Academic Management and Legal AI Platform
Client
LexKey
Year
2026
Working at
AppX Digital

Overview
Law went digital. Legal education didn't.
Why it matters — one system, four roles, the same objects and the same rules, without becoming four products.
Product Designer, end-to-end · AppX Digital
May–Aug 2026 · 30+ high-fidelity prototypes
In implementation — no outcome data yet
The decision I'd defend — permissions as named, reusable groups with dependencies, instead of screen-by-screen configuration.
Where it's headed
LexKey is in implementation, so there's no measured impact. Whether institutions adopt it is the question still open. What the design leaves in place is a shared grammar: permission groups with dependencies, specialised flows where the task demands them, and an AI that applies criteria written by people.
The design left a system that could absorb a fourth role mid-build without rebuilding its permissions model.
Thanks to the AppX team, and to the lawyers who reviewed every rule.

The Problem
Law digitised fast. Teaching it didn't. Students spend five years studying from PDFs and being assessed on paper, then enter a market where research happens in databases and legislation is read in tools that show versions and cross-references.
The domain is itself a design constraint. Legislation has versions, states of force and cross-references. All of it has to stay legible while someone works directly on the law.
Four roles, one object model. Admin, Institution Manager, Professor and Student share the same objects and rules. A permission set in one place has to have predictable consequences everywhere else.
An institutional, multi-tenant sale. Adoption is decided once, by the institution, so the cost of standing up a new one is a commercial number as well as a design one.
The real barrier was the LMS already in place. We matched it on academic management and differentiated on assessment and on working directly with the law.
My Role
End-to-end Product Designer at AppX Digital. I owned the design work; the product decisions were made by the team. I usually framed the choice (alternatives, trade-offs, a recommendation), then designed what the team landed on: main flows for all four roles, dependency and edge-case modelling, the visual system and a component-by-component handoff.
The clearest example is the fourth role: I identified the gap and proposed the role, and the team and client approved it.
It was built with IAPMEI recovery funding, which meant a fixed deadline and building from scratch.

The System
Permissions aren't a settings screen. They're the product's grammar.
Capabilities are grouped, named and reusable, with dependencies visible in the interface: switch off a parent capability and everything depending on it switches off and recedes.
The domain is structural, and the model had to match it. Law is organised by hierarchies, numbering and relations between articles, and a flat list of permissions carried none of that.
The same grammar solved two problems that looked unrelated: configuring an institution, and configuring an exam.


Decisions
A fourth role, added mid-build. The Admin had access to every institution, so every faculty's admin task went through someone outside it. That doesn't scale in a multi-tenant product. I proposed an Institution Manager. The business model already assumed many institutions; the permission model didn't. Adding it didn't force a permissions rebuild, which is the best evidence for the group system.
Exams open by default, closed by choice. Locking everything down assesses memory, but legal practice always happens with the law in front of you. The professor defines per exam what stays available: legal library, course documents, the student's own documents, the AI, even copy-paste.
The AI applies the professor's criteria, not its own. The marking guideline is written with the question. During grading the professor can request a suggested mark and see the reasoning criterion by criterion. The suggestion is requested. It never appears on its own.
Fairness built into the product. Grading can be anonymous until marks close, and extra time for accommodations is applied automatically. These support fairer assessment; whether they produce it depends on how institutions use them.
A layer that belongs to the student. Students accumulate annotated legislation across years, beyond any single course, so they get their own documents, folders and tags. The curriculum organises teaching; the student organises study.


Trade-offs
Screen-by-screen permissions → reusable groups with dependencies.
Costs: more complexity upfront. Watch: a group becoming a dump for exceptions.
Lock down exams → the professor configures access per exam.
Costs: more setup, and two exams can differ. Watch: whether professors can build the exam they want without help.
Autonomous AI grading → written criteria, applied on request.
Costs: criteria must be explicit before the exam. Watch: whether professors recognise the suggestion as theirs.
One grading flow → separate written and oral flows.
Costs: structural complexity. Watch: the two flows drifting too far apart to share anything.

Testing & Metrics
A 30-minute moderated usability test with five people who teach or supervise higher-education students, focused on the Professor role.
Configure exam access — 4/5 without help. The dependency model was understood; one person expected a single global switch, then recovered unprompted.
Define the grading criteria — 4/5 understood the guideline comes before the AI; one looked for the AI first.
Review an AI-suggested mark — 5/5 completed it. 3/5 opened the reasoning before deciding; 2/5 accepted immediately. 4/5 recognised the mark as their own.
The counter-metric that matters: 2 of 5 accepted the AI's suggestion before checking how it was reached. Validation can't depend on the teacher choosing to inspect.
What changed: the suggestion stays on request, but the criterion-by-criterion reasoning becomes prominent at the moment of decision, rather than a detail someone has to open.
Still to instrument (not running yet)
Hypothesis — new institutions are cheap to stand up.
Metric — hours from account creation to first class configured.
Hypothesis — teacher validation stays real at scale.
Metric — % of AI suggestions accepted unchanged; above roughly 80%, I'd revisit the flow.

Learnings & What's still open
Users earlier. Lawyers validated terminology and rules, but professors came in after interaction patterns were locked. Next time I'd test while decisions are still cheap. Five moderated sessions show comprehension and trust; they don't show a semester of real use.
Measurement in week one. Writing down how will we know this worked changes the decisions you make next.
Consistency where the model supports it. I put annotation controls under every source when they only made sense in the Legal Library. I fixed it and kept the principle.
Still unproven: the permission model held the fourth role on paper, not in a shipped system. The oral assessment flow has the least precedent and is the one I'd expect to change first. Adoption against an installed LMS is a commercial risk that design can only partly address.
