A Practitioner's Field Guide Β· 2026

Claude Cowork &
The Legal Plugin

The complete hands-on guide for small firm practitioners

By Esmarie Swanepoel Β· Building AI Systems Embedded in the Human Edge

If you like this kind of thing, subscribe here for more

Important before you start: The Legal Plugin only works inside the Claude Desktop app (Cowork) β€” not in the browser version of claude.ai. You must download the desktop app first. This guide will show you exactly how.

Contents

What You'll Learn

What Is Claude Cowork?

Cowork is the agentic desktop version of Claude β€” think of it as the difference between asking a colleague a question, and delegating an entire project to them.

Launched in January 2026, Claude Cowork was described by Anthropic as "Claude Code for the rest of your work." Where the standard Claude web interface handles one task at a time in a browser, Cowork is a downloadable desktop application that can take on complex, multi-step tasks and execute them autonomously β€” reading files from folders on your computer, creating documents, processing batches of contracts, and working through a matter file from start to finish.

The critical difference for legal practitioners is this: Cowork can work with your local files. You give it access to a folder on your computer, and it reads, analyses, and creates documents inside that workspace β€” all running locally, without your files going back and forth through a chat window.

πŸ–₯️

Desktop App

Available for macOS and Windows. Must be downloaded and installed β€” it is separate from claude.ai. Works locally on your machine.

πŸ“‚

Folder Access

You grant Cowork access to a specific folder on your computer. It reads and creates files there β€” your matter files, contracts, and precedents stay on your machine.

βš™οΈ

Autonomous Tasks

Instead of one prompt β†’ one response, Cowork plans and executes multi-step workflows. "Review these 10 contracts and rank by risk" is a single instruction it can execute.

πŸ”Œ

Plugin System

Cowork is the only place the Legal Plugin (and all other knowledge-work plugins) can be installed and used. Plugins are free for all paid plan users.

What Is the Legal Plugin?

The Legal Plugin is a structured workflow layer that sits on top of Claude β€” giving it a defined sequence, output format, and risk-flagging system specifically for legal documents.

Released on 2 February 2026 and expanded significantly on 12 May 2026 with the full Claude for Legal launch, the plugin is open-source (available on GitHub) and free for all paid Claude users. It doesn't add a new AI model β€” it gives Claude a structured legal thinking process: how to read a clause, how to flag risk, what a deliverable should look like.

As Reed Smith described it: "A set of high-quality system prompts and workflow maps layered on top of Claude's existing language model β€” providing a structured pathway for processing legal requests with consistent output formatting and risk flagging."

What It Does

The plugin automates contract review, NDA triage, compliance checks, risk assessment, vendor agreement monitoring, legal briefings, and templated legal responses β€” using simple slash commands rather than prompts you have to write yourself.

TaskWithout the PluginWith the Legal Plugin
Contract reviewWrite a detailed prompt, get unstructured output/legal:review-contract β€” structured clause-by-clause analysis with GREEN/YELLOW/RED flags
NDA triagePaste and ask, manually interpret output/legal:triage-nda β€” classification, risk level, and recommended action automatically
Compliance checkDescribe the regulation, hope it knows it/legal:compliance-check β€” required clauses checklist with pass/fail status
Risk assessmentVariable output, inconsistent format/legal:risk-assessment β€” risk matrix with visual indicators and mitigation language
Batch processingNot possible in chatUpload 10 contracts to your folder; run one instruction; get ranked output
Honest Limitation

Anthropic itself advises against using the plugin for high-stakes or regulated legal work without lawyer review. Every output must be reviewed by a qualified practitioner. The plugin is a first-pass tool, not a substitute for legal judgment. This is expanded in Section 09.

Installation: Step by Step

There are two phases: installing Cowork (the desktop app), then adding the Legal Plugin. Both take under 10 minutes.

Phase 1 β€” Install Claude Desktop (Cowork)

01

Confirm you have a paid plan

The Legal Plugin requires a paid Claude subscription β€” Pro ($20/month), Max ($100/month), Team, or Enterprise. If you're on the free tier, upgrade first at claude.ai/settings.

02

Download the Claude Desktop app

Go to claude.ai/download and download for macOS or Windows. This is the Cowork application β€” separate from the browser. Install it as you would any desktop app.

03

Sign in and switch to Cowork mode

Open the app and sign in with the same account as your paid Claude subscription. You'll see a tab or toggle to switch to Cowork mode β€” this is where the Legal Plugin lives.

04

Set your Workspace folder

Cowork works with a folder on your computer. Create a dedicated folder β€” e.g. Legal Matters / Cowork Workspace β€” and point Cowork to it in Settings. All files you want Claude to process go here.


Phase 2 β€” Install the Legal Plugin

There are three ways to install β€” choose the one you're most comfortable with:

Option A β€” Via the Cowork Interface (Recommended for non-technical users)
1. Open Claude Desktop and go to Cowork mode
2. Click "Plugins" in the left sidebar
3. Find "Legal" in the plugin marketplace
4. Click Install β€” it's free, activates immediately
5. The slash commands (/legal:...) appear in your sidebar
Option B β€” Direct Web Install
1. Go to: claude.com/plugins/legal
2. Sign in with your paid account
3. Click "Add to Cowork"
4. Claude Desktop will open and complete the installation automatically
Option C β€” Command Line (for those comfortable with Terminal)
claude plugin marketplace add anthropics/knowledge-work-plugins
claude plugin install legal@knowledge-work-plugins
After Installation

You'll see the Legal plugin appear in your Cowork sidebar. Your first task: drop a contract PDF into your Workspace folder and type /legal:review-contract in the chat. That's it β€” no prompt writing needed.

Navigating the Interface

The Cowork interface looks different from the browser version of Claude. Here's what everything does.

πŸ’¬

Chat Panel

Where you type your slash commands and instructions. Unlike the browser version, commands here trigger multi-step agentic workflows β€” Claude will work through tasks and report progress as it goes.

πŸ“

Workspace Panel

Shows the files in your connected folder. You can see documents Claude is working with, files it has created, and the outputs it produces β€” all in your local folder structure.

πŸ”§

Plugins Sidebar

Lists your installed plugins, including Legal. Click any plugin to see its available commands, documentation, and settings. This is also where you update or remove plugins.

πŸ”—

Connectors Panel

Where you connect external tools (DocuSign, Westlaw, Box, etc.) via MCP. See Section 05 for the full connector guide. Connected tools appear here as active integrations.

How to Upload a Document

Simply drag and drop a PDF, Word document, or text file into your Workspace folder in the Workspace Panel β€” or copy it directly into the folder on your computer. Once it's in the folder, Claude can access it. You never paste contract text into the chat window β€” that's the old way.


Understanding How Cowork Thinks

When you give Cowork an instruction, it doesn't just respond β€” it plans, then executes. You'll see it work through steps in real time: "Reading contract... Identifying clauses... Checking against playbook... Flagging risks..." This is intentional. You can monitor progress, pause, or redirect at any step.

For a 20-page contract, a full /legal:review-contract run typically takes 60–120 seconds. For a batch of 10 NDAs, expect 5–10 minutes. Claude works through them sequentially and produces a report for each.

Connecting Your Tools (MCP Connectors)

MCP (Model Context Protocol) is Anthropic's open standard that lets Claude connect securely to your existing legal software β€” so it can read from and act on your real systems.

As of the May 2026 Claude for Legal launch, there are 20+ MCP connectors available. You don't need all of them β€” connect the ones your firm actually uses. Each connector is a one-time setup.

CategoryAvailable ConnectorsWhat Claude Can Do With It
Document ManagementiManage, NetDocuments, Box, EgnyteRead, analyse, and create documents directly in your DMS without downloading files
Contract LifecycleDocuSign, Ironclad, Datasite, DefinelyReview contracts in your CLM, trigger signature workflows, check execution status
Legal ResearchThomson Reuters / Westlaw, LexisNexis, Midpage, Trellis, Legal Data Hunter (31M+ documents)Pull cited cases, run research queries, verify authorities within a Cowork session
eDiscovery & LitigationRelativity, Everlaw, ConsilioProcess document productions, build chronologies, flag relevant documents
ProductivityMicrosoft 365 (Word, Outlook), Slack, JiraDraft in Word, triage matter emails in Outlook, create tasks from legal flags in Slack
For Small Firms β€” Start Here

You don't need enterprise software to get value. A small general practice firm should start with: Microsoft 365 (you almost certainly already have it) + DocuSign (if you use it for signatures) + Box or your DMS of choice. That alone covers 80% of daily workflow automation.

How to Connect Microsoft 365 (Example)
1. In Cowork, go to Connectors Panel β†’ Add Connector
2. Search for "Microsoft 365" and click Connect
3. Sign in with your Microsoft work account
4. Grant the requested permissions (read/write on Word, read on Outlook)
5. Test: ask Claude "Summarise the last 5 emails from [client name]"

All 7 Slash Commands Explained

These are the core commands the Legal Plugin gives you. No prompt writing needed β€” each command triggers a structured workflow with consistent, formatted output.

/legal:review-contract Most Used

What it does: Full clause-by-clause analysis of any contract. Claude reads the entire document before flagging issues β€” because clauses interact, and context matters.

How to use it: Drop your contract PDF into the Workspace folder, then type /legal:review-contract

Output includes:

  • Executive summary of key terms
  • Each clause rated: GREEN (aligns with your playbook) YELLOW (review recommended) RED (significant risk)
  • Specific redline suggestions with alternative language
  • Missing standard provisions flagged

Example instruction: "Review this vendor agreement. My client is the service recipient. Flag any liability, IP, and termination risks."

/legal:triage-nda High Volume

What it does: Rapid pre-screening of NDAs β€” ideal when you have multiple incoming NDAs to sort before deeper review.

Output includes:

  • NDA type: mutual, one-way, or multilateral
  • Duration, scope, territorial coverage
  • Risk classification: Standard Approval / Counsel Review / Full Review
  • Recommended action: approve as-is, modify specific terms, or escalate

Batch use: Drop 5 NDAs into the folder and type "Triage all NDAs in this folder. Which can be approved with standard terms?"

/legal:compliance-check

What it does: Checks a document against a specific regulatory framework and tells you what's present, what's missing, and what needs updating.

How to use it: /legal:compliance-check GDPR data processing agreement

Output includes:

  • Required clauses checklist with pass/fail status per clause
  • Missing or incomplete provisions identified
  • Recommended additions with draft language
  • Regulatory references cited

South Africa example: "/legal:compliance-check POPIA data processing agreement"
Mauritius example: "/legal:compliance-check Mauritius DPA 2017 data processing agreement"

/legal:risk-assessment

What it does: Produces a structured risk matrix for any legal document β€” useful when a client asks "is this agreement safe to sign?"

Output includes:

  • Risk matrix (high / medium / low) with visual indicators
  • Specific risk areas and their potential business impact
  • Mitigation recommendations with alternative language

Example: "Risk-assess this shareholder agreement for a minority shareholder. Focus on exit rights, drag-along, and deadlock provisions."

/legal:vendor-check

What it does: Monitors vendor agreement status, obligations, renewal dates, and SLA commitments β€” particularly useful with a document management connector.

Output includes:

  • Current agreement status and expiration dates
  • Key obligations and SLA commitments
  • Renewal terms and auto-renewal flags
  • Outstanding compliance requirements

Example: "Check all vendor agreements expiring in the next 90 days. Flag any with auto-renewal clauses."

/legal:brief Daily Use

What it does: Generates contextual legal briefings β€” from daily matter summaries to deep research memos to incident response briefs.

Briefing types:

  • Daily Brief: Pending items, upcoming deadlines, priority actions
  • Topic Research: In-depth memo on a specific legal question
  • Incident Response: Rapid brief for a time-sensitive matter

Example: "Brief me on the key commercial law changes in [your jurisdiction β€” e.g. South Africa / Mauritius] in the last 12 months relevant to SME contracts."

/legal:respond

What it does: Creates templated responses for common legal inquiries β€” reducing time on repetitive correspondence.

Response types:

  • Data subject access requests (DSAR)
  • Discovery holds and litigation preservation notices
  • Standard contract inquiry responses
  • Compliance certification requests

Example: "Draft a response to a data subject access request. Governing law: [your jurisdiction β€” e.g. South Africa POPIA / Mauritius DPA 2017 / GDPR]."

Real-World Workflows

Here's what a typical week in a small general practice firm looks like with Cowork and the Legal Plugin active.

Monday Morning β€” Matter Triage
Place all new contracts received over the weekend into your Workspace folder.

Instruction: "Triage all new documents in the folder. For each: identify the document 
type, the parties, the key obligations, and give me a priority order for my review 
this week."

β†’ Result: A ranked list with a one-paragraph summary of each document.
Contract Review β€” Single Document
Drop the contract PDF into your Workspace folder.

Instruction: "/legal:review-contract 
My client is [Party A]. Flag any clauses that are unusual or disproportionately 
favour the other party. The governing law is [your jurisdiction β€” e.g. South African 
law / Mauritius law / English law]."

β†’ Result: Clause-by-clause analysis with GREEN/YELLOW/RED flags and redline suggestions.
NDA Batch Processing
Drop 5 incoming NDAs from potential partners into the Workspace folder.

Instruction: "/legal:triage-nda
Review all NDAs in this folder. Which can I approve on standard terms? 
Which need modifications? Summarise the top issue in each that needs attention."

β†’ Result: Five individual triage reports + a summary table you can share with your 
paralegal or client.
Client Advice Summary (Plain Language)
After running /legal:review-contract, follow up with:

Instruction: "Based on your review, draft a plain-language client summary 
I can send to my client explaining:
1. What this contract is asking them to agree to
2. The three most important risk areas
3. What I recommend they ask the other side to change
Keep it under one page. No legal jargon."

β†’ Result: A ready-to-review client letter draft.
M&A / Due Diligence Support
Drop a folder of target company contracts into the Workspace folder.

Instruction: "Review all contracts in this folder. For each: identify key obligations, 
change of control provisions, termination rights, and any unusual liabilities. 
Then give me an overall risk summary suitable for inclusion in a due diligence report."

β†’ Result: Individual contract summaries + a consolidated due diligence memo.
(Best run on Claude Max for large document batches.)

Jurisdiction-Specific Notes: South Africa & Mauritius

South Africa β€” POPIA compliance: When reviewing contracts involving personal information processing, add: "Flag any data processing provisions against South Africa's POPIA requirements. Identify missing operator obligations, data subject rights clauses, and cross-border transfer provisions." Always verify against the current Information Regulator guidance at inforegulator.org.za.

South Africa β€” B-BBEE considerations: For commercial contracts with South African entities, add: "Flag any provisions that may affect B-BBEE compliance or ownership structures, including change of control clauses and subcontracting obligations."

Mauritius β€” FSC-regulated work: For FSC-licensed entities (Global Business, Management Companies), add: "The entity is FSC-licensed under [category]. Flag any provisions that may require FSC disclosure or conflict with standard licence conditions."

Mauritius β€” DPA 2017: For data processing agreements, add: "Check this DPA against the Mauritius Data Protection Act 2017. Flag missing provisions and suggest compliant alternative language."

Cross-border SA–Mauritius matters: For joint ventures or investment structures using both jurisdictions, state both explicitly: "This is a Mauritius–South Africa investment structure. Apply Mauritius commercial law as governing law. Flag any provisions that may conflict with South African exchange control regulations or SARS requirements."

All jurisdictions β€” verification rule: Always verify Claude's statutory references against primary legislation. Claude's training has a knowledge cutoff and will not reflect the most recent regulatory amendments, court decisions, or circular guidance in any jurisdiction.

Building Your Firm Playbook

The single most powerful thing you can do is create a Playbook file. This tells Claude your standard positions β€” so every review is automatically calibrated to your firm's standards, not generic defaults.

Create a file called playbook.md and save it in your Workspace folder. The Legal Plugin will reference it automatically in every command you run.

## FIRM PLAYBOOK β€” [Your Firm Name]
## Jurisdiction: [e.g. South Africa / Mauritius / Both]
## Last updated: [Date]

---

## INDEMNIFICATION
# Standard position: Mutual indemnification for material breaches only
- Acceptable: Cap at total contract value
- Flag for review: Cap exceeding 2x contract value
- Red line: Unlimited or uncapped indemnity

## LIMITATION OF LIABILITY
# Standard position: Aggregate cap at 12 months of fees paid
- Acceptable: Cap at contract value
- Red line: No limitation of liability clause at all

## IP OWNERSHIP
# Standard position: Client owns all work product created for them
- Acceptable: Joint ownership with full licence back to client
- Red line: Vendor retains any rights in client data or bespoke deliverables

## GOVERNING LAW
# Set your preferred jurisdiction(s) below
- Preferred: [Your jurisdiction β€” e.g. South African law / Mauritius law]
- Acceptable: English law (common law heritage, widely familiar)
- Requires escalation: Unfamiliar jurisdictions without clear enforcement mechanism

## DATA PROTECTION
# Set the relevant data protection law for your jurisdiction
# South Africa: POPIA (Protection of Personal Information Act)
# Mauritius: Data Protection Act 2017
# EU/UK clients: GDPR / UK GDPR may also apply
- Standard: Full DPA compliant with [your jurisdiction's data protection law]
- Acceptable: Standard clauses with explicit statutory reference
- Red line: No data processing provisions at all

## AUTO-APPROVAL THRESHOLDS
# Adjust currency and values to your firm's risk appetite
- Contract value under [ZAR 500,000 / MUR 500,000] + standard terms = paralegal approval
- Standard NDA, no unusual terms = paralegal approval
- Any IP, exclusivity, or non-compete clause = escalate to senior practitioner
- Any cross-border data transfer = compliance review required
- Any regulated entity involvement = escalate for regulatory check
Start Simple

Your first playbook doesn't need to be comprehensive. Start with your three most common contract types and your non-negotiable red lines. Add to it after every matter where you find yourself making the same judgment call β€” that's a signal a playbook rule is needed.


Adding Your Precedent Library

You can also add your standard precedents to the Workspace folder β€” your preferred NDA template, shareholder agreement structure, employment contract base, etc. Reference them by name in your instructions:

Example β€” Using a Precedent
Instruction: "Review the attached vendor agreement against our standard services 
agreement template (file: standard-services-agreement.docx in this folder). 
Identify every clause where the vendor's version deviates from our standard 
position and flag whether each deviation is acceptable, needs negotiation, or is 
a red line."

Ethics & Professional Responsibility

This section is not optional. The duty rests with you β€” not the AI, not the plugin, not Anthropic.

Verify Every Citation

The Legal Plugin can generate case references that sound authoritative but do not exist. Never include a citation in a court document, legal opinion, or client advice without independently verifying it on Westlaw, LexisNexis, or the official case database. This is the single highest-risk area in legal AI use.

Client Confidentiality

Files you drop into your Cowork Workspace are processed locally on your machine β€” but if you use cloud connectors (Box, iManage), those files travel through third-party systems. Understand your data flow. For highly sensitive matters, use only local processing. Anonymise where possible.

Anthropic's Own Warning

Anthropic explicitly advises against using the Legal Plugin for high-stakes or regulated legal work without full lawyer review. This is not a disclaimer to skip β€” it is an accurate description of the tool's limits. Every output is a first-pass draft, not a final work product.

Supervision Obligation

Cowork output must be reviewed with the same rigour you'd apply to work from a junior attorney. The GREEN/YELLOW/RED flags are a starting point β€” your professional judgment is the final gate. A GREEN flag does not mean the clause is unquestionably acceptable for your specific client.

AI Use Disclosure

Develop a firm policy on when you disclose AI use to clients. Regulatory guidance is evolving, but the direction of travel globally is toward disclosure. A simple line in your engagement letter β€” "We use AI-assisted tools in our document review process, all subject to practitioner review" β€” is a reasonable starting position.

Billing Honestly

If Cowork reduces a 3-hour contract review to 45 minutes, your billing should reflect the time actually spent. Using AI efficiency gains while billing at pre-AI rates is attracting professional standards scrutiny internationally. Review your billing practices alongside your AI adoption.

The Non-Negotiable

Claude Cowork and the Legal Plugin are your associates. You are the partner. The professional judgment, the ethical obligation, and the liability always remain with the qualified practitioner. The plugin does not hold a practising certificate β€” you do.

Quick-Reference Checklist

Your daily workflow checklist β€” print it, pin it, use it every time you open Cowork.

Before You Start a Session

☐ Is my Workspace folder set up and pointing to the right directory?
☐ Is my Playbook file (playbook.md) in the Workspace folder?
☐ Have I anonymised or pseudonymised any highly sensitive client identifiers?
☐ Are my relevant connectors (DocuSign, DMS, etc.) showing as connected?

Running a Document Review

☐ Have I dropped the correct file into the Workspace folder?
☐ Have I specified my client's position and jurisdiction in my instruction?
☐ Have I referenced my playbook or standard template where applicable?
☐ Have I specified the output format I need (summary, full analysis, client letter)?

Reviewing Cowork Output

☐ Have I verified every legal citation and statutory reference independently?
☐ Have I read the full output β€” not just the executive summary?
☐ Does the output reflect current law? (Check for post-August 2025 changes)
☐ Have I applied my own professional judgment to each RED and YELLOW flag?

Before Work Leaves the Firm

☐ Has a qualified practitioner reviewed and signed off the final document?
☐ Is my AI disclosure obligation satisfied (engagement letter / client policy)?
☐ Is billing for this matter accurately reflecting actual time spent?
☐ Would I be comfortable if a professional standards body reviewed this file?

Build as You Go

Every playbook rule you add, every workflow you refine, every precedent you upload β€” these compound. Within three months, your Cowork workspace will be a proprietary firm asset that makes every new matter faster than the last. Start today, even imperfectly.

About the Author

Esmarie Swanepoel

Building AI Systems Embedded in the Human Edge

Director & Board Advisor Microsoft Certified Generative AI Strategist Anthropic Specialist NLP Practitioner Corporate / Immigration Advisor: Mauritius AI-Powered Women Ambassador & SA Chapter Lead

I sit at the intersection of three things most people never combine: the precision of law, the psychology of human behaviour, and the leverage of artificial intelligence.

I come from a Commercial & Corporate Strategy background β€” and pivoted fully into AI building, NLP practice, and community leadership. Everything I build lives at that intersection: the unfiltered version of what it looks like to solve niche problems nobody else is solving, and to build the community rising around it.

I believe AI is only as powerful as the human intelligence directing it. That conviction drives everything I build β€” and everything I create in practice, in community, and on the ground.

Are You an AI-Powered Woman?

A Global Movement.
Africa Is the Opportunity.

AI-Powered Women is a global leadership platform anchored at MIT β€” connecting 5,000+ women leaders across 50+ countries. Built for founders, corporate leaders, entrepreneurs, solopreneurs, students, and women who know the future is being built right now.

Cape Town is first. Johannesburg is next. Africa is the opportunity.

Join the Movement β†’
Get First Access

Subscribers Hear First.
Always.

My Substack is where I share the builds, the breakthroughs, and the niche problems nobody else is solving β€” before they go anywhere else. Events, invitations, new tools, new guides: subscribers always get first access.

If this guide was useful, the Substack is the natural next step.

Subscribe Free β†’
Need Help With Setup?

Let's Build Your
Firm Playbook Together.

If you'd like hands-on help installing connectors, configuring your Cowork workspace, or building a playbook tailored to your firm's practice areas and risk positions β€” I'm available for that.

The fastest way to reach me is LinkedIn. DM me "LEGAL GUIDE" and I'll know exactly what you need.

Connect on LinkedIn β†’