read: over 12 to 36 months, we think the vertical gap closes last. The initial server list is weighted toward knowledge-work and developer tools, so practice-management and document-management systems — where the most sensitive matter data actually lives — are likely to lag. Firms should plan for a period where their general-purpose tools are centrally governed and their most sensitive one is not.

Our read: the extension does not supervise agent behavior, only connection. Any firm treating this as a complete answer to AI oversight will find the gap the first time an agent does something permitted-but-wrong inside a system it was legitimately connected to.

Key Takeaways

  • Enterprise-Managed Authorization lets a firm enable AI tools once, centrally, scoped to existing groups and roles, rather than per person per tool.

  • The clearest operational win is offboarding: deactivating one identity provider account withdraws the entitlements instead of hunting through individual consents.

  • Adoption is already near-universal in legal while policy is not, with 79% using AI and 53% reporting no policy or unaware of one.

  • The prerequisite is a working identity provider with accurate groups; without that, central authorization propagates existing access problems.

  • It governs connection and audit, not what an agent does once connected — per-action supervision remains separate.

Frequently Asked Questions

Does this tell us whether our AI use is ethically compliant?

No. This is an access-control capability that shows which tools are authorized and by whom; it makes supervision possible but makes no determination about professional responsibility. Questions about your obligations belong with your bar association and your own counsel.

Our firm has 12 people. Is this relevant at that size?

Yes, though the prerequisite matters more than the size. Small firms carry the same client-confidentiality expectations and are less likely to have a documented tool inventory — but the extension only works if you run an identity provider with meaningful groups.

Will our practice management system support it?

Possibly not yet. The initial server-side list skews toward knowledge-work and developer tools rather than vertical legal systems, so ask your practice-management and document-management vendors directly rather than assuming coverage.

How is this different from just turning on single sign-on?

Single sign-on authenticates the person; this extension authorizes the tool connection on the organization's behalf. It rides on the single sign-on you already run, using the identity provider to issue a grant the tool accepts without prompting the individual.

Can it stop an AI tool from touching a specific matter?

Not by itself. Scoping happens at the group and role level, so it controls which tools a person's role can reach — matter-level restrictions and limits on what an agent may do inside a system require separate controls.

What should we do before adopting it?

Inventory first. List which AI assistants staff use, what systems those assistants reach, and whose account granted the access. Firms consistently find at least one connection nobody knew existed, and that list is what tells you whether central entitlement is replacing something or just formalizing it.

Where this leaves a firm operation

The honest summary is narrow but genuine: this does not make AI safer to use, and it does not answer any question about professional responsibility. It gives a firm the record it needs to supervise tool access at all — one list, one console, one revocation path.

For firms mapping how entitlements attach to the document and intake workflows already running, our legal document extraction workflows show where connection and approval steps sit in practice.

Related reading: client onboarding automation for personal injury practices, helpdesk software choices for law firms, and how legal teams recover lost billable hours.

About the Author

Garrett Mullins
Garrett Mullins
Workflow Specialist

Helping businesses leverage automation for operational efficiency.

See how AI agents fit your team

US Tech Automations builds and runs the AI agents that handle this work end to end, so your team doesn't have to.

View pricing & plans