WorkBuddy with Claude API: Lock down permissions and fields before saving
Community Discussion · Company Watch

WorkBuddy with Claude API: Lock down permissions and fields before saving

ZhiyuanZhiyuanSep 32026/09/03 29 views

Conclusion first. Integrating Claude API into WorkBuddy—essentially pointing the model entry to Claude-series service interfaces—isn't technically complicated. Following tutorials, you can get it running in about ten minutes. What tends to go wrong is how API Keys are managed, who can read contract files, and whether field rules were defined beforehand. I've used WorkBuddy for about a month, and this time switching the model entry was mainly because I had a batch of supplier framework agreements and email attachments on hand, wanting it to do clause summaries and rough difference screening first.

Tutorials say integrating Claude API into WorkBuddy International takes about 5 to 10 minutes to configure. My experience shows the UI operations are similar, but what really takes time in contract scenarios is redaction and fields.

Our firm is sensitive to data leakage, so I didn't upload raw contracts directly. First, I created a test workspace and redacted PDFs, Word docs, and exported emails: client names replaced with Party A/B/C, amounts converted to ranges, ID numbers and bank card numbers not retained. No matter how handy AI tools are, they cannot bypass confidentiality obligations.

I configured the path via Settings in the bottom-left corner of WorkBuddy, then selected Models. You can also click the current model name at the bottom of the chat box, e.g., Auto, scroll to the bottom, and select + Configure Custom Model. Choose Custom for the provider. Enter the Base URL (the base address for calling the interface, usually ending with /v1) in the interface address field. The API Key is the secret generated by the platform, typically starting with sk-; paste it and click the eye icon next to it to verify once. Enter the Model ID (the exact identifier assigned by the platform) in the model name field; it must match exactly.

In advanced settings, I checked Tool Calling and Image Input. Tool calling allows the model to read files and execute actions; image input is suitable for scanned documents. For context, I conservatively chose 128K (the length of text processed in one go); output was set to 8K. After saving, don't just close the window; fully exit WorkBuddy. On Windows, right-click the tray icon to exit, then reopen it. After restarting, you'll see this custom entry in the model list. Switch to it at the bottom of the chat box and send a test question. If it returns normally, it works.

On the first run, I asked it to extract fixed fields: contracting parties, service period, payment milestones, acceptance criteria, liability for breach, data protection, termination conditions, dispute resolution. It listed most of them but missed "data protection"; I had to prompt it again to add it. This result is acceptable but shouldn't be treated as a final deliverable.

I also set permission policies separately. Only I and the lead lawyer have read access to this workspace; assistants can only upload redacted versions and cannot export full summaries.

File access scope is handled with least privilege: keep only one copy of original attachments, store AI-generated intermediate summaries in a separate directory labeled "Unverified." During collaboration, avoid multiple people editing the same prompt and field table simultaneously, or versions will get messy. I habitually add dates and version numbers to filenames, e.g., 20260903_FrameworkAgreementFieldTable_v2.xlsx.

In terms of effectiveness, after switching models, long clause summaries feel more like usable drafts; fields like payment milestones and liability for breach don't require page-by-page searching. But it can't replace sentence-by-sentence comparison. I used WorkBuddy's sentence-by-sentence comparison feature to review two versions of a contract. It can list differences, but nuances in wording like "shall," "may," and "has the right to" still require lawyer judgment. As I mentioned before, WorkBuddy cannot effectively identify AI-generated content in contracts; this judgment hasn't changed after integrating the Claude API. Being better at organizing doesn't mean being better at taking responsibility.

There are pitfalls too. If you enter the full endpoint /v1/chat/completions as the interface address, WorkBuddy sometimes automatically appends the path, resulting in a 404 error. In such cases, revert to the Base URL, or enable Custom Protocol in advanced settings. Another pitfall is one-click summarization. If fields aren't fed accurately, AI might mix payment cycles from different contracts into one line. My current approach is to first unify header terminology using semantic comparison, clean the fields, and then let WorkBuddy summarize. This step seems slow but actually saves rework. My environment is Windows and our internal test directory, which may not apply to everyone.

Core viewpoint in one sentence: Integrating Claude API into WorkBuddy can improve efficiency, but the prerequisite for lawyers using it is treating it as an assistant requiring permissions, redaction, and field constraints, not an omnipotent brain that can be casually fed contracts.

1 replies

?
Ctrl + Enter to reply
Dao Shi Shuo Dui

The desensitization step is indeed a hassle. I just lock the fields directly in WorkBuddy to avoid manual edits. I used to handle documents with Codex and it often misclassified things; WB is much smoother. However, the Claude API glitches occasionally—maybe keep a local model as a backup?