Blog

Governing Astra for Law plugins: activate per matter type, limit access and require logging

Astra for Law launches with 26 partner plugins reaching into DMS, time recording and deal systems. Without scoping and logging per matter, an opaque layer appears.

· By

A row of labelled folders on a wooden desk, one lying open with a checklist where a hand with a fountain pen places a tick.
Activate Astra for Law plugins per matter type, limit their access to DMS, time recording and deal systems, and log every call.Image: IamVera.ai — original editorial illustration

Treat each of the 26 Astra for Law plugins as a governance object: decide per matter type which plugins are active, limit their access to DMS, time recording and deal systems, and log every call with model version, data read or written and human approval. Without those choices upfront, research and drafting output stays untraceable across the connected tools.

On 17 September 2026 OpenAI announced Astra for Law: GPT-6 Astra configured for legal work, linked to a legal search index and legal analysis instructions. According to OpenAI's official announcement, the product launches with precisely 26 partner plugins that connect ChatGPT to tools firms already use, including Relativity, Clio, iManage, Intapp, DeepJudge, Thomson Reuters, Harvey and Legora. In our estimation, that is where the real work lies: not in the model, but in the question of which plugins you switch on and how you limit their access.

What exactly did OpenAI launch with Astra for Law and the 26 plugins?

Astra for Law is, according to OpenAI, a vertical configuration of GPT-6 Astra. The announcement mentions a legal search index, instructions for legal analysis and writing, and access via Trusted Access in ChatGPT and Codex, with an API variant under the name gpt-6-astra-law. ExplainX's technical explanation describes the index as a collection of over 230 million sources and, alongside the 26 partner plugins, also counts nine community plugins and 47 skills.

  • Model plus index: GPT-6 Astra linked to a curated legal search index.
  • Access: first via Trusted Access in ChatGPT and Codex, then via the API.
  • Extension: 26 partner plugins that connect to existing legal tools.
  • Repeatable tasks: community plugins and skills that package recurring workflows.

ExplainX stresses that Astra for Law is intended as a foundation layer on which vendors build, not as a stand-alone product. That is precisely why the plugins weigh more heavily than the model itself.

What do those plugins actually do in matter management, time recording and deal comparison?

The 26 plugins are not decorative. LawNext describes concrete examples: the iManage plugin lets a lawyer draft a negotiation letter in ChatGPT and save it straight into the matter file; the Intapp plugin shows activities that still need a time entry; the DeepJudge plugin brings in earlier deals for comparison; and the Thomson Reuters plugin brings HighQ matter context into ChatGPT, with a later link to CoCounsel Legal.

Legal IT Insider points out that the plugins touch both the practice and the business of law. This means Astra output ends up in systems that are financially and disciplinarily sensitive: files, time recording and deal databases. That is the core of the matter the sources leave open. None of the announcements explains how a plugin's access to a specific matter, to the DMS or to time recording is precisely limited, and how the output is systematically verified. That is a choice firms must make themselves, per matter type.

What do the Harvey and Legora tests show about integration into specialist products?

Artificial Lawyer describes early tests of GPT-6 Astra at Harvey and Legora. In Legora, an agent for tying out financial statements carried out a check on 41 documents, found all the planted discrepancies, including a difference of 500,000 pounds, and recorded each check with citations. According to Artificial Lawyer, that specific workflow improved by nearly 40 per cent over the previous model, and by around 3 per cent on average across Legora's BAR benchmark.

What this example illustrates is not that the model is better on its own, but that the gain arises when Astra sits behind the ontology and citator of a specialist product, with the agentic workflow managed within that product. The checks were traceable because Legora recorded them as citations. That same traceability is not an automatic consequence of a plugin; it has to be set up. How you keep the citations and source evidence from such a research tool controllable per matter is something we set out earlier in an analysis on checking citations from an AI research tool such as Legora per matter.

Which governance and verification choices must you record per plugin and per matter?

In our estimation, each Astra plugin becomes a separate policy and verification surface. The sources confirm what the plugins can do; controlling them is up to the organisation itself. That calls for explicit choices along four axes.

  • Access and scoping: which plugins are on per team and per matter, and where a plugin may read or write in the DMS, matter system or time recording.
  • Workflow linkage: which tasks (research, drafting, time recording, deal comparison) run via Astra, and at which point a human check sits.
  • Logging and audit trail: recording per call which data was read or written, which model version was used and which lawyer accepted or rejected a suggestion.
  • Responsibility: how liability is divided between OpenAI, the plugin vendor and the internal team when an Astra-driven step leads to an error.

These four axes tie in with broader control of AI in document workflows; see our piece on controlling AI agents in legal workflows with governance and audit trails and the wider topic hub on AI governance and control per workflow. Without these choices upfront, in our estimation, an additional opaque layer appears on top of already complex systems, rather than demonstrably faster and more accurate workflows.

Which integration patterns suit complex cases and transactions with a high confidentiality level?

For matters with a high confidentiality level, such as complex proceedings, regulatory advice and large transactions, the following patterns are usable. They are our editorial recommendation, not a source requirement.

  1. Research plugins as a proposal generator: use Astra research as a proposal that is mandatorily checked against primary sources before it enters an advice.
  2. Drafting with checkpoints: route Astra drafts via DMS plugins with an intermediate step in which the lawyer confirms changes and annotates the reason. How you demonstrably record that human intermediate step is set out in our piece on demonstrably logging human oversight of AI decisions.
  3. Time and billing via a review queue: let whatever the time plugin proposes pass a lawyer first before it enters financial records.
  4. Deal comparison on delimited datasets: restrict deal plugins to jurisdictionally delimited data collections and record which precedent sets Astra consulted.

The common thread is always the same: every plugin that reads or writes something in a system that matters must be chosen, bounded and logged upfront. Only then does the performance gain that Artificial Lawyer describes at Legora also become a verifiable gain, and not merely a faster black box.

Sources and references

  1. Harvey + Legora on OpenAI's GPT-6 AstraArtificial Lawyer · 2026-09-07
  2. Astra For LawOpenAI · 2026-09-17
  3. OpenAI Releases Astra for Law, A GPT-6 Model Tailored for Legal Work, Targeting Large Firms and Tech VendorsLawNext · 2026-09-17
  4. Breaking news: OpenAI unveils Astra for LawLegal IT Insider · 2026-09-17
  5. OpenAI Astra for Law: What It Is, Who Gets It (2026)ExplainX · 2026-09-18

Sources: The article draws on OpenAI's official Astra for Law announcement and on reporting by Artificial Lawyer, LawNext, Legal IT Insider and ExplainX.

← All articles in this topic ← All articles