Use this article when:
- A new starter joins the firm in a role that qualifies for a Harvey licence.
- A new starter has not been picked up by the standard onboarding run and needs to be provisioned manually.
- A new starter has a licence but cannot sign in, or Harvey is not appearing for them.
Step 1 - Confirm eligibility by role
Harvey eligibility is based on a person's role, not on self-request. Job titles are checked by the Service Desk onboarding script, so most eligible new starters are provisioned as part of the standard onboarding run without a ticket being raised. Requests from roles outside those listed below require a business justification and approval before a licence is granted.
Licences are consumed automatically once a user is provisioned. Only add eligible users to the Harvey AI group, as adding anyone else draws down the firm's contracted licence count.
Staff role |
Harvey licence |
How it is triggered |
Lawyers |
Automatic |
By job title, through the Service Desk onboarding script |
Legal Assistants |
Automatic |
By job title, through the Service Desk onboarding script. Also covers Casual Legal Assistant, Practice Team Coordinator and Practice Team Manager, which carry the Legal Assistant role in Harvey |
Paralegals |
On request |
Manager or Service Desk request, assessed case by case |
All other staff, for example IT or business services |
Escalate |
Do not provision. Escalate to AI @ Maddocks for a decision, as set out below |
Step 2 - Confirm AI Foundations training is complete
A Harvey licence is assigned only once the new starter has completed the mandatory AI Foundations training. This is a hard prerequisite, not a formality. If training is outstanding, place the ticket on hold and do not provision until it is confirmed complete.
Step 3 - Set the business-unit extension attribute in Entra ID
The business-unit extension attribute must be set on the new starter's Entra ID account before they are added to the Harvey AI group. This attribute drives their practice-area group membership in Harvey.
- Copy and paste the exact value provided for the practice group or business unit.
- Matching is exact, with no fuzzy matching. A stray space, a trailing character or a typo will stop provisioning silently, with no error raised.
- Confirm the value is saved before moving to the next step. Setting it after the user has been added to the group will delay their practice-area access.
Step 4 - Add the user to the Harvey Users group
Add the new starter to the Harvey AI (Harvey Users) group in Entra ID. This is the only Harvey group the Service Desk adds manually. Every other group is dynamic, with membership evaluated from the user's Entra ID attributes or job title, and no role is ever set by hand in Harvey.
Adding the user to this single group cascades membership into the other required groups, provisions them into Harvey via SCIM, and enables the Word and Outlook add-ins.
Never add a new starter to an administrator group. The MDX-AI-HARVEY-AU-Admin and MDX-AI-HARVEY-AU-SuperAdmin groups are managed by IT Operations and Security and are never added at the Service Desk. Legal Assistant is the role that permits Vault sharing; a standard user cannot share a Vault, and elevating someone is not an acceptable workaround for a Vault access request. Follow the Vault access article instead.
Step 5 - Allow SCIM provisioning to synchronise
SCIM provisioning synchronises the user into Harvey after the group membership is applied. Practice-area groups and the Harvey role follow automatically from the user's Workday-derived attributes and job title. Allow time for the synchronisation to run before telling the new starter that Harvey is ready, and confirm the user has appeared in Harvey before closing the ticket.
Step 6 - Install and sign in
Once provisioning has synchronised, direct the new starter to the relevant access method. Harvey uses Maddocks single sign-on and there is no separate Harvey password.
- Browser. No deployment is required. Harvey is reached at app.harvey.ai, signing in with the Maddocks email address
- Word and Outlook add-ins. Enabled automatically through Harvey Users group membership. No packaging or manual install is required. The user must close and reopen Word or Outlook before the add-in appears.
- Mobile. The Harvey app is published in the Microsoft Intune Company Portal. The device must be enrolled in Intune, have HYPR and Microsoft Authenticator installed, and be secured with a passcode, Face ID, fingerprint or PIN. Harvey must be installed from the Company Portal, not the public App Store or Google Play, or sign-in errors will follow.
Users are not required to set a password.
Escalation for requests outside the standard roles
A request for a new starter whose role is not listed in the eligibility table is an exception and must not be provisioned by the Service Desk. This covers business services, IT, marketing, finance, contractors and secondees, and it applies equally where a manager has made the request on the person's behalf.
Escalate to AI Program team [email protected] and place the ticket on hold pending a decision. Do not add the user to the Harvey AI group in the meantime. Include the person's full name, job title, practice group or business unit and office; who has requested the licence and the business justification; whether AI Foundations training is complete; and the ticket reference. Provision only once written approval has been received, then record that approval against the ticket before closing it.
Expected outcome
The new starter holds a Harvey licence with the role that matches their position, reaches Harvey through single sign-on, and has the Word and Outlook add-ins available. Their practice-area group membership and Vault permissions follow from their role and their matter access.