Clifford Chance has put more than 400,000 reclassified and AI-summarised legal documents into a new firm-wide Knowledge Bank built on Microsoft 365 and Azure, with a custom permission-aware search layer intended to make the material usable by Microsoft Copilot without exposing confidential client work to the wrong lawyer.

The project, announced in July and revisited this week by Legal IT Insider’s Orange Rag, is more consequential for Microsoft 365 administrators than its legal-industry framing first suggests. Clifford Chance is not presenting Copilot as a magic interface laid over a document estate. It has treated AI deployment as a content curation, metadata and access-control programme—then connected that governed repository to natural-language search, summarisation and generative answers.

Epiq Advisory for Law Firms, which developed the platform with Clifford Chance and Microsoft, says the Knowledge Bank was delivered firm-wide after more than 400,000 documents were migrated, reclassified and summarised. The underlying stack includes SharePoint, Power Platform, Microsoft Graph API, Azure and Azure AI Studio. Artificial Lawyer separately reported the July 20 launch and confirmed the same broad architecture and document count.

The meaningful part is not the use of Azure AI Studio or the presence of a Copilot-style prompt box. It is the decision to build a curated, Microsoft-native knowledge layer around legal work product that must remain segmented by client, matter, geography and role.

Futuristic legal knowledge bank dashboard showcasing document management, AI search, metadata, and role-based access.Permissioned search is the actual product​

Clifford Chance and Epiq describe the differentiator as “Permissioned Search,” an Epiq-developed capability that applies metadata-driven access restrictions while allowing lawyers to locate relevant knowledge. In a law firm, that is a necessary design constraint rather than a premium feature: a useful precedent, memo or client note can also be material that a particular lawyer must never know exists.

Microsoft 365 Copilot already works within a signed-in user’s existing Microsoft 365 permissions. Microsoft’s own product documentation is clear that Copilot retrieves data through Microsoft Graph and does not give a user access to content they could not otherwise open. But that baseline is only as reliable as the permissions and sharing model beneath it.

That is why Microsoft now steers Copilot customers toward SharePoint Advanced Management, Purview controls and data-access governance reporting before wide AI deployment. Its guidance specifically warns administrators to locate overshared content, broken permission inheritance, anonymous or organization-wide sharing links, inactive sites and ownerless sites that could otherwise become discoverable through Copilot or agents.

Clifford Chance’s work appears designed to address a harder version of that problem. The firm is dealing not merely with broadly shared Office files but decades of specialist legal knowledge, including documents historically held in iManage. Legal IT Insider reports that the Knowledge Bank is meant to overcome challenges in using Copilot against iManage-held content, particularly around respecting access permissions.

The reporting does not explain whether the 400,000 documents were fully moved from iManage, copied into SharePoint, indexed from a separate source, or maintained through a continuing synchronization process. That omission matters. The security and operational burden differs sharply between a one-time, curated migration and a live integration that must continuously account for ethical walls, client restrictions, document changes and permission changes across two systems.

For enterprise IT teams, the lesson is blunt: preserving document-level access at query time is only one part of the problem. The organisation must also know which content deserves to be surfaced, which content has reliable metadata, who owns the classification decision, and how fast those decisions change when people join teams, leave matters or shift jurisdictions.


The 400,000-document figure signals a preparation project, not an AI pilot​

Epiq calls the Knowledge Bank an AI-ready content set and says its consultants worked with Clifford Chance’s knowledge, legal, risk and IT functions. The platform was shaped through workshops, prototypes and validation by practice leads and professional support lawyers, according to Epiq’s case study.

That process is significant because raw corporate repositories rarely make sound generative-AI sources. Legal documents in particular have problems that broad enterprise search does not resolve automatically: near-duplicate precedents, superseded advice, jurisdiction-specific rules, private matter data, inconsistent naming and valuable internal knowledge trapped in documents whose original purpose was not reuse.

Reclassification and summarisation can make the collection more discoverable, but they also create a new governance obligation. Someone must define what each class means, decide which source documents are authoritative, maintain the summaries as source material changes, and retain enough provenance for a lawyer to verify an AI-generated answer. A polished summary of an old or inapplicable precedent is still a bad answer if the system fails to show the underlying authority and its context.

Neither Clifford Chance nor Epiq has released accuracy measurements, retrieval-quality benchmarks, user-error rates, the number of active users, or a breakdown of the 400,000 documents by practice area and sensitivity. Epiq says early adoption has exceeded expectations, but that is a vendor-partner assessment, not independently published evidence of time saved or reduced legal risk.

The absence of published performance data does not diminish the implementation itself. It does place a limit on what outside observers can conclude. The firm has demonstrated the scale of its preparation effort, but not yet whether the system consistently returns better, faster or safer results than iManage search, existing knowledge portals or a conventional Microsoft Search deployment.

Microsoft gets a reference architecture, but Epiq owns a critical layer​

The Knowledge Bank illustrates a growing pattern in enterprise AI: Microsoft supplies the identity, collaboration, search, storage and AI platform components; a specialist integrator supplies the domain-specific data model, workflow design and controls that make the stack usable in a regulated profession.

Epiq’s published description stresses that the platform is “fully Microsoft-native” while also identifying Permissioned Search as an exclusive Epiq capability. That combination is worth reading carefully. The project is not evidence that a Microsoft 365 tenant can replace a legal knowledge-management system through a standard Copilot rollout. It is evidence that a large organisation can use Microsoft’s platform as the foundation for a bespoke knowledge product—provided it invests in substantial information architecture and specialist implementation work.

That distinction is useful for Windows and Microsoft 365 decision-makers. Microsoft’s Graph API can connect search and applications across Microsoft 365 data, but API permissions and application identities need their own scrutiny. Microsoft documents that an app using application permissions can search SharePoint content within the owner’s sites in a specified region, a powerful capability that must not be casually granted to a custom search service.

A firm creating a similar system should treat app registration, consent, managed identities, Graph scopes and service-account access as core security-design questions. “Copilot respects permissions” does not automatically answer whether every connected application, indexing job or custom retrieval component has been given appropriately narrow privileges.

There is also a practical commercial implication. A Microsoft-native platform can reduce dependence on a single legal-software vendor’s roadmap, but it does not eliminate dependency. Clifford Chance now relies on its own taxonomy and governance processes, Microsoft’s cloud services and Epiq’s specialist capability. That may be a deliberate and sensible trade-off, but it is a different operating model from buying a packaged platform with one supplier responsible for the application layer.


The architecture favours curated sources over tenant-wide discovery​

Clifford Chance says lawyers will receive knowledge in context, based on their work, role, location and requirements, and that the system can surface results in everyday tools such as Word and Outlook. This is where the design departs from the often-promised idea of simply turning on a tenant-wide AI assistant and letting users ask questions of everything.

Microsoft has added controls such as Restricted Content Discovery and Restricted SharePoint Search for organisations that need to limit what appears in Copilot and organisation-wide search. Those features acknowledge a recurring deployment reality: existing permissions may be technically valid while still being too broad for AI-era discovery. A file that was obscure in a neglected SharePoint library can become much easier to find once users can describe what they want in ordinary language.

Clifford Chance’s approach appears to start with a curated repository instead. That does not mean the firm has eliminated risk; it means the AI grounding set has been narrowed and structured before it is presented to lawyers. For a regulated organisation, that is often a safer path than treating every legacy repository as immediately fit for generative retrieval.

The source material also says Clifford Chance plans to capture knowledge as reusable skills that AI can understand. The term is not defined in the published reporting, and the firm has not disclosed a timetable, technical model or examples of those skills. It could mean structured playbooks, reusable prompts, workflow components or domain-specific AI agents. Until the firm provides those details, it should be read as a roadmap direction rather than an announced product capability.

The missing test is auditability under real legal pressure​

The project’s most important future measure will be whether it can provide a defensible answer when a generated response is challenged: what source material supported it, what version was current, why the user was permitted to see it, and whether a more relevant but restricted document was correctly withheld.

Those are not edge cases in legal work. They are the conditions under which an AI-enabled knowledge system earns trust or becomes another liability channel. Clifford Chance has put the right components on the table—curated data, metadata, role-aware access and human knowledge professionals—but the public material does not yet show its audit trail, evaluation process or exception handling.

Epiq’s detailed case study calls the delivery a six-month programme, while a shorter version describes the same project as completed in under seven months. That is a minor discrepancy, likely a matter of counting the project window, but it underlines how little implementation detail has been released outside partner materials. There is no disclosed budget, no public service-level commitment, and no description of how the platform will govern newly created knowledge after the initial document-cleanup effort.

For Microsoft 365 administrators, Clifford Chance’s Knowledge Bank is therefore best read as a useful reference point rather than a turnkey blueprint. The firm did not solve the Copilot readiness problem by buying a model. It funded the slower work—classification, permissions, controlled retrieval and workflow design—that determines whether an AI answer is safe enough for a lawyer to act on.