For Florida law firms
Firm workstation review · OCP · redline · cite-check (Opus 5)
firm lane · Generative, gated — the model output is the paid, role-gated work product
Current availability
ShippedConfigured and enabled: firm staff only; the direct tenant refuses (HTTP 410).
- Where it lives
- /admin/workspace · /admin/matter/[id]/review
- What unlocks it
- an active firm matter grant ($299 per trust, estate or power-of-attorney matter; $149 per probate matter) or the workstation AI plan
Status is evaluated against this deployment's configuration by the capability-status service at build time; the catalogue's facts were last reviewed on the date shown.
Capabilities
- ShippedReview, redline, cite-check and the Opposing Counsel Pass™ over pasted or attached text, on the included engine, with the citation panel on every result and the dual consensus mode when two engines are configured.
- ShippedEvery run records its input manifest and hash; every export is a working copy with the footer line; the decision workstation turns a redline into accepted, rejected or rewritten changes and a tracked-changes Word file.
- ShippedThe desk assistant (Ask) answers about the matter and the attached files with a receipt naming the spans it saw.
Limits
- Work product for a licensed attorney's own review — never legal advice to a client and never a substitute for the attorney's judgment.
- Opus 5 by default through the governed gateway (audit row per call, spend brake, the operative-text cage); the direct consumer tenant has no door to it.
- Nothing here files, signs, sends or approves anything; every consequential act is recorded as a firm decision by a person.
- 400,000 characters per document, 6,000 characters of engine context, ten attachments of 10 MB each (200,000 characters of text per attachment — the clip is disclosed).
- Statute citations are verified against the source-locked Florida corpus; case citations against CourtListener for existence only — treatment (KeyCite, Shepard's) is dormant.
What EstateDraftFL refuses
| Reason code | HTTP | What it means |
|---|---|---|
| forbidden | 403 | The session is not firm staff (or a platform admin); every workspace door answers this before reading any input. |
| matter-required | 402 | A paid matter must be selected; a platform admin may run unbilled platform work without one. |
| payment-required | 402 | This exact matter carries no active grant or plan for the operation (the picker names the activation page). |
| matter-not-found | 404 | The matter is not readable in the caller's tenant context (RLS decides; a cross-tenant id reads back nothing). |
| workstation-ai-locked | 402 | The lane grant found no workstation AI access for the matter (membership or per-matter plan). |
| surcharge-not-priced | 422 | The maximum tier is staged until the owner sets its per-document price; the option renders disabled. |
| engine-not-configured | 503 | The engine's governed key is not configured on this deployment; the option renders disabled, never simulated. |
| document-required | 400 | A run needs document text (pasted or attached). |
| revised-document-required | 400 | A redline needs both versions. |
| invalid-manifest | 400 | The attachment manifest must be up to ten {name, sha256, chars, includedChars, truncated} rows. |
| input-too-large | 413 | A document exceeds the 400,000-character request envelope — split it. |
| input-over-lane-cap | 413 | The input exceeds the selected engine's token allowance (chars ÷ 3, conservatively) — split it or choose the larger-capacity lane. |
| rate-limited | 429 | Too many AI runs in the window; the reply names the wait. |
| engine-error | 502 | The engine failed mid-run; nothing was delivered and nothing was charged. |
| unavailable | 503 | The governed gateway is unavailable (spend brake, provider outage); honest 503, never a degraded answer. |
| unsupported | 415 | Only .pdf, .docx, .txt and .md attach. |
| invalid-file | 422 | The bytes fail the shared upload policy: name/content mismatch, structure, empty, oversized, or binary under a text name. |
| unsafe-file | 422 | The armed scanner reported the file; it is not read. |
| scanner-unavailable | 503 | The armed scanner could not be reached; retry later, nothing kept. |
| scan-required | 503 | SCAN_REQUIRED is set and no scanner is configured — fail closed, the file is not read. |
| unreadable | 422 | No text layer, an encrypted or damaged file, or the parser exceeded its time budget. |
| too-large | 413 | Attachments up to 10 MB. |
Evidence
- src/lib/workspace/workspace-gates.test.ts
- src/lib/consumer-ai.test.ts
- e2e/workspace.spec.ts
- docs/NUCLEAR-WORKSPACE-EDFL-PLAN.md
- docs/security/MASTER-PLAN-PHASE1-2026-09-24.md
Last reviewed 2026-09-24