Level 4 taught a firm to govern AI. Level 5 is about building the part that acts. A drafting assistant suggests; an agent does. It files, schedules, sends, updates and bills, and when it is wrong the error has already happened by the time anyone looks. This level is about building automation whose authority is bounded in writing, whose every action is recorded, and whose failures are caught by design rather than by luck.

The fourteen modules move from authority to plumbing to control. The first three establish what an agent may do in a law firm and orchestrate the two flows where automation pays off and fails most expensively: first contact through conflicts to engagement, and the matter lifecycle through its deadline events. Modules four to six are the integrations: the map of every system an automation touches and the data contract at each boundary, the document management system approached read-first with write access earned one narrow action at a time, and practice management, calendaring and billing, where a wrong date or a wrong time entry does direct harm.

Modules seven to nine are human control: approval gates designed so people make a real decision rather than clicking through, automation identities with least privilege and ethical screens enforced exactly as they are for people, and the override, the stop and the clean return to the manual route. Modules ten to twelve are defence and observation: prompt injection arriving through opposing documents and inbound mail, logging every agent action to a trail that would survive scrutiny, and monitoring for the silent failures, drift and cost that no error message announces. Modules thirteen and fourteen close the level with incident response for automation failures and a measured, honest implementation project.

Every lesson follows the same format: why the topic matters now, a question worth sitting with, what goes wrong, the practical answer as architectures, checklists, decision tools and worked examples, and the points to remember, a knowledge check and an exercise on invented systems and matters. Statements of authority are labelled: law or rule with its jurisdiction, professional guidance with its issuing body and date, best practice, emerging practice, or an AI Coalition Network recommendation. Security standards and platform documentation are named as what they are, never as law, and the course never compares or ranks products.

Security material in this level is written for defenders. It teaches threat modelling, detection, containment and response, and describes attacker capability only as far as a control needs.

The course ships with a printable workbook and nine templates: an agent authority register, an integration map, a data contract template, an approval gate design worksheet, an automation identity register, an injection threat model, an agent action log specification, an automation incident runbook and the implementation project template. The final examination draws forty scenario questions at random from a reviewed bank, and the capstone is an automation implementation project documented well enough that a supervising attorney and a security reviewer could both approve it.

Everything here is professional education. It is not legal advice, it does not replace the rules of professional conduct, court rules or other requirements of any jurisdiction, and learners must verify the laws, rules, court requirements and professional guidance that apply to their own practice. Completing the level earns an independent educational certificate issued by AI Coalition Network with a public verification page. It carries no professional education hours or approvals.