# Mike.ai buyer assurance pack

Boundary: Controlled buyer assurance pack for a UK law-firm evaluation. Not affiliated with, approved by, endorsed by, used by, or being evaluated by any real law firm.

Procurement position: Starter 5 has a self-service subscription path into controlled sample mode. Private client sources, live Microsoft consent and formal enterprise assurance remain separately gated.

Readiness: controlled-workspace-assurance-ready

Private data blocked: true

## Data boundary and private-data bar

- Status: live
- Owner: Product and security
- Buyer question: What data can a firm safely use during evaluation?
- Current position: Public routes use fictional, sample, redacted, or source metadata records. The Worker health model keeps documentBodyStorageEnabled=false.
- Evidence: /mike-ai/assurance, /mike-ai/evidence-room, /api/mike-ai/health, MIKE_AI_ALLOW_DOCUMENT_BODY_STORAGE=false
- Remaining gate: Private document body storage requires approved Access, retention, deletion, storage and audit evidence.

## Tenant model and named-user access

- Status: controlled
- Owner: Platform
- Buyer question: How are firms, users, roles and workspaces separated?
- Current position: Worker private routes require bearer auth, active workspace membership and role checks; Cloudflare Access JWT verification is implemented for enforced mode.
- Evidence: workers/mike-ai-api/src/index.js, /mike-ai/private-admin, /mike-ai/internal-v3, workspace_memberships role checks
- Remaining gate: Live Cloudflare Access application, audience/JWKS configuration and production token readback remain approval-gated.

## Retention, deletion and source vault

- Status: blocked
- Owner: Backend
- Buyer question: Can document retention and deletion be proven before private use?
- Current position: Metadata records carry retention labels, storage refs, processing state and deletion state. Raw document bodies remain refused while storage is disabled.
- Evidence: 0004_private_vault_beta.sql, /mike-ai/internal-v3, source metadata records, document body rejection tests
- Remaining gate: Complete a metadata deletion drill, signed object access design and recovery/hold policy before enabling object bodies.

## Human review, export locks and audit

- Status: live
- Owner: Legal operations
- Buyer question: What prevents unsupported output leaving the workflow?
- Current position: High-risk unresolved items block external export in the browser workflow; public packs expose reviewer status, source refs, locked exports and audit-ready evidence.
- Evidence: /mike-ai/supervision-queue, /mike-ai/completion-pack, /mike-ai/roi-report, role-limited audit export route
- Remaining gate: Persisted production queue UI, reviewer assignment readback and audit export acceptance test for a live Access workspace.

## Model policy and no-training stance

- Status: controlled
- Owner: AI governance
- Buyer question: Does the system send private matter data to a model provider?
- Current position: Private source assistant calls remain disabled. Assistant-run records store provider/model/state and hashed refs only until provider controls are approved.
- Evidence: /mike-ai/internal-v3, /mike-ai/private-admin, assistant-runs metadata route, source-grounding insufficiency tests
- Remaining gate: Approve provider terms, workspace model policy, prompt/output audit and reviewer sign-off before private-source model calls.

## Commercial controls and workflow economics

- Status: live
- Owner: Commercial
- Buyer question: How is spend kept tied to measurable operational value?
- Current position: The founding workflow offer is fixed-scope, controlled-data and measured against monthly matters, reviewer actions, export locks and estimated minutes saved.
- Evidence: /mike-ai/engagement-pack, /mike-ai/board-pack, /mike-ai/roi-report, billing records controlled route
- Remaining gate: Live Stripe products, invoices, webhooks and reconciliation remain disabled until separately approved.

## Microsoft and DMS integration boundary

- Status: planned
- Owner: Integrations
- Buyer question: What is the realistic Microsoft/DMS path?
- Current position: The V3 sequence is SharePoint/OneDrive matter-folder import first, Outlook evidence pack second, DOCX reviewed output third, then DMS connectors.
- Evidence: /mike-ai/office-readiness, /mike-ai/source-map, /mike-ai/integrations, Word-ready completion pack export
- Remaining gate: No Microsoft Graph consent, Word add-in, Outlook add-in, Copilot extension, iManage or NetDocuments connector is live.

## Decision Gates

- [ready] Run a 60-day controlled deployment conversation (Workspace enablement team): Use controlled or approved redacted data only, with the engagement pack and assurance pack attached.
- [gated] Enable named-user private workspace access (Platform): Cloudflare Access application, audience/JWKS, enforced mode, malformed assertion rejection and live health readback.
- [blocked] Accept private client document bodies (Security and operations): Retention/deletion drill, signed object access, storage audit export, malware scanning and explicit approval.
- [gated] Verify production subscription activation (Commercial): Signed checkout, webhook verification, entitlement activation, invoice policy and reconciliation readback.

## Operating Principles

- No public real-firm endorsement, approval, evaluation, staff name, matter detail, or brand implication without explicit permission.
- No private client document body storage until named-user auth, tenant checks, object storage, retention, deletion, and audit export are implemented.
- No public claim that Mike.ai can do everything Harvey can do; capability claims must match the benchmark scorecard.
- No legal advice automation claim. Mike.ai supports supervised legal operations, source review, and reviewer evidence.
- No external send, billing configuration mutation, Microsoft admin consent, DMS connection, or shared-space launch outside its approved operating route.
