Skip to main content
Back to the field guide

Meet Brief, Clause, and Shield

AI Agents for Legal Departments: Clear the Contract Backlog

In-house legal teams use Tonone's Brief, Clause, and Shield to triage vendor contract risk, draft fallback redlines, and track regulatory exposure across jurisdictions before an attorney opens a document.

Brief · Contract & Policy Drafter10 min readMay 27, 2026

At a 200-person B2B SaaS company, the general counsel's office is two attorneys and a paralegal. Every vendor deal over $10,000 needs contract review before signature, and most quarters that queue holds 15 to 20 pending agreements at once: MSAs from new SaaS vendors, DPAs from subprocessors, NDAs from prospective partners, SOWs from freight and fulfillment vendors. The standard three-week wait for a redline isn't because any single contract is hard. It's because it sits behind eleven others and nobody has triaged which ones actually carry risk. Meanwhile sales is redlining an enterprise MSA on its own authority, procurement just signed a vendor SOW with an uncapped indemnification clause nobody reviewed, and when a state privacy law updates mid-quarter, whichever attorney happens to remember is the only line of defense against a filing gap. You cannot staff your way out of this inside a legal ops budget built for two attorneys. It's a triage problem, and it's exactly the gap a generalist AI tool cannot close, because it has no memory of your playbook, no consistent risk scoring across contracts, and no tracking of which jurisdiction just changed its rules.

Why ChatGPT and Cursor don't close the contract backlog

Paste a clause into ChatGPT or Claude.ai and you get a competent, generic explanation of what it means. What you don't get is any memory of your negotiated fallback positions. Every session starts from zero. It doesn't know your MSA playbook caps liability at twelve months of fees, or that legal already rejected uncapped IP indemnity language from this exact vendor category twice this year. Ask it to review contract fourteen in your queue and it treats that contract the same way it treated contract one, as an isolated question with no accumulated context about your risk tolerance, your standard fallback clauses, or the pattern of issues this vendor's paper has shown before. For a one-off NDA that's tolerable. For a queue of eighteen vendor agreements that need consistent scoring against the same standard, it produces inconsistent, unauditable output that an attorney still has to re-verify line by line.

Cursor and GitHub Copilot don't even attempt this problem. They are autocomplete layers built for source code, fast and context-aware inside an IDE, and they have no concept of a vendor contract, a DPA, or a jurisdiction's data protection regime as a domain to specialize in. The closest a legal team gets to using them is pasting contract text into an editor and hoping a code-tuned model happens to say something useful, which it sometimes does and just as often misses. There is no clause library, no risk-tier output, no structured redline an attorney can act on without reconstructing the reasoning from scratch. The gap isn't that Cursor is bad at law. It's that an autocomplete architecture built for code has nothing in it, by design, that specializes in contract risk, and no legal team should expect it to.

The fundamental mismatch is repeatability. Legal ops needs a process that produces the same risk call on the same clause every time: draft against a known template, score against a known playbook, flag known jurisdictional exposure, and leave an audit trail an attorney can sign off on. A generalist model treats every request as a fresh Q&A and has to be re-taught your standards each time you open a new chat. That's fine for drafting a single email. It breaks down the moment your queue has eighteen contracts, three business units generating redlines independently, and a regulatory landscape that changes without anyone flagging it.

That gap compounds every quarter it goes unaddressed. The redlines sales generates on its own authority this quarter become the precedent procurement points to next quarter when it wants to skip legal review too. The subprocessor DPA that slipped through without standard contractual clauses becomes the template the next three vendor contracts get copied from. A generalist chatbot has no way to catch that drift because it never held the full picture in the first place, it answered one question at a time and moved on. What a legal ops team actually needs is something that keeps the playbook, the precedent, and the regulatory picture in view across the whole queue, not one contract at a time.

Brief drafts, Clause triages, Shield tracks the regulation

Brief is the contract and policy drafter on the legal team. It doesn't wait for a blank Word document and a blinking cursor. Point it at the deal context, an MSA renewal, a new subprocessor DPA, a vendor SOW, and it starts from a recon pass over what already exists: your prior agreements with this counterparty, the template your team actually uses, and any special terms that already got negotiated. That recon step is what makes the draft that follows usable on the first pass instead of a generic template an attorney has to rebuild from scratch.

From there, Brief drafts the agreement itself, an NDA, MSA, SLA, or vendor contract, built from your existing templates and precedent rather than boilerplate pulled from a generic training set. When the draft comes back from the counterparty with changes, Brief reviews the redline against what went out originally and flags exactly what moved, so an attorney's first read is a diff, not a fresh read of a twenty-page document.

This isn't limited to vendor paper. The same drafting and review pass covers employment agreements when the team is hiring, the SLA that goes out with a new enterprise customer, and the internal policy documents that legal is asked to produce every time a new business process needs a written standard. An in-house team of two attorneys cannot realistically draft all of that from scratch every time without a backlog forming somewhere. Brief handles the first pass so the attorney's time goes to the judgment calls, whether a clause is acceptable, not to retyping a template that already exists in a slightly different form three folders over.

Clause scores risk before an attorney opens the document

Clause is the contract clause analyst, and it's the one doing the triage in the scenario below. Instead of an attorney reading eighteen contracts cold to find the three that matter, Clause runs a recon pass across the batch, reads each contract against your negotiation playbook, and scores every clause for risk. High-risk items, uncapped indemnity, missing data processing terms, an auto-renewal buried in a late section, get flagged for an attorney immediately. Clauses that match your playbook within tolerance get signed off without consuming attorney time at all.

Clause's analysis pass is what produces the risk score itself: which clause deviates from your standard, by how much, and what the negotiation history on this counterparty says about how hard to push back. Its playbook skill is what keeps that scoring consistent contract to contract, so clause fourteen gets judged by the same standard as clause one, which is the exact consistency a generalist chatbot cannot hold across sessions.

Shield tracks regulatory exposure across jurisdictions

Shield is the regulatory risk advisor, and it's the piece that catches the problem no single attorney has time to track manually: which jurisdictions changed their rules this quarter, and which of your active vendor contracts now have a gap because of it. A subprocessor DPA that was compliant last year might be missing standard contractual clauses now required for a new EU data flow, or a vendor handling export-controlled data might trip a rule that changed after the contract was signed. Shield's recon and assessment skills read your current contract set against the regulatory landscape you actually operate in, GDPR, CCPA, export controls, and financial regulation where relevant, and its response skill drafts the remediation steps when a gap turns up, rather than leaving that discovery to whoever happens to notice next.

Concretely, that means Shield is the agent that notices when a new state privacy law adds a disclosure requirement your existing vendor DPAs don't cover, or when an export control update changes which countries a data processing vendor can operate from. Those changes don't arrive with a memo addressed to legal. They show up as a line item in a regulatory bulletin that someone has to notice, cross-reference against every active contract, and act on before it becomes a filing gap or an enforcement action. That's the exact task a two-attorney team structurally cannot keep on top of every quarter across every jurisdiction they operate in, and it's the task Shield is built to run continuously instead of reactively.

Tonone's Clause triages a full vendor contract queue by risk tier before an attorney opens a single document.

A worked example: triaging an eighteen-contract queue

Say the general counsel at a mid-size SaaS company, call her Maria, opens the quarter with eighteen pending vendor agreements stacked in the review queue: new SaaS vendor MSAs, subprocessor DPAs, and freight vendor SOWs. Reading each cold at roughly forty-five minutes per contract is thirteen and a half hours of attorney time before she's approved a single one, and that's before anyone accounts for the redlines that come back from the counterparty. Instead, Clause runs a recon and scoring pass over the full batch against Maria's negotiated playbook before she opens any of them.

text
Clause Vendor Contract Triage, Q3 batch (18 agreements)
Playbook: SaaS Vendor MSA v4, DPA Addendum v2

=======================================================
HIGH RISK (3), route to attorney first
  DataForge Analytics MSA
    - Uncapped IP indemnification (playbook caps at 12mo fees)
    - No SCCs in DPA addendum, EU personal data in scope
    Action: escalate to Maria (GC), do not sign as drafted

  Larkspur Freight SOW
    - Auto-renewal, 90-day notice window buried in Section 14
    - Liability cap silent on data breach carve-out
    Action: escalate, redline before countersigning

  Vantage Cloud Storage MSA
    - Subprocessor list not disclosed, GDPR Art. 28 gap
    Action: route to Shield for regulatory assessment

MEDIUM RISK (9), Brief drafts fallback redline, attorney spot-checks
  Liability cap 2x fees instead of playbook 1x fees (6 contracts)
  Termination for convenience clause missing (3 contracts)
  Action: Brief applies standard fallback language, ~15min review each

LOW RISK (6), matches playbook within tolerance
  Standard SaaS subscription terms, indemnity capped, DPA has SCCs
  Action: paralegal signs off, no attorney time required
=======================================================
Attorney time before triage: ~13.5h (45min x 18, reading every contract cold)
Attorney time after triage:  ~2.5h (3 high-risk contracts, spot checks on 9)

The three high-risk contracts get Maria's actual attention: the DataForge indemnity clause needs a real negotiation call, and the Vantage subprocessor gap goes to Shield to confirm whether the missing disclosure is a GDPR Article 28 problem or just an oversight in the paperwork Shield can flag for remediation. The nine medium-risk contracts get a fallback redline from Brief, pulled from the same playbook Clause scored against, so Maria's nine spot-checks are fifteen minutes each instead of a full cold read. The six low-risk contracts, the ones that already match the playbook within tolerance, never take attorney time at all. Total attorney time drops from thirteen and a half hours to about two and a half, and the two and a half hours that remain are spent on the three contracts that actually needed a lawyer's judgment, not on rediscovering which three those were.

On the Vantage contract specifically, Shield's assessment confirms the missing subprocessor disclosure is a genuine GDPR Article 28 gap, not just a paperwork oversight, because Vantage added a new EU-based data center last quarter that never got reflected in the DPA addendum. Shield drafts the remediation request to send back to Vantage along with the specific clause language the addendum needs, so Maria's negotiation call starts from a drafted fix rather than an open-ended problem. That's the difference between discovering a compliance gap during an audit six months from now and closing it during a routine quarterly triage.

Brief, Clause, and Shield vs the alternatives

None of this is about Brief, Clause, and Shield being smarter readers of contract language than a general-purpose model. It's about consistency across a queue and a persistent playbook that doesn't reset every session. The comparison below is specific to what a legal ops team actually needs when a contract backlog builds up, not a general capability comparison.

CapabilityTononeGeneralist chatbotCursor / Copilot
Scores contract risk against your playbookYes, Clause scores every clause against your negotiated fallback positionsNo, generic explanation per session, no persistent playbookNo, code-focused autocomplete, no contract review capability
Drafts fallback redlines automaticallyYes, Brief drafts fallback language pulled from your existing templates and playbookNo, requires re-explaining your standards in every new sessionNo, not built for legal documents
Tracks regulatory exposure across jurisdictionsYes, Shield flags GDPR, CCPA, and export control exposure per contractNo, no persistent regulatory tracking between sessionsNo, no regulatory awareness at all
Triages a full contract queue by risk tierYes, sorts an entire batch into high, medium, and low risk before an attorney opens oneNo, one contract per conversation, no batch triageNo, no document batch capability
Produces a reviewable audit trailYes, a structured findings report per contract an attorney can sign off onNo, chat history, not a structured or attributable recordNot applicable
Keeps scoring consistent contract to contractYes, clause-playbook applies the same standard across the whole queueNo, scoring drifts session to session with no shared memoryNot applicable

Tonone's Brief drafts fallback redlines pulled from your negotiated playbook, not generic legal boilerplate.

Tonone's Shield flags GDPR, CCPA, and export control exposure per contract, before it becomes a regulatory filing gap.

If your in-house team is sitting on a vendor contract backlog, don't assign attorney review time yet. Run Clause's recon and scoring pass over the full queue first. Sorting by risk tier before anyone opens a document turns a three-week queue into a same-day one for the contracts that actually need a lawyer's judgment.

Tonone is free and MIT-licensed. Install it once and Brief, Clause, Shield, and the rest of the legal team's agents are available in your Claude Code session. You pay only for the Claude Code token usage during the work itself, there's no separate legal-tech license fee stacked on top.

1. Add to marketplace

$ claude plugin marketplace add tonone-ai/tonone

2. Install Brief

$ claude plugin install brief@tonone-ai

Frequently asked questions

What does Tonone's Brief do for legal departments?+

Brief drafts contracts and policies, NDAs, MSAs, SLAs, employment agreements, and vendor contracts, from your existing templates and precedent. It also reviews redlines that come back from a counterparty against the original draft, so an attorney's first read is a diff rather than a full re-read.

How does Clause help with a vendor contract backlog?+

Clause runs a recon and scoring pass across a full batch of contracts, reading each against your negotiated playbook. It flags high-risk clauses, uncapped indemnity, missing data terms, buried auto-renewals, for attorney review, and clears low-risk contracts that already match the playbook without consuming attorney time.

What does Shield track for in-house counsel?+

Shield assesses your active contracts against current regulatory requirements, GDPR, CCPA, FTC rules, financial regulation, and export controls, and flags exposure gaps. Its response skill drafts remediation steps when a gap is found.

How is this different from asking ChatGPT to review a contract?+

ChatGPT and Claude.ai have no persistent memory of your negotiated playbook or fallback positions between sessions, so risk scoring is inconsistent across a contract queue. Clause applies the same playbook to every contract in a batch, and Brief drafts from your actual templates rather than generic boilerplate.

Can Cursor or Copilot help with contract review?+

No. Cursor and Copilot are autocomplete tools built for source code and have no concept of contract review, clause risk scoring, or regulatory tracking as a domain. Brief, Clause, and Shield are built specifically for legal ops workflows.

How much attorney time does contract triage actually save?+

In a worked example with eighteen pending vendor contracts, triaging the queue by risk tier before assigning review dropped attorney time from roughly 13.5 hours (reading every contract cold) to about 2.5 hours (the contracts that actually needed a lawyer's judgment).

Is Tonone free to use for legal teams?+

Yes. Tonone is MIT-licensed and free. You pay only for Claude Code token usage during the work itself, with no separate legal-tech license fee.

What is clause-playbook and why does it matter?+

clause-playbook is the skill that keeps Clause's risk scoring consistent across an entire contract batch by applying the same negotiated standard to every clause, rather than scoring each contract in isolation the way a generalist chatbot session would.

Pairs well with