Meet Caddi in personADVISE AIOct 20–22AI for Mid-Sized LawNov 5Legal InnovatorsNov 17–18
BlogMeta Muse for Law Firms

Meta Muse for Law Firms

Meta's Muse can sign into your apps and work around the clock. Here is where it helps a law firm, and what to check before it touches client work.

Muse is a capable always-on assistant for a person's own work at a law firm: research, inbox and calendar, follow-ups, and one-off tasks the person checks. For repeated client work like matter intake, conflicts, filing, and billing, it plans each run fresh and keeps records per user, so most law firms will want a verifiable agent for that work and keep Muse for the rest.

This fall, three AI companies shipped the same idea within weeks: an agent with its own computer that works for you around the clock. xAI launched Grok Bot in August, Meta launched Muse in September, and OpenAI answered with dots at the end of the month. Operations teams at law firms are already asking whether one of them can take work off their plate.

This guide is for that question. It covers what Meta's Muse is, where it fits at a law firm, and the five things the firm has to answer before an always-on agent touches repeated client work. Every product fact comes from Meta's own pages as of October 1, 2026, and these products are changing fast.

What is Meta Muse?

Muse is Meta's personal AI agent, launched September 8, 2026 in the US and since expanded to Canada, on iOS, Android, the web, and Mac. It runs on Meta's Muse Spark model inside its own isolated Linux VM with a browser, file system, and terminal. You give Muse a goal; it builds a plan and advances the work on its own, on a schedule and in response to events.

A separate agent called Sentinel is the sole authority over Muse's connector actions and network traffic. On September 29, Meta added Muse for Small Business, with connectors like QuickBooks, Slack, Box, Dropbox, and Stripe inside the same app.

Muse is good at personal operations: planning, research, messages, errands, and a small business owner's admin, with a permission system that was clearly designed with care.

  • Plans. Free with a usage limit, Power at $20 a month, and Maximum at $100 a month. Meta has not described a team or enterprise plan, an admin console, or SSO.
  • Model. Muse Spark, running in an isolated VM Meta calls Muse Secure VM.
  • Permissions. Sentinel allows, denies, or asks you. Grants can be one-time, per session, per task, time-bounded, or perpetual.
  • Records. An in-app activity log Meta describes as a complete audit trail of what Muse has done and plans to do.
  • Training. Sanitized trajectories are used for training by default, with an opt-out.
  • Connectors. Email, calendar, and Meta's apps, plus dozens of small-business tools. Muse can also write its own connectors for services with an API.

Product details as of October 1, 2026, from the vendor's own announcement, help, and security pages.

Where law firms want to use Muse

Nobody at a law firm needs an agent to do the professional judgment. They want back the hours their teams spend on repeated, system-to-system work:

  • Matter intake and conflicts. Reading the intake form, running the conflict search in Intapp, and opening the matter.
  • Document filing. Profiling and filing email and documents into iManage or NetDocuments by the firm's conventions.
  • Time and prebill review. Chasing missing time, applying outside counsel guidelines, and preparing prebills in Aderant or Elite 3E.
  • Docketing. Pulling dates out of orders and emails and getting them onto the right calendars.
  • Inbox triage. Sorting shared mailboxes into new matters, client questions, and court notices, and routing each one.

Picture a solo practitioner asking Muse to keep their practice running: sort the inbox, put court dates on the calendar, follow up with clients who have not signed engagement letters. Muse makes a plan, Sentinel asks before the first email goes out, and the practitioner grants approval for routine follow-ups.

For one lawyer handling their own matters, that can be genuinely useful. For a firm, the gaps show up quickly: there is no admin console, no SSO, and no firm-wide view of what each person's Muse did. Every associate's agent would carry its own plan, its own grants, and its own activity log, and training on activity is on unless each person opts out.

Five questions before Muse touches client work

None of these are reasons to avoid Muse. They are the questions any law firm has to answer for any agent that acts on a client's behalf.

Will Muse do the work the same way every time?

Muse is goal-driven. It plans, then works, and it learns from your conversations as it goes. Meta describes only two parts of Muse as deterministic: its approval cards and its credential storage. There is no saved, step-by-step workflow a reviewer can read before a run.

For matter intake, conflicts, filing, and billing, that matters. You cannot test a procedure on last month's cases and rely on the result if the next run is planned again from scratch.

Who supervises Muse at a law firm?

Sentinel is a thoughtful design: a separate agent that sits outside Muse, tracks whether a process has read your data, and decides whether an action is allowed, denied, or needs you. Meta also chose not to ask about everything, because constant prompts get ignored. Read-only, previously allowed, or low-risk actions proceed without asking, and grants can be perpetual. That is right for one person's life. In a firm, it means the supervision lives in each user's individual grants.

ABA Model Rule 5.3 requires lawyers with supervisory authority to make reasonable efforts to ensure that nonlawyer assistance is compatible with their professional obligations, and ABA Formal Opinion 512 (July 2024) applies the supervision rules to generative AI tools. A supervising partner needs something to supervise: a procedure they can review and a record of how it ran.

Can the firm show what Muse did?

Each user has an activity log of what Muse did and plans to do, and can download their files and memory. Meta has not described an export format, admin access to those logs, or a retention period.

When a client, an auditor, or opposing counsel asks how a document was filed or why a matter opened without a flagged conflict, the firm needs an answer tied to the specific transaction, not a reconstruction from an agent's chat history.

What happens to client data?

Muse uses sanitized trajectories for training unless you opt out. Meta's security page also says the current architecture does not prevent Meta from accessing data when needed to support, secure, or operate the service; a Confidential VM with a user-held key is planned for later this year.

Rule 1.6(c) asks lawyers to make reasonable efforts to prevent unauthorized disclosure of client information. An agent with a user's email, files, and app logins is inside that duty.

Meta's own security page says "prompt injection remains an open problem."

Does Muse reach the systems law firms run on?

Muse connects to email, calendar, and Meta's apps, and Muse for Small Business adds QuickBooks, Slack, Box, Dropbox, Asana, Shopify, Stripe, and others. Meta has not named Microsoft 365, Outlook, or Salesforce connectors.

Most law firm operations run through Intapp, iManage or NetDocuments, Aderant or Elite 3E, and Outlook, often with portals and desktop software that do not have friendly APIs. Reaching a system is only half of it; the other half is doing the same thing in it every time.

Meta MuseCaddi
How the work is definedA goal Muse plans against each timeTested code you can read and change
Same input, same path?Not claimed by the vendorYes, for the coded steps
Role of AI in a runPlans and performs each stepNamed judgment steps, scoped and logged
Human controlSentinel allows, denies, or asks; grants can be perpetualReview the procedure; exceptions go to a named person
Record of each runPer-user activity log; no stated admin exportEvery run logged, tied to its source documents
Built forA person's own varied workLaw firms' repeated back-office workflows
Meta Muse vs. Caddi on what a law firm has to answer before an agent runs client work. Meta Muse details as of October 1, 2026.

What a verifiable agent does differently

The fix is not a better prompt or a stricter approval setting. It is moving the procedure out of the model. A hybrid agent runs the workflow as code, which can be read, tested, and versioned, and calls AI only for the steps that need judgment, each one scoped and logged.

For matter intake, that means the code reads the intake email, runs the conflict search, opens the matter, and files the engagement letter the same way every time, while AI handles the judgment inside it: is this email a new matter, which party name on the form is the client, does this hit look like a real conflict. Uncertain calls go to the intake team, logged.

That split is what makes an agent verifiable: a reviewer can read the procedure before it runs, every judgment call is on the record, and changes are made on purpose.

More on the idea in what are verifiable AI agents and what are hybrid agents.

  1. Connect Intapp to Caddi

    Allow

    1Sign in to your tools

    One click each for Intapp, iManage and Microsoft Outlook. No API keys.

  2. Automate matter intake.

    Type it

    2Show or tell it

    Screenshare the job, or type it in chat. Change it any time.

  3. Running

    14 done1 for review

    3Watch it run

    Caddi does the work and flags anything unsure for review.

Show Caddi the workflow on a call or describe it in chat. It runs as tested code across your tools, with the judgment steps scoped and logged.

How law firms can use both

Muse and a verifiable agent are not competing for the same job. Let people use Muse for the work around them, where every task is different and the person who asked checks the result.

Put the repeated client work, matter intake, conflicts, filing, and billing, on an agent the firm can verify. That is what Caddi builds: an ops person shows Caddi the workflow on a screen share or describes it in chat, Caddi runs it as code across the firm's tools with the judgment steps logged, and the team changes it in plain English as the work changes. Across Caddi customers, 99% of agent runs complete successfully.

Muse shows how much an agent can now do inside your apps. For law firms, the next question is whether you can check what it did. Keep Muse for personal work, and run client work on a procedure you can review, with a record for every run.

Keep reading

Caddi

See how Caddi AI Agents can run your firm's back office the same way every time and log every run for review

Or sign up free

Frequently asked questions

Is Meta Muse safe for law firms?

Muse has real safeguards: sentinel allows, denies, or asks; grants can be perpetual. For a person's own work, those are sensible. For repeated client work, a law firm also has to answer for supervision, records, and confidentiality, and Muse plans each run fresh with records kept per user. Most firms will keep it for personal work and use a verifiable agent for client workflows.

Can Meta Muse run matter intake, conflicts, filing, and billing unattended?

It can attempt it: Muse works in the background and can reach many apps. But it decides how to handle each case on that run, and the vendor does not claim repeatable runs, so the firm cannot test the procedure once and rely on it. For unattended client work, a verifiable agent that runs the steps as code is the safer fit.

Does Meta Muse keep an audit trail?

Each user has an activity log of what Muse did and plans to do, and can download their files and memory. Meta has not described an export format, admin access to those logs, or a retention period. For law firms, check whether that record can be exported, retained, and reviewed at the firm level before relying on it.

Does Meta Muse train on our data?

Muse uses sanitized trajectories for training unless you opt out. Meta's security page also says the current architecture does not prevent Meta from accessing data when needed to support, secure, or operate the service; a Confidential VM with a user-held key is planned for later this year.

What should a law firm use for repeated client work?

A verifiable agent: one whose procedure you can read, whose judgment steps are logged, and whose every run leaves a record. Caddi builds these for law firms. Your team shows the workflow on a screen share or describes it in chat, and Caddi runs it as code across your tools, with exceptions routed to a named person.