Nishi FamilyCompare › Sovereign Legal Practice: Documents, E-Sign and Client Portal

Nishi Compare · measured, not asserted

Sovereign Legal Practice: Documents, E-Sign and Client Portal

Nishi vs the field — every Nishi cell is measured against real organ source at emit time; each gap names the watch contract that will close it.

Nishi vs DocuSign, Clio, NetDocuments and PandaDoc -- the Utah practice stack from open-a-Word-file to edited, merged, signed, tracked and client-visible, with the law-clerk desk (templates, staleness, court forms) as first-class rows

Layer 1 · Executive

Where we are. Measured 2026-08-18 against source, not recalled. The practice spine already runs as gated organs (matter and conflicts, trust IOLTA, billing, docketing, document assembly, e-sign envelope and consent ceremony, completion certificate, new-matter intake) and the office suite reads and writes Word (.docx) natively, writes tracked revisions and comments, versions every save append-only, shares by ReBAC and serves diffs. The client vault and mail portal are LIVE on the firm's own subdomains (admin.andelinwest.com, mail.andelinwest.com). What is NOT there is the connective tissue the firm asked for: no way to bring an existing Word or Google document INTO the browser editor, no firm-scoped office on the firm domain, no signing from a document version, the client portal handler built but unpromoted on loopback, no tracked-revision rendering, no field placement or signer links, no PDF writer, no identity-verification, RON or e-filing connector. Two of the field's four rivals ship all of that today; the sovereign stack has the harder halves (fail-closed assembly, hash-chained audit, legal-validity predicates, never-void wills, append-only history) and is missing the easy halves. Landed the same evening (2026-08-18): mail merge and ODT promoted and registered (LP2), and the clerk desk -- template registry with version CID and effective epoch, document lineage at assembly, and the staleness worklist -- live and gated 13 of 13 (LP6, LP7, LP8), so a revised clause now names every template and every client document built from the old text. Landed 2026-08-19: LP1 import and LP4 sign-from-version shipped in ONE health-checked deploy of nx_office_daemon (now fork-per-request, so the per-request mmap scratch of the office core is reclaimed by construction, and ONE binary serves N realm-bound instances for LP3) -- a genuine Microsoft Word document imported live on nishifamily.com/office with its original kept byte for byte and 67 spec lines, refused 403 without the consent box, sealed certificate with two chained signers; nx_office_import_sign_gate 28 of 28 GREEN live; nx_odt grew the spec verb so .odt uploads import. Measured cost at the same time: the sign's durable store commit took longer than the 15 s edge window twice at box load 22 (the artifact landed both times) where the profiled quiet-box figure is 129 ms -- the box's fsync latency, recorded as such, not the ceremony.

Where we need to go. Version 0.1 is the firm's sentence made true on the firm's own host: open a Word, Google-exported or ODF document in the browser, edit it as a new version, merge it against the matter record, sign it under a consent-gated ceremony, and see the work trail; this page on /compare is the roadmap and the firm's site carries only the firm's deliverables. Version 1.0 adds the client portal on the firm domain and the law-clerk desk: template registry, document lineage and template staleness, tracked revisions rendered, signer fields and links, co-editing wired, Word MERGEFIELD templates honoured. Version 2.0 is beyond DocuSign for a Utah practice: a sovereign PDF writer with PAdES-shaped signed output, a signer identity ladder up to government ID, a Utah 46-1-3.6 remote-notarization record, bulk send, the NDA-gated e-filing connector, court-forms staleness, and clause-grounded cite-or-abstain contract review measured against the Vals redlining bar.

The unit. 1 u = one measured session-leg. Calibration: the office and legal suite shipped one lib+cli+gate organ per leg on 2026-07-19 (nine organs over two days), the refs rung took about seven domains per seat-leg on 2026-08-18, and the compare migration on this page (54 rows, 30 refs, this plan) took one leg on 2026-08-18. Estimates recalibrate as each rung lands.
Cost to open, edit, merge and sign on the firm's host (0.1): 3.5 u. Through milestone L0. All four rungs landed (LP2 2026-08-18; LP1, LP3 and LP4 2026-08-19): the firm office instance is live at admin.andelinwest.com/office in closed mode over the andelinwest_docportal realm, with nx_office_closed_gate 16 of 16 GREEN re-run after the deploy. Milestone L0 is DONE.
Cost to the client portal plus the clerk desk (1.0): 15 u. Through milestone L1 cumulative (11.5 u of new work over L0). Template staleness is 2 u of the 11.5 and is the single most differentiating rung on the board -- no rival documents it -- which is why the ranker will place it early once L0 lands.
Cost to beyond DocuSign for a Utah practice (2.0): 30 u. Everything below. The PDF writer (3 u) and the e-filing connector (3 u, NDA-gated by the courts) are the long poles; RON needs a commissioned notary and an approved provider posture, which the plan records honestly as a sovereign record around a notary rather than a notary network.

Research bar. Vals Legal AI Report -- redlining is measured on AI legal assistants against a lawyer baseline on redlining, extraction, Q and A, summarization. Theirs: lawyers 79.7 percent, Harvey Assistant 59.4, Vincent AI 53.6 on redlining; Harvey 94.8 on document Q and A. Ours: our 'Contract review grounded on the clause library' watch: designed as clause-grounded cite-or-abstain because free-form AI redlining is measured below the lawyer.

Research bar. Stanford RegLab hallucination study is measured on share of legal research answers citing unsupported law in leading RAG products. Theirs: 17 percent and over 33 percent for two leading products. Ours: our /compare/legal cite-or-abstain lane and this page's AI review watch.

Research bar. Utah RON statute 46-1-3.6 (effective 2026-05-06) is measured on what a lawful remote notarization must record and satisfy. Theirs: Utah-located notary, sight-and-sound A/V, ID image, stored recording, personal-appearance satisfied. Ours: the ron_session watch's done-rule fields.

Research bar. Utah e-filing integration is measured on whether a filer may build its own connector. Theirs: yes under NDA, then an eFiling Integration Guide describing the API. Ours: the efl_submit watch's named unblock.

Research bar. NIST SP 800-63A-4 (final July 2025) is measured on identity proofing evidence strength, document validation, presentation-attack detection. Theirs: IAL1 to IAL3, FAIR/STRONG/SUPERIOR evidence, PAD required for remote biometrics. Ours: the government-ID leg of the sc_signer_idv watch.

42 of 56 capabilities measured|9 of them measured exceeds|14 open|coverage 750/1000|adoption 37 full / 5 partial

Layer 2 · Roadmap

Do this next — computed by the ranker, never chosen by a seat

Order from nx_compare_rank (nx_dr_ocm: (deficit + cost-of-delay + option + enables) x sponsor x self-sufficiency x momentum / cost). FINISH rows are rungs whose symbol is present but whose organ is short of full adoption: the cheapest closures on this board, listed before any new work. Stamp: # asof=1787883541 domain=legalpractice target_version=1.0 rungs=21 done=7 open=14 finish=1 ranker=nx_dr_ocm

#StageRungPriorityDerivation
FFINISHPromote and register nx_mailmerge and nx_odt (source-only today) (LP2) mm_merge_oneREGISTERED-DARKcallable, authorised, no MCP invocation on record (a direct fork logs the runner, so this is not proof it never ran); no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked)
#11.0Tracked revisions and comments rendered in the browser view (LP11) dx_html_track4800v=12 m=2 c=5
#21.0Signature, initial, date and text fields, per-signer secure links, signing UI (LP10) sf_place1600v=16 m=2 c=20
#31.0Word MERGEFIELD field codes honoured (LP13) mm_mergefield1600v=8 m=2 c=10
#41.0Client portal daemon promoted, realm-bound and served on the firm domain (LP9) lpd_serve_realm800v=6 m=2 c=15
#51.0Structure-preserving Word round-trip (LP12) dx_patch_para100v=1 m=1 c=10
#61.0Co-editing wired into the office (LP14) of_coedit0v=0 m=2 c=10
#7laterSigner identity verification ladder (LP16) sc_signer_idv750v=15 m=1 c=20
#8laterBulk send: merged documents become N envelopes (LP18) nx_env_bulk600v=6 m=1 c=10
#9laterSovereign PDF writer and PAdES-shaped signed PDF export (LP15) pdf_sign_pades400v=6 m=2 c=30
#10laterCourt forms refresh and staleness watch (LP20) forms_refresh400v=2 m=2 c=10
#11laterContract review grounded on the clause library with cite-or-abstain (LP21) cl_review400v=4 m=2 c=20
#12laterUtah remote online notarization session record (LP17) ron_session250v=5 m=1 c=20
#13laterUtah e-filing connector (LP19) efl_submit100v=3 m=1 c=30
#14laterDefined-terms and cross-reference consistency proofing (LP22) pf_defined_terms100v=1 m=1 c=10

Critical path — contract, done-rule, executor, cost

RungCloses withDefinition of done (pre-declared)ExecutorEst.
Import a Word, Google-exported or ODF document into the office as a versioned document (LP1)of_importPOST /import accepts a .docx or .odt upload, extracts text via docx_read_text or odt_read_text into a spec that lands as v1, and keeps the ORIGINAL bytes beside it so /file returns the untouched original until the first edit; gate: upload then /file round-trips byte-identical, an oversize or non-package upload is refused with a reasonOrgan1 u
Promote and register nx_mailmerge and nx_odt (source-only today) (LP2)mm_merge_one/api/build, /api/promote and /api/tools/register for both organs; nx_mailmerge_gate 7 of 7 and nx_odt_gate re-run from the PROMOTED binaries, not from a scratch build; nx_catalog shows PROMOTED plus REGISTERED for bothDeploy0.5 u
Firm office instance on the firm domain with the client realm (LP3)
after LP1
od_sessionnx_office_daemon accepts the andelinwest_docportal session as its handle and refuses unauthenticated saves; proxy row admin.andelinwest.com /office; documents owned by firm handles, ReBAC-gated; gate: unauthenticated GET of an owned document is refused, an authenticated save claims ownership; the shared open-mode office namespace is never exposedDeploy1 u
Sign a document version from the office (LP4)
after LP1
of_sign_versionPOST /sign runs nx_sign_ceremony over the version's CID with the consent gate and stores the certificate CID beside the version; gate: no-consent is refused, the certificate CID reproduces from the record, and the version's manifest row names the certificateOrgan1 u

Milestones

MilestoneRungsCumulative
L0 · Open, edit, merge and sign on the firm's hostLP1,LP2,LP3,LP43.5 u
RungCloses withDefinition of done (pre-declared)ExecutorEst.
Template registry: list, version and effective date (LP6)
after LP2
dg_tmpl_listTemplates listed from the registry index with a version id and effective date per put; gate: two puts of one template id list as two versions with the newest currentOrgan0.5 u
Document lineage recorded at assembly time (LP7)
after LP6
dg_assemble_lineagedg_assemble writes a lineage record beside the document CID naming the template CID and every clause CID it merged; gate: the lineage of a re-assembled document is byte-identical to the first, and a document assembled after a clause revision names the new clause CIDOrgan0.5 u
Template and document staleness for the clerk desk (LP8)
after LP7
dg_tmpl_staleGiven a clause revision, name every template that references it and every generated document whose lineage carries the old clause CID; gate plants one revision and asserts the exact stale set (templates and documents) plus a fresh control template that stays fresh; output is a worklist, never a countOrgan2 u
Client portal daemon promoted, realm-bound and served on the firm domain (LP9)
after LP4
lpd_serve_realmnx_legal_portal_daemon promoted with file-backed per-tenant stores, bound to the andelinwest_docportal realm and proxied at portal.andelinwest.com with HTML views over lp_handle; gate: envelopes, status, checklist and document fetch answer over the edge, a cross-tenant document id is 404, a wet-signature Will is surfaced not offeredDeploy1.5 u
Signature, initial, date and text fields, per-signer secure links, signing UI (LP10)
after LP4
sf_placeFields placed on the document through the annotation overlay (AN_SIGFIELD), each signer receives a single-use link bound to the envelope and routing order, and the signing page runs the consent ceremony; gate: a link used out of order is refused, a completed field set completes the envelopeOrgan2 u
Tracked revisions and comments rendered in the browser view (LP11)
after LP1
dx_html_trackdx_to_html renders w:ins as insertions, w:del as strike-through and comments as anchored notes; gate: the docx_html gate gains three teeth (ins, del, comment) and a neg-control that a clean document renders noneOrgan1 u
Structure-preserving Word round-trip (LP12)
after LP11
dx_patch_paraAn edited paragraph is patched in place inside document.xml; every other byte of the package is identical; gate: nx_contentdiff over the two packages shows exactly the edited runs changed and Word opens the resultOrgan2 u
Word MERGEFIELD field codes honoured (LP13)
after LP2
mm_mergefieldfldSimple and complex field runs resolved against the data table so a lawyer's existing Word merge template works unchanged; gate: a Word-authored template with split placeholder runs merges correctlyOrgan1 u
Co-editing wired into the office (LP14)
after LP3
of_coeditnx_office_serve imports nx_coedit and two browsers converge on one document version; gate: the coedit live gate runs against the office routeOrgan1 u
L1 · Client portal on the firm domain and the law-clerk deskLP6,LP7,LP8,LP9,LP10,LP11,LP12,LP13,LP1415 u
RungCloses withDefinition of done (pre-declared)ExecutorEst.
Sovereign PDF writer and PAdES-shaped signed PDF export (LP15)
after LP4
pdf_sign_padesA PDF writer that emits the signed document with an embedded signature and validation data in the PAdES baseline shape over ISO 32000-2; gate: a third-party reader opens and validates the structure, a tampered byte fails validationOrgan3 u
Signer identity verification ladder (LP16)
after LP10
sc_signer_idvEmail OTP, then SMS, then knowledge-based, then government-ID document validation as declared levels recorded in the audit chain; gate: each level's evidence is present in the chain and a signature at a level below the envelope's requirement is refusedOrgan2 u
Utah remote online notarization session record (LP17)
after LP16
ron_sessionA record composing the notary's Utah location, the A/V session, the identification image reference and the recording reference per 46-1-3.6, sealed into the audit chain; gate: a session missing any statutory element is refusedOrgan2 u
Bulk send: merged documents become N envelopes (LP18)
after LP13
nx_env_bulkOne action turns a mail-merge output set into N envelopes with per-recipient routing; gate: N documents give N envelopes and one refused document refuses only its own envelopeOrgan1 u
Utah e-filing connector (LP19)efl_submitSubmission through the courts' eFiling API under the courts' non-disclosure agreement, composing efl_status_pure for filing-date and timeliness; gate: a rejected submission never reads as filed and a late one is named lateOrgan3 u
Court forms refresh and staleness watch (LP20)
after LP8
forms_refreshUtah courts forms re-fetched on a beat, hash-compared, each changed form named; gate: a planted change is named and an unchanged control is notOrgan1 u
Contract review grounded on the clause library with cite-or-abstain (LP21)
after LP8
cl_reviewEvery proposed edit is traceable to a governed clause or the reviewer abstains; gate: a review over a document with no matching clause abstains, and the Vals redlining protocol is re-run with our row published beside the lawyer baselineOrgan2 u
Defined-terms and cross-reference consistency proofing (LP22)
after LP11
pf_defined_termsEvery capitalised defined term defined once and used consistently, every cross-reference resolves; gate: a planted undefined term and a dangling reference are named, clean prose yields noneOrgan1 u
L2 · Beyond DocuSign for a Utah practiceLP15,LP16,LP17,LP18,LP19,LP20,LP21,LP2230 u
Layer 3 · Engineering
How this is scored. Every Nishi mark is measured: the generator reads the real organ source on disk and requires the implementing symbol to exist (no self-grading). A watching tag names the organ and symbol contracted to close a gap — the mark flips itself on the next compare beat when that workstream ships, and the comparewatch- plane row flips with it. The flip is necessary, not sufficient: it proves the symbol exists, never that the capability is good. The bar is the rung's pre-declared done-rule, proven by its gate — a symbol shipped without the behaviour behind it is a defect, and the flip is exactly what makes that defect visible instead of quiet. Competitor marks record documented capability presence — presence, not depth or scale. Adoption is measured too: every measured row carries where its organ stands on the estate's ladder (source → built → promoted → registered → invoked; libraries by importer reach minus validation importers; gates by the execution surfaces that run them). A row is fully adopted only at the top of its ladder; anything short is tagged partial with the exact remedy, so a build nobody promoted can no longer read as shipped. Census stamps: importers asof 1787849099, gate census asof 1787855507 (unix seconds; -1 = census absent).

Capability matrix — measured against source

leads / measured exceed present partial absent · click any capability for its evidence

CapabilityNishiDocuSignClioNetDocumentsPandaDoc
OPEN
Word .docx read -- own OPC/ZIP reader, text runs extractedMeasured: docx_read_text exists in runtime/_hdl_build/nx_docx.nx, verified at emit. docx_read_part unzips STORED and DEFLATE parts of the OOXML package [ecma-376] and docx_read_text extracts the w:t runs; text-level today (no structural DOM) with a 1 MiB read cap declared in source. Every rival opens Word uploads; Clio Draft converts existing Word files into reusable templates [clio-draft] Adoption: RUN-BY:fork:nx_doc_view_gate — fully adopted (top of its ladder).
Word .docx rendered in the browserMeasured: dx_to_html exists in runtime/_hdl_build/nx_docx.nx, verified at emit. Headings, bold and italic runs, tables and a download link, zero JS, registered as the docx viewer in doc_viewers.conf. Lists, images, named styles and tracked-change marks are the named next rung (dx_html_track below) Adoption: RUN-BY:fork:nx_doc_view_gate — fully adopted (top of its ladder).
OpenDocument .odt read and writeMeasured: odt_read_text exists in runtime/_hdl_build/nx_odt.nx, verified at emit. Open format both ways so there is no lock-in [odf-1-3]; PROMOTED and registered 2026-08-18 (LP2), and on 2026-08-19 a spec verb (content.xml to H and P lines, inner spans stripped, entities decoded) lets .odt uploads import into the office -- behaveprobe live-vs-staged proved the verb before promote. Rivals graded Part because the mirrored product pages document Word and PDF intake and do not document ODT -- re-grade when a vendor page is banked Adoption: REGISTERED-DARK — PARTIAL: callable, authorised, no MCP invocation on record (a direct fork logs the runner, so this is not proof it never ran); no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked); only referenced by unpromoted-source -- a mention, not a run.
adoption REGISTERED-DARK
Google Docs and any Word file brought in by upload -- an import route into the versioned officeMeasured: of_import exists in runtime/nx_office_serve.nx, verified at emit. LANDED 2026-08-19 (LP1): POST /import takes a multipart .docx or .odt (Google Docs exports both natively), keeps the ORIGINAL bytes as v1 and serves them untouched at /original and /file until the first edit, extracts the spec through the format organ's spec verb and renders the preview; refusals name themselves (409 duplicate name, 415 not a package, 413 larger than the named request ceiling, 400 no file part). Live receipt: a genuine Microsoft Word document (25 parts, headers, footnotes, 48849 bytes) imported on nishifamily.com/office, original byte-identical (sha 10b848ad), 67 spec lines; nx_office_import_sign_gate 28 of 28 GREEN Adoption: LIB-WIRED importers=5 nonval=2 — fully adopted (top of its ladder).
Paragraph-faithful Word extraction -- headings, paragraphs and table rows kept as structure, not a run soupMeasured: docx_read_spec exists in runtime/_hdl_build/nx_docx.nx, verified at emit. docx_read_text joins every w:t run with a newline (a bold word shreds its paragraph into three lines); docx_read_spec keeps paragraph boundaries, maps Heading and Title styles to H, table rows to T with cells, everything else to P, decodes entities and keeps UTF-8 punctuation intact -- the spec verb the import consumes. Every rival opens Word files; this row is the extraction fidelity of the import Adoption: RUN-BY:fork:nx_doc_view_gate — fully adopted (top of its ladder).
PDF text extraction and reflow viewMeasured: pf_to_html exists in runtime/_hdl_build/nx_pdf.nx, verified at emit. Reader only (forks nx_pdf_text); there is no sovereign PDF writer -- see the signed-PDF row under SIGN Adoption: RUN-BY:actlog — fully adopted (top of its ladder).
EDIT
In-browser editor with append-only versions -- every save a new version, restore and diff servedMeasured exceed: of_save in runtime/nx_office_serve.nx, verified at emit. Exceed with the why: the manifest is append-only, restore writes a NEW version rather than rewinding, and the diff of any two versions is a served page -- history cannot be rewritten or deleted. NetDocuments and PandaDoc keep version history inside the vendor store where it is a mutable feature; Clio Draft hands editing to Word (Part) Adoption: LIB-WIRED importers=5 nonval=2 — fully adopted (top of its ladder).
Inline run formatting and images inside a paragraph in the editorOpen — watching runtime/nx_office_serve.nx : of_inline_runs, re-measured on every compare beat. Ship that symbol and this mark flips itself; the comparewatch- plane row flips with it. The editor is a spec-model veneer (H B I P T blocks) over contenteditable; nx_docx already writes runs, tables and PNG drawings (dx_emit_drawing), the UI does not yet expose them
watching of_inline_runs
Structure-preserving Word round-trip -- edit one paragraph, every untouched XML byte identicalOpen — watching runtime/_hdl_build/nx_docx.nx : dx_patch_para, re-measured on every compare beat. Ship that symbol and this mark flips itself; the comparewatch- plane row flips with it. The beyond-Google-Docs contract: runs are patched in place inside document.xml so styles, numbering, headers and sectPr survive untouched, provable by nx_contentdiff over the two packages; converters re-serialise the whole document and e-sign vendors flatten to PDF. No rival documents in-place round-trip fidelity
watching dx_patch_para
Tracked revisions written as w:ins and w:delMeasured: dx_emit_track exists in runtime/_hdl_build/nx_docx.nx, verified at emit. Real revisions Word accepts or rejects, deletions as w:delText [ecma-376]; write side only today. DocuSign is PDF-centric (0), Clio Draft hands the file to Word (Part), NetDocuments edits through Word (Yes), PandaDoc offers in-editor suggestions rather than OOXML revisions (Part) Adoption: RUN-BY:fork:nx_doc_view_gate — fully adopted (top of its ladder).
Tracked revisions and comments rendered in the browser viewOpen — watching runtime/_hdl_build/nx_docx.nx : dx_html_track, re-measured on every compare beat. Ship that symbol and this mark flips itself; the comparewatch- plane row flips with it. The read side of the row above: dx_to_html gains w:ins, w:del and comments so a redlined draft is reviewable without Word (LP11)
watching dx_html_track
Comments anchored in the .docxMeasured: dx_cm_add exists in runtime/_hdl_build/nx_docx.nx, verified at emit. commentRangeStart and End plus commentReference anchored by lookahead [ecma-376]; write side only today, threads live in the overlay row below Adoption: RUN-BY:fork:nx_doc_view_gate — fully adopted (top of its ladder).
Format-agnostic annotation overlay -- notes, threads, redlines, checklists and signature-field placement, frozen once the envelope completesMeasured exceed: nx_ann_add in runtime/nx_doc_annotate.nx, verified at emit. Exceed with the why: the overlay anchors to document, version and page and never parses the file; redlines are additive (a rejected redline is retained, the count never shrinks); required checklist items gate send; and the whole overlay is IMMUTABLE once the envelope is COMPLETED -- proven both by the frozen-flag contract and by driving a real envelope to completed and asserting the add is refused. Rival comments live inside the vendor editor and stay editable after signature (Part) Adoption: LIB-WIRED importers=8 nonval=3 — fully adopted (top of its ladder).
Real-time co-editing -- RGA text CRDT with convergence proven for two concurrent clientsMeasured: cd_live_sync exists in runtime/_hdl_build/nx_coedit.nx, verified at emit. Built and gated, NOT yet imported by the office (of_coedit is the rung, LP14); NetDocuments co-authors through Word and PandaDoc collaborates in its editor Adoption: BUILT-UNPROMOTED — PARTIAL: compiled, never promoted to the serving root: /api/promote it.
adoption BUILT-UNPROMOTED
Proofing -- rule-based grammar checks and a corpus-derived spell checkMeasured: pf_check exists in runtime/_hdl_build/nx_proof.nx, verified at emit. Doubled words, double spaces, sentence starts and ends, unbalanced quotes and brackets; spell check precision-first from our own corpus (a lexicon gap costs a missed typo, never a false accusation) Adoption: BUILT-UNPROMOTED — PARTIAL: compiled, never promoted to the serving root: /api/promote it.
adoption BUILT-UNPROMOTED
Defined-terms and cross-reference consistency (the Litera class of proofing)Open — watching runtime/_hdl_build/nx_proof.nx : pf_defined_terms, re-measured on every compare beat. Ship that symbol and this mark flips itself; the comparewatch- plane row flips with it. Uncontested by these four; contract-drafting suites sell it separately. Every capitalised defined term must be defined once and used consistently, every cross-reference must resolve (LP22)
watching pf_defined_terms
ASSEMBLE
Clause library and templates as data on the immutable plane, fail-closed mergeMeasured exceed: dg_assemble in runtime/nx_docgen_lib.nx, verified at emit. Exceed with the why: an unknown clause or an unfilled field REFUSES the whole document (never a silent blank in a contract) and the result is a deterministic content-addressed CID reproduced byte-identically across machines (live receipt cid=nxc1-1f96692d). Rivals: DocuSign Document Generation [docusign-docgen], Clio Draft templates [clio-draft], NetDocuments document automation [netdocs-docauto], PandaDoc templates [pandadoc-templates] Adoption: LIB-WIRED importers=5 nonval=4 — fully adopted (top of its ladder).
Field merge from the matter recordMeasured: dg_merge exists in runtime/nx_docgen_lib.nx, verified at emit. Fields resolve from the canonical matter record; a field left unmerged is a refusal, not a warning (dg_unmerged) Adoption: LIB-WIRED importers=5 nonval=4 — fully adopted (top of its ladder).
Mail merge -- one Word template times a data table gives N .docx filesMeasured: mm_merge_one exists in runtime/_hdl_build/nx_mailmerge.nx, verified at emit. Composes docx_read_part and docx_write_document_xml; placeholders are double-brace fields and must sit inside ONE run (a Word-authored template that splits a placeholder across runs will not merge); PROMOTED and registered 2026-08-18 (LP2). Word's own field codes are the next row [ms-word-mailmerge] Adoption: REGISTERED-DARK — PARTIAL: callable, authorised, no MCP invocation on record (a direct fork logs the runner, so this is not proof it never ran); no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked).
adoption REGISTERED-DARK
Word MERGEFIELD field codes honoured, so a lawyer's existing merge template works unchangedOpen — watching runtime/_hdl_build/nx_mailmerge.nx : mm_mergefield, re-measured on every compare beat. Ship that symbol and this mark flips itself; the comparewatch- plane row flips with it. fldSimple and complex field runs resolved against the data table [ecma-376] [ms-word-mailmerge] (LP13); PandaDoc maps fields in its own editor (Part)
watching mm_mergefield
Bulk send -- merged documents become N envelopes in one actionOpen — watching runtime/nx_doc_envelope.nx : nx_env_bulk, re-measured on every compare beat. Ship that symbol and this mark flips itself; the comparewatch- plane row flips with it. DocuSign bulk-sends envelopes to multiple signers [docusign-esign]; PandaDoc bulk send [pandadoc-esign]; Clio Draft populates whole document sets but sends per matter (Part) (LP18)
watching nx_env_bulk
Template registry -- list, version and effective date as first-class dataMeasured: dg_tmpl_list exists in runtime/nx_tmplstale_lib.nx, verified at emit. LANDED 2026-08-18 (LP6): ts_tmpl_put snapshots the clause CIDs at put time with an effective epoch, and dg_tmpl_list reads every template as id, version CID of its clause list, and epoch; nx_tmplstale_gate 13 of 13 GREEN, live receipt templates=2 Adoption: LIB-WIRED importers=2 nonval=1 — fully adopted (top of its ladder).
CLERK
Document lineage -- every generated document records the template CID and each clause CID it was built fromMeasured: dg_assemble_lineage exists in runtime/nx_tmplstale_lib.nx, verified at emit. LANDED 2026-08-18 (LP7): dg_assemble_lineage assembles through dg_assemble and writes lineage:<docid> = template id, document CID and every clause CID merged; uncontested -- the vendor pages describe template libraries and versioning, not the downstream lineage of the documents produced from them Adoption: LIB-WIRED importers=2 nonval=1 — fully adopted (top of its ladder).
Template staleness -- a revised clause names every stale template and every client document built from the old textMeasured exceed: dg_tmpl_stale in runtime/nx_tmplstale_lib.nx, verified at emit. LANDED 2026-08-18 (LP8), exceed with the why: dg_tmpl_stale compares every snapshot and lineage clause CID against the clause's CURRENT text and prints a WORKLIST (TEMPLATE-STALE and DOC-STALE rows naming template, document, clause, old and new CID), never a count; a worklist that would not fit REFUSES rather than truncating. nx_tmplstale_gate 13 of 13 GREEN with the fresh control (nda, M-002) silent and the detector bite-proven; live receipt stale-before=0 stale-after=2. No rival page documents downstream staleness Adoption: LIB-WIRED importers=2 nonval=1 — fully adopted (top of its ladder).
Clause and template governance history -- every put is a new version on the append-only seg-storeMeasured: dg_clause_put exists in runtime/nx_docgen_lib.nx, verified at emit. Add or revise a clause = a data change on the immutable plane; who changed what and when is history by construction Adoption: LIB-WIRED importers=5 nonval=4 — fully adopted (top of its ladder).
Court forms refresh and staleness watch -- Utah forms re-fetched and hash-compared on a beatOpen — watching runtime/nx_forms_refresh.nx : forms_refresh, re-measured on every compare beat. Ship that symbol and this mark flips itself; the comparewatch- plane row flips with it. Clio Draft ships always-current fillable court forms for all 50 states [clio-draft] (Best); ours composes nx_research_fetch and nx_filehash over the Utah courts forms index and names each changed form (LP20)
watching forms_refresh
SIGN
Tamper-evident hash-chained signature audit -- each event chained by sha256 over the previous head and the canonical eventMeasured exceed: se_chain in runtime/nx_sign_envelope_lib.nx, verified at emit. Exceed with the why: every audit event is canonicalised, content-addressed and chained on the sovereign plane, so a holder of the head verifies the whole history without trusting a vendor (tamper at any position is DETECTED, cross-machine determinism proven); DocuSign and PandaDoc keep the certificate and audit trail on their service [docusign-esign] [pandadoc-esign]; Clio Draft collects e-signatures inside Clio (Part); NetDocuments signs through integrations (Part) Adoption: LIB-WIRED importers=3 nonval=2 — fully adopted (top of its ladder).
UETA and ESIGN consent-gated ceremony -- no recorded consent, no signatureMeasured: sc_sign exists in runtime/nx_sign_ceremony_lib.nx, verified at emit. Intent to sign and consent to transact electronically are required fields of the ceremony [utah-ueta-201] [esign-15usc7001]; a signature without them is refused (live receipt no-consent-sign=REFUSED, consent=UETA-OK) Adoption: LIB-WIRED importers=4 nonval=3 — fully adopted (top of its ladder).
Legal-validity verdict per signature -- ESIGN four elements, consumer-consent overlay, eIDAS tier SES/AES/QESMeasured exceed: es_ready in runtime/nx_esign_lib.nx, verified at emit. Exceed with the why: readiness is a computed fail-closed predicate (elements AND tier AND audit completeness) graded per signature, not a compliance sentence on a product page; the consumer overlay is ESIGN 7001(c) [esign-15usc7001]. DocuSign and PandaDoc offer AES and QES through partners (Part) Adoption: LIB-WIRED importers=6 nonval=1 — fully adopted (top of its ladder).
Sealed completion certificate -- CID over envelope, document, signers and audit headMeasured: sc_cert exists in runtime/nx_sign_ceremony_lib.nx, verified at emit. Reproducible from the record itself (live cert_cid=nxc1-d3587e48); rival certificates are vendor-issued PDFs Adoption: LIB-WIRED importers=4 nonval=3 — fully adopted (top of its ladder).
Sign any office document version in place -- consent-gated ceremony, per-version hash-chained log, sealed certificate served as the receiptMeasured: of_sign_version exists in runtime/nx_office_serve.nx, verified at emit. LANDED 2026-08-19 (LP4): the Sign cell on every version row runs sc_sign over that version's document CID (refused 403 without the UETA and ESIGN consent box -- bite-proven, no certificate is written), chains each signer into v<N>/sign.log under v<N>/sign.head, seals the certificate (CID over envelope, document, signers and audit head) into the version and the immutable sign store, and /cert serves the receipt. Live receipt on the imported Word document: two chained signers, audit head advanced, certificate binds the document CID. Field placement, per-signer links and the signing page are LP10, where DocuSign and PandaDoc are Best. Measured UX constraint: at box load 22 the sign's durable store commit exceeded the 15 s edge window twice while the artifact landed both times, against a quiet-box profile of 129 ms for the same commit -- the box's fsync latency under load, not the ceremony; re-checked 2026-08-19 at load 14.6, where a same-class durable write again exceeded the edge window Adoption: LIB-WIRED importers=5 nonval=2 — fully adopted (top of its ladder).
Envelope routing -- ordered signers, CC and approver roles, decline, void, out-of-order refusedMeasured: nx_env_send exists in runtime/nx_doc_envelope.nx, verified at emit. Track-D core gated 7 of 7 with negative controls: a signer ahead of routing order is refused, a tampered seal cannot complete, decline is terminal and additive Adoption: LIB-WIRED importers=9 nonval=3 — fully adopted (top of its ladder).
Never-void instrument gate -- a Will routed for e-signature outside an e-wills posture is refused at send and at sealMeasured exceed: nx_legal_regime in runtime/nx_legal_compliance.nx, verified at emit. Exceed with the why: ESIGN 7003 and Utah UETA 46-4-103 carve wills out of e-signature law [esign-7003]; Utah recognises electronic wills only under 75-2-1405 (readable as text, signed by the testator, two witnesses in physical or electronic presence) [utah-ewill-1405]; the classifier keys the regime by document type and posture, so the void execution cannot be produced while a compliant e-will still routes. No rival refuses to route a will Adoption: LIB-WIRED importers=13 nonval=5 — fully adopted (top of its ladder).
Signature, initial, date and text fields placed on the document, per-signer secure links, signing UIOpen — watching runtime/nx_doc_annotate.nx : sf_place, re-measured on every compare beat. Ship that symbol and this mark flips itself; the comparewatch- plane row flips with it. AN_SIGFIELD already exists in the overlay; the placement UI and per-signer links are the rung (LP10); DocuSign and PandaDoc are the reference here
watching sf_place
Signer identity verification ladder -- email OTP, SMS, knowledge-based, government ID with document validationOpen — watching runtime/nx_sign_ceremony_lib.nx : sc_signer_idv, re-measured on every compare beat. Ship that symbol and this mark flips itself; the comparewatch- plane row flips with it. DocuSign Identify is the reference [docusign-idv]; the bar for the government-ID leg is NIST SP 800-63A-4 evidence validation and presentation-attack detection [nist-800-63a-4] (LP16)
watching sc_signer_idv
Remote online notarization -- Utah 46-1-3.6 session record with A/V recording and identity evidenceOpen — watching runtime/nx_ron.nx : ron_session, re-measured on every compare beat. Ship that symbol and this mark flips itself; the comparewatch- plane row flips with it. Utah RON (effective 2026-05-06) requires a Utah-located remote notary, sight-and-sound A/V, an ID image and a stored recording [utah-ron-46-1-3-6] through a provider that prints tamper-evident certifications [utah-r623-100-9]; PandaDoc is on the Lieutenant Governor's approved vendor list [utah-ron-vendors] while DocuSign Notary [docusign-notary] is not listed there (Part). Ours is the sovereign record and audit around a commissioned notary, not a notary network (LP17)
watching ron_session
Signed PDF output with an embedded PAdES signature and long-term validation dataOpen — watching runtime/nx_pdf_write.nx : pdf_sign_pades, re-measured on every compare beat. Ship that symbol and this mark flips itself; the comparewatch- plane row flips with it. There is no sovereign PDF writer today (readers only) -- named honestly; PAdES baseline levels B, T, LT and LTA over ISO 32000-2 are the target (LP15)
watching pdf_sign_pades
Utah e-filing connector -- submit through the courts' NDA-gated eFiling APIOpen — watching runtime/nx_efile_lib.nx : efl_submit, re-measured on every compare beat. Ship that symbol and this mark flips itself; the comparewatch- plane row flips with it. The filing-date, timeliness and relation-back logic exists (efl_status_pure); the connector needs the courts' non-disclosure agreement and eFiling Integration Guide, which the courts provide to filers building their own interface [utah-efiling] (LP19); Clio integrates e-filing through partners in some states (Part)
watching efl_submit
TRACK
Matter spine plus RPC 1.7 and 1.9 conflicts checkMeasured: mt_conflict exists in runtime/nx_matter_lib.nx, verified at emit. Cross-matter adverse-party check by construction on the immutable plane [aba-rule-1-7]; Clio graded Part because its conflict search sits inside case and contact management and the mirrored features page [clio-features] does not name it; NetDocuments is matter-centric with conflicts through integrations (Part) Adoption: LIB-WIRED importers=35 nonval=28 — fully adopted (top of its ladder).
Matter-scoped DMS -- privilege and work-product tags, privilege log, Bates numberingMeasured: box_matter_scan exists in runtime/nx_box_lib.nx, verified at emit. NetDocuments is the legal DMS reference [netdocuments] (Best); ours produces the privilege log from the tags as an e-discovery deliverable and numbers Bates per matter sequentially Adoption: LIB-WIRED importers=3 nonval=2 — fully adopted (top of its ladder).
URCP docketing -- data-driven rules, Rule 6 weekend roll, fail-closed on an unknown ruleMeasured: dk_compute exists in runtime/nx_docket_lib.nx, verified at emit. Add a rule = a data change; a calendar deadline landing on a weekend rolls forward; an unknown rule returns -1, never a silent wrong date. Clio ships legal calendaring [clio-features]; whether its court-rules feed covers Utah is not on the mirrored page Adoption: LIB-WIRED importers=3 nonval=2 — fully adopted (top of its ladder).
Time and billing with RPC 1.15 fee application from trust, integer centsMeasured: bl_bill_from_trust exists in runtime/nx_billing_lib.nx, verified at emit. Earned fees move trust to operating only up to the trust balance and a refused billing leaves the trust untouched; Clio billing is the reference [clio-features] (Best); PandaDoc collects payments (Part) Adoption: LIB-WIRED importers=2 nonval=1 — fully adopted (top of its ladder).
Trust accounting IOLTA -- no commingling, no overdraw, three-way reconciliationMeasured: trust_disburse_ok exists in runtime/nx_trust_lib.nx, verified at emit. Utah Rule 3-1.15 (records kept five years after the representation ends) [utah-rpc-1-15], Utah IOLTA Rule 4-1001 [utah-iolta-4-1001] and ABA 1.15 [aba-rule-1-15] enforced mechanically; Clio trust accounting is the reference (Best) [clio-features] Adoption: LIB-WIRED importers=5 nonval=3 — fully adopted (top of its ladder).
New-matter intake -- validate-then-commit composition of conflicts, docket, consent and retainerMeasured exceed: intake_new_matter in runtime/nx_matter_intake_lib.nx, verified at emit. Exceed with the why: all compliance gates fire BEFORE any write, so a refused intake leaves ZERO partial state (no half-open matter, no orphan retainer); Clio Grow intake and Draft questionnaires gather the data [clio-draft]; PandaDoc forms (Part) Adoption: LIB-WIRED importers=2 nonval=1 — fully adopted (top of its ladder).
Contract lifecycle -- auto-renewal trap flagged, obligations overdue, fail-closed on unknown termsMeasured exceed: clm_renewal_state in runtime/nx_clm_lib.nx, verified at emit. Exceed with the why: the missed cancellation window is a hard state that cannot be reported as safe; DocuSign surfaces agreement dates across its IAM platform [docusign-esign]; PandaDoc CLM (Part) Adoption: LIB-GATE-ONLY importers=1 — PARTIAL: imported only by validation organs (gates, tests, benches): wire it into a shipping program.
adoption LIB-GATE-ONLY importers=1
Playbook redline risk -- deviation from the standard clause scored, auto-approve only inside the bandMeasured: cl_risk_pure exists in runtime/nx_clause_lib.nx, verified at emit. cl_best_match finds the governing clause, cl_deviation_permille scores the distance and cl_auto_approve_pure closes only inside the declared band; DocuSign agreement AI (Part) Adoption: LIB-WIRED importers=6 nonval=5 — fully adopted (top of its ladder).
Work-done trail -- every save, restore and share event on the append-only manifest with a served diffMeasured: of_diffpage exists in runtime/nx_office_serve.nx, verified at emit. The trackability the operator asked for is the manifest itself: usec-stamped versions, restore-as-new-version, ReBAC share and unshare tuples, and /diff of any two versions Adoption: LIB-WIRED importers=5 nonval=2 — fully adopted (top of its ladder).
PORTAL
Client document vault on the firm's own host -- invite-gated OPAQUE login, private uploads isolated from public searchMeasured: dad_handle exists in runtime/_hdl_build/nx_docportal_admin_daemon.nx, verified at emit. LIVE at admin.andelinwest.com: register by invite, no cookies, Public versus Private (client vault) uploads, private uploads proven absent from public search; Clio for Clients is the portal reference [clio-portal] (Best) Adoption: LIVE-DAEMON — fully adopted (top of its ladder).
Client workspace routes -- envelopes, status, checklist, document fetch, staff view, deny-by-defaultMeasured: lp_handle exists in runtime/nx_legal_portal.nx, verified at emit. Gated over a real socket (loopback live gate) with a wet-signature-required Will surfaced rather than offered to sign; the daemon is BUILT and UNPROMOTED on loopback, so this row is measured present while NOT yet served -- the next row is the deploy Adoption: LIB-WIRED importers=6 nonval=2 — fully adopted (top of its ladder).
Client portal served on the firm domain with the docportal realm and HTML viewsOpen — watching runtime/_hdl_build/nx_legal_portal_daemon.nx : lpd_serve_realm, re-measured on every compare beat. Ship that symbol and this mark flips itself; the comparewatch- plane row flips with it. portal.andelinwest.com over the andelinwest_docportal realm, HTML views over lp_handle, per-tenant file-backed stores (LP9)
watching lpd_serve_realm
Firm office workspace mounted on the firm domain with the client realmMeasured: od_session exists in runtime/_hdl_build/nx_office_daemon.nx, verified at emit. LANDED 2026-08-19 (LP3): ONE nx_office_daemon binary takes port, keys, store, realm, root, base, uid index, closed mode and authz prefix from argv, and od_session resolves the andelinwest_docportal session to the firm handle. Live at admin.andelinwest.com/office in closed mode, verified over the edge: 401 unauthenticated, invited login 200 with an owned save, and the firm document 404 on the public nishifamily office; nx_office_closed_gate 16 of 16 GREEN re-run after the deploy. The shared open-mode office namespace is never exposed to a law firm Adoption: RUN-BY:daemon — fully adopted (top of its ladder).
Secure client messaging on the firm domain -- no-cookie webmail, per-user mailboxesMeasured: epd_handle exists in runtime/_hdl_build/nx_email_portal_daemon.nx, verified at emit. LIVE at mail.andelinwest.com on the same Modern Auth as the vault; Clio secure messaging [clio-portal] Adoption: RUN-BY:daemon — fully adopted (top of its ladder).
Byte-exact document delivery -- inline in the browser or download to Word, header-injection safeMeasured: nx_doc_serve_response exists in runtime/nx_doc_serve.nx, verified at emit. Content-Length framing round-trips embedded CRLFCRLF and NUL bit-for-bit, a malicious filename cannot inject a header, unknown types download rather than render Adoption: LIB-WIRED importers=6 nonval=2 — fully adopted (top of its ladder).
AI
In-document sovereign drafting -- no cloud, on our own no-float modelMeasured: of_llm_complete exists in runtime/nx_office_serve.nx, verified at emit. Honest: the seat is 0.5B and output quality sits far below the rivals' assistants (Best): DocuSign IAM, Clio Duo, NetDocuments ndMAX, PandaDoc AI; every AI turn lands as an additive restorable version Adoption: LIB-WIRED importers=5 nonval=2 — fully adopted (top of its ladder).
Contract review grounded on the clause library with cite-or-abstainOpen — watching runtime/nx_clause_lib.nx : cl_review, re-measured on every compare beat. Ship that symbol and this mark flips itself; the comparewatch- plane row flips with it. The bar: in the Vals Legal AI Report the lawyer baseline beat every AI tool on redlining (79.7 versus 59.4 and 53.6 percent) [vals-vlair], and leading legal research tools cited unsupported law in a large share of answers [magesh2024]; a review that can only propose text traceable to a governed clause, and abstains otherwise, is the design answer (LP21)
watching cl_review
SOV
On-premise, no telemetry -- client files never leave the firm's hostMeasured: docx_write exists in runtime/_hdl_build/nx_docx.nx, verified at emit. A PROPERTY, not a capability, and deliberately NOT claimed as an exceed; every rival is a cloud service, and ABA Formal Opinion 512 (July 2024) makes confidentiality of client information entered into AI tools an explicit duty [aba-op-512] Adoption: RUN-BY:fork:nx_doc_view_gate — fully adopted (top of its ladder).
On these two registers. Rows are declared in the domain's plan file and carry the debt id, which is the join key back to the sovereign debt plane — that plane, not this page, is the authority on state. Reconciling them automatically (the regen reading the plane and refreshing these rows) is a named, owed rung; until it lands, treat an id here as a pointer to look up, not a status to trust.
Honest verdict. The coverage above is capability presence measured against source — not depth, scale, or polish, where mature rivals may lead. Exceeds are claimed only where a mechanism backs them. Every open gap is a watch contract: it names the organ and symbol that closes it, and this page flips the cell itself when that workstream ships.

Person · product · place — not yet measured for this domain

Every compare carries this layer. Declare knowledge/compare/legalpractice.ppp (rows surface|nishi or c1..c4|label|url|connect naming OUR live surface and each rival's front door), run nx_ppp_probe domain legalpractice, and this section fills itself on the next beat: the same ruler on both sides — privacy and CX (third-party hosts, tracker classes, cookies, security headers), design and longevity (design hygiene, computed WCAG contrast, render-blocking resources, unsized media, script weight, theme and motion queries), findability (landmarks, skip link, on-site search, breadcrumb, headings, internal links).

References

Beyond a link list. Every reference below resolves twice — the publisher's copy and, where banked, the estate's own non-rottable library mirror with a content pin — and carries its evidence class plus the exact claim on this page it grounds. Keyed marks like [key] in the matrix notes jump here. A dash means honestly absent, never assumed.
  1. [docusign-esign] Docusign. Electronic Signature -- Fast and Easy e-Signature (product page): send and sign agreements, templates, bulk-send envelopes to multiple signers, digital certificates and audit trail kept on the Docusign service. Accessed 2026-08-18. publisher · read in our library knowledge/fetched/cmp_legalpractice_docusign-esign.html · pin hb75fb3cb270ab6cfa624b63c92caa1776cdd82636a04f5924f24341ceb05fabe · accessed 2026-08-18 · vendor-docGrounds: The DocuSign column: Yes on the SIGN audit, ceremony, certificate and routing rows (vendor-hosted audit trail is why our hash-chain row grades an exceed), Yes on 'Bulk send' (the page lists bulk-send envelopes to multiple signers), Yes on 'Contract lifecycle' (agreement dates across the IAM platform).
  2. [docusign-idv] Docusign. Docusign Identify -- identity verification for signers (ID document verification, knowledge-based and phone authentication) (product page). Accessed 2026-08-18. publisher · read in our library knowledge/fetched/cmp_legalpractice_docusign-idv.html · pin h5be07bc66fb5adb1590ec2d50589bb9f87d68b43e9ca1445f1b37509bdd61bfa · accessed 2026-08-18 · vendor-docGrounds: The DocuSign Best code on 'Signer identity verification ladder': the reference the sc_signer_idv watch is measured against.
  3. [docusign-notary] Docusign. Docusign Notary -- remote online notarization on the Docusign platform (product page). Accessed 2026-08-18. publisher · read in our library knowledge/fetched/cmp_legalpractice_docusign-notary.html · pin h64b3ad7d2c4f3a2b52e3c247d0d98d3539e9b873d379e7b76022a7c482d48aca · accessed 2026-08-18 · vendor-docGrounds: The DocuSign Part code on 'Remote online notarization': the product exists, and the Utah Lieutenant Governor's approved-vendor list does not carry it, so it grades Part for a Utah practice.
  4. [docusign-docgen] Docusign. Document Generation -- generate agreements from templates and data (product page). Accessed 2026-08-18. publisher · read in our library knowledge/fetched/cmp_legalpractice_docusign-docgen.html · pin he44af5db9e124ef93b38f1788df07689867e931a574de8914256ed9beca02f77 · accessed 2026-08-18 · vendor-docGrounds: The DocuSign Yes on 'Clause library and templates', 'Field merge' and 'Template registry': template-driven generation is documented here; downstream lineage and staleness are not, which is why the CLERK rows read 0.
  5. [clio-draft] Clio. Clio Draft -- AI legal document automation: convert existing Word files into reusable templates, up-to-date fillable court forms for all 50 states, AI-powered client questionnaires, populate whole document sets, collect e-signatures (product page). Accessed 2026-08-18. publisher · read in our library knowledge/fetched/cmp_legalpractice_clio-draft.html · pin h2228cbe3e322b2ea043d4dd5981ece5e776dc8def18a1510ff1040af7121f6fd · accessed 2026-08-18 · vendor-docGrounds: The Clio column on the ASSEMBLE rows and its Best on 'Court forms refresh' (always-current fillable court forms), Yes on 'New-matter intake' (questionnaires), Part on the tracked-revision rows because Draft hands the file to Word.
  6. [clio-portal] Clio. Legal Client Portal With AI for Law Firms -- Clio for Clients: secure document sharing, messaging, e-signature and payments in one client portal (product page). Accessed 2026-08-18. publisher · read in our library knowledge/fetched/cmp_legalpractice_clio-portal.html · pin h261e8d6160b44409f3deda0c0001a09895dce12f399e0d3463045d5e0edb15ae · accessed 2026-08-18 · vendor-docGrounds: The Clio Best code on the PORTAL vault, workspace and served-portal rows and Yes on 'Secure client messaging': the portal reference the andelinwest.com rungs are measured against.
  7. [clio-features] Clio. Clio Manage features -- calendaring, case and task management, legal documents, accounting, billing, online payments, time and expense tracking, trust account management, client portal, workflow automation and legal AI (features index). Accessed 2026-08-18. publisher · read in our library knowledge/fetched/cmp_legalpractice_clio-features.html · pin h3ff3668b3952e38ec5a4e989e0207d952f93e61cdaebb75bc8b3f3244320c314 · accessed 2026-08-18 · vendor-docGrounds: The Clio Best codes on 'Time and billing' and 'Trust accounting IOLTA' and its Yes on 'URCP docketing' (calendaring); the conflicts row grades Clio Part because this index does not name conflict search.
  8. [netdocuments] NetDocuments. Document and Email Management for Legal Firms and Departments (home page): cloud DMS with matter-centric workspaces, Word integration and legal AI. Accessed 2026-08-18. publisher · read in our library knowledge/fetched/cmp_legalpractice_netdocuments.html · pin hbdd6254a2e58323a4f4ecf0b5dc33c7c1e37ff702fd643c33e1d1f45dc0d740b · accessed 2026-08-18 · vendor-docGrounds: The NetDocuments Best code on 'Matter-scoped DMS' (the legal DMS reference), Yes on the version-history and co-editing rows (through Word), Part on the SIGN rows (signing through integrations).
  9. [netdocs-docauto] NetDocuments. Legal Document Automation and Assembly Software (solutions page): template-driven assembly inside the DMS. Accessed 2026-08-18. publisher · read in our library knowledge/fetched/cmp_legalpractice_netdocs-docauto.html · pin hf05e49d7f90dcf2be599293aa6a456af8083562a7440ac219056bdde99440e3c · accessed 2026-08-18 · vendor-docGrounds: The NetDocuments Yes on 'Clause library and templates', 'Field merge', 'Mail merge' and 'Template registry'.
  10. [pandadoc-esign] PandaDoc. Electronic Signature Software (product page): legally binding e-signatures under ESIGN, UETA and eIDAS, a digital certificate and a full audit trail (who opened, viewed and signed, timestamps, IP addresses), templates and bulk send. Accessed 2026-08-18. publisher · read in our library knowledge/fetched/cmp_legalpractice_pandadoc-esign.html · pin heb857f08debd12a37edb8fb7e98411d5716fedbf4f370369a95079d9b0d6b164 · accessed 2026-08-18 · vendor-docGrounds: The PandaDoc column on the SIGN rows (Yes on audit, ceremony, certificate, routing, bulk send; Best on field placement) -- its audit trail is kept on the PandaDoc service, the contrast our hash-chain exceed names.
  11. [pandadoc-templates] PandaDoc. Templates -- reusable document templates and content library (product page). Accessed 2026-08-18. publisher · read in our library knowledge/fetched/cmp_legalpractice_pandadoc-templates.html · pin h362a8fcc2023618ca1b84819de8af36a5c5e256952d639dde8dd38a208595d94 · accessed 2026-08-18 · vendor-docGrounds: The PandaDoc Yes on 'Clause library and templates' and 'Template registry'.
  12. [esign-15usc7001] 15 U.S.C. section 7001 -- General rule of validity (Electronic Signatures in Global and National Commerce Act, ESIGN), including the 7001(c) consumer-consent conditions. Legal Information Institute, Cornell Law School. publisher · read in our library knowledge/fetched/cmp_legal_esign-15usc7001.html · pin h975a5f762bc64f153f2f396cfc0600f50366a406383aefc1b56420cf020013c1 · accessed 2026-08-18 · published-standardGrounds: The 'UETA and ESIGN consent-gated ceremony' and 'Legal-validity verdict per signature' rows: the federal validity rule and the consumer-consent overlay that es_esign_valid and es_consumer_ok compute per signature.
  13. [esign-7003] 15 U.S.C. section 7003 -- Specific exceptions to ESIGN: laws governing the creation and execution of wills, codicils or testamentary trusts, family law, most of the UCC, court orders and notices. Legal Information Institute, Cornell Law School. publisher · read in our library knowledge/fetched/cmp_legalpractice_esign-7003.html · pin he2628f8d9a56507bc2daae1945763090db94bc53b9f26e673713642318fff581 · accessed 2026-08-18 · published-standardGrounds: The 'Never-void instrument gate' row: the federal carve-out that makes a Will routed for ordinary e-signature a void execution, which nx_legal_regime refuses at send and at seal.
  14. [utah-ueta-201] Utah Code 46-4-201 -- Legal recognition of electronic records, electronic signatures and electronic contracts (Utah Uniform Electronic Transactions Act, Title 46 Chapter 4). Utah State Legislature. publisher · read in our library knowledge/fetched/cmp_legalpractice_utah-ueta-201.html · pin hfd5c071fa99de4ace7d41de850e2722c7956a7fbf00eced57c8565bd39da4165 · accessed 2026-08-18 · published-standardGrounds: The 'UETA and ESIGN consent-gated ceremony' row: Utah's enactment that a record or signature may not be denied legal effect solely because it is electronic; 46-4-103 in the same chapter carves out wills, grounding the never-void row.
  15. [utah-ewill-1405] Utah Code 75-2-1405 -- Execution of an electronic will (Uniform Electronic Wills Act, effective 2020-08-31): a record readable as text, signed by the testator, and signed by at least two witnesses in the physical or electronic presence of the testator. Utah State Legislature. publisher · read in our library knowledge/fetched/cmp_legalpractice_utah-ewill-1405.html · pin hb22a204187b0bf1c4b1f8be60bac75691acd6d372ab35b061181d235785aa774 · accessed 2026-08-18 · published-standardGrounds: The 'Never-void instrument gate' row: Utah is an e-wills state, so the gate must let a compliant electronic will route (two witnesses, electronic presence allowed) while refusing the unwitnessed one.
  16. [utah-ron-46-1-3-6] Utah Code 46-1-3.6 -- Remote notarization procedures (effective 2026-05-06, amended by Chapter 56, 2026 General Session): remote notary physically in Utah, simultaneous sight-and-sound communication plus an identification image, an electronic recording of each remote notarization, and satisfaction of personal-appearance requirements. Utah State Legislature. publisher · read in our library knowledge/fetched/cmp_legalpractice_utah-ron-46-1-3-6.html · pin h48383c64eeeb5c1e74b6841bff7fe878e04bf0a630322466ce82d5a128122faf · accessed 2026-08-18 · published-standardGrounds: The 'Remote online notarization' row: the elements the ron_session watch must record (Utah-located notary, A/V, ID image, recording), current as of the 2026 amendment.
  17. [utah-r623-100-9] Utah Administrative Code R623-100-9 -- Remote Notarization: Recording; the solution provider must generate a printable version of all documents and associated tamper-evident certifications, and the certificate must state the principal appeared remotely by audio-video technology. Legal Information Institute mirror of the Utah rule. publisher · read in our library knowledge/fetched/cmp_legalpractice_utah-r623-100-9.html · pin haf68f191512d5fe0988db9f1bfa998facb424d0d7aa4616c4a5f6efa2373b087 · accessed 2026-08-18 · published-standardGrounds: The 'Remote online notarization' row: the provider-side output contract (tamper-evident certifications, remote-appearance certificate wording) that a sovereign RON record must satisfy.
  18. [utah-ron-vendors] Utah Lieutenant Governor, Notary Office. Approved Remote Notary Vendors (list, last verified 2025-11-18): the platforms a Utah remote notary may use, each shown Active, including PandaDoc; Docusign is not listed. publisher · read in our library knowledge/fetched/cmp_legalpractice_utah-ron-vendors.html · pin h11841d8d851b04cca0afe3bd56b3e0de54ba97127eceffaa212bdf4e9fcf98d4 · accessed 2026-08-18 · vendor-docGrounds: The 'Remote online notarization' row: PandaDoc Yes and Docusign Part are read from this state list, not from the vendors' own pages.
  19. [utah-rpc-1-15] Utah Supreme Court Rules of Professional Practice, Rule 3-1.15 (previously UCJA 13-1.15) -- Safekeeping Property: client funds in a separate trust account, complete records preserved for five years after the representation ends, own funds only for bank charges, advance fees withdrawn as earned. Utah State Courts. publisher · read in our library knowledge/fetched/cmp_legalpractice_utah-rpc-1-15.html · pin h98f516fa237120410db64a7186e753f82c3c8f2296b11c7546678f5cf98739c6 · accessed 2026-08-18 · published-standardGrounds: The 'Trust accounting IOLTA' and 'Time and billing' rows: the Utah rule text nx_trust_lib and nx_billing_lib enforce (no commingling, no overdraw, records kept).
  20. [utah-iolta-4-1001] Utah Supreme Court Rules of Professional Practice, Rule 4-1001 -- Interest on Lawyers Trust Accounts (IOLTA), effective 2025-07-09 (formerly UCJA 14-1001): interest-bearing trust account for nominal or short-term client funds, earnings remitted to the Utah Bar Foundation, annual certification. Utah State Courts. publisher · read in our library knowledge/fetched/cmp_legalpractice_utah-iolta-4-1001.html · pin hb0993d8499786554992f00ca1bc1bc7a7aeb39c339dd84bb37deb0292d9e0f2c · accessed 2026-08-18 · published-standardGrounds: The 'Trust accounting IOLTA' row: the current Utah IOLTA rule the trust ledger is measured against.
  21. [utah-efiling] Utah State Courts. District Court e-Filing for attorneys: attorneys may build a system to submit electronic filings; a non-disclosure agreement is required of all Electronic Filing Service Providers and filers building an interface, after which an eFiling Integration Guide describing the API is provided. Accessed 2026-08-18. publisher · read in our library knowledge/fetched/cmp_legalpractice_utah-efiling-district.html · pin hc898ee22c1cfa74a5b040ffedcbcaefc9e0998b0956c6ada0299579d88e805e2 · accessed 2026-08-18 · published-standardGrounds: The 'Utah e-filing connector' row: the connector is buildable by a filer under NDA, so the efl_submit watch is a lane with a named unblock, not a guess.
  22. [aba-rule-1-7] American Bar Association. Model Rules of Professional Conduct, Rule 1.7: Conflict of Interest -- Current Clients. publisher · read in our library knowledge/fetched/cmp_legal_aba-rule-1-7.html · pin hc00ea96f94678376a0bc513bc61b3a3eec3773e2ca87b02a37c3f7cdb891cf07 · accessed 2026-08-18 · published-standardGrounds: The 'Matter spine plus RPC 1.7 and 1.9 conflicts check' row: the current-client conflict rule mt_conflict implements.
  23. [aba-rule-1-15] American Bar Association. Model Rules of Professional Conduct, Rule 1.15: Safekeeping Property. publisher · read in our library knowledge/fetched/cmp_legal_aba-rule-1-15.html · pin h1467a6a1dccf7c4d2ecf6fad846d35790671605acea29511e26373a46373a3ea · accessed 2026-08-18 · published-standardGrounds: The 'Trust accounting IOLTA' row: the model rule behind Utah 3-1.15.
  24. [ecma-376] Ecma International. ECMA-376: Office Open XML File Formats (WordprocessingML, Open Packaging Conventions), also ISO/IEC 29500. publisher · read in our library knowledge/fetched/cmp_office_ecma376.html · pin h6ebf45ac6b3db5afc2316f13acd0dddff5d78d78f2a8720cc7a07b2975d38c83 · accessed 2026-08-18 · published-standardGrounds: The OPEN and EDIT rows on .docx read, tracked revisions (w:ins, w:del), comments and the MERGEFIELD watch: the package and elements our own reader and writer implement.
  25. [odf-1-3] OASIS. Open Document Format for Office Applications (OpenDocument) Version 1.3, Part 1. OASIS Standard, 2021 (also ISO/IEC 26300). publisher · read in our library knowledge/fetched/cmp_office_odf13.html · pin h4891a74a8772d7678c4fd720ebb5a54a810a4d98811b9b68ecb2e3bcf468e91f · accessed 2026-08-18 · published-standardGrounds: The 'OpenDocument .odt read and write' row.
  26. [ms-word-mailmerge] Microsoft. Word VBA reference -- MailMerge object (Microsoft Learn): the mail merge model behind Word merge fields and data sources. Accessed 2026-08-18. publisher · read in our library knowledge/fetched/cmp_legalpractice_ms-word-mailmerge.html · pin hb21f46b9abb4863d9e72ea756a7455e3df5407d7b967e5152409f138f13790b3 · accessed 2026-08-18 · vendor-docGrounds: The 'Mail merge' and 'Word MERGEFIELD field codes' rows: the incumbent merge model a lawyer's existing templates were authored against, and the reason the double-brace merge is graded present while the field-code watch stays open.
  27. [vals-vlair] Vals AI. Vals Legal AI Report (VLAIR): CoCounsel, Vincent AI, Harvey Assistant and Oliver measured against a lawyer baseline on document Q and A, extraction, summarization, redlining, transcript analysis and chronology; on redlining the lawyers scored 79.7 percent against 59.4 (Harvey) and 53.6 (Vincent). Accessed 2026-08-18. publisher · read in our library knowledge/fetched/cmp_legalpractice_vals-vlair.html · pin h21714fd53458c08192ea35cb8b1a86b194205d6166fde459b1052f5f49d4b118 · accessed 2026-08-18 · published-paperGrounds: The 'Contract review grounded on the clause library' row: the independent benchmark showing AI redlining below the lawyer baseline, the reason the cl_review watch is designed as clause-grounded cite-or-abstain rather than free generation.
  28. [magesh2024] Magesh, Surani, Dahl, Suzgun, Manning, Ho. Hallucination-Free? Assessing the Reliability of Leading AI Legal Research Tools. arXiv:2405.20362, 2024 (Stanford RegLab / HAI). publisher · read in our library knowledge/fetched/cmp_legal_magesh2024.html · pin hf724e03a034bb9f1b3a099f1782fd1219d67a3eb9c7cd721a7de8ac97f6c66f0 · accessed 2026-08-18 · published-paperGrounds: The 'Contract review grounded on the clause library' row: the published measurement of unsupported citations in legal AI answers.
  29. [nist-800-63a-4] NIST. Special Publication 800-63A-4, Digital Identity Guidelines: Identity Proofing and Enrollment (final, July 2025): identity assurance levels, evidence strength, document validation, remote and on-site proofing, presentation-attack detection. publisher · read in our library knowledge/fetched/cmp_legalpractice_nist-800-63a-4.html · pin hf60296577b7ce92458f1109718d86684361858b6a858bac06b83ea07814cefbb · accessed 2026-08-18 · published-standardGrounds: The 'Signer identity verification ladder' row: the bar the government-ID leg of sc_signer_idv is measured against.
  30. [aba-op-512] American Bar Association, Standing Committee on Ethics and Professional Responsibility. Formal Opinion 512: Generative Artificial Intelligence Tools (July 29, 2024) -- competence, confidentiality (informed consent before client information enters a self-learning tool), communication, candor, supervision and fees. The publisher returned HTTP 403 to the sovereign fetcher on 2026-08-18, so no mirror is banked; the URL was witnessed. publisher · accessed 2026-08-18 · published-standardGrounds: The 'On-premise, no telemetry' row: the ethics duty that makes on-host processing of client documents a stated property of the stack rather than a marketing line.

generated by nx_swcompare_matrix (sovereign NishiLang organ) from knowledge/compare/legalpractice.matrix · every Nishi cell verified against organ source at emit time · watch cells re-measured on every compare beat · zero JS, zero trackers