Build Your Own Research Assistant — Projects, Notebooks and RAG
Retrieval drawn as a mechanism you can picture, then built as a thing you own: a grounded workspace over a bundle of judgments, with an instruction set that makes it cite paragraphs and admit what its sources do not say — in ten minutes, on a free account.
The hook
“Everything you did yesterday dies with the chat: the judgment you pasted, the instructions you wrote, the style you taught it. A workspace is where that work stops evaporating — files that persist, instructions that persist, answers that point into your own sources. You can build one over your moot bundle in ten minutes, free, tonight. This hour, you will.”
What you'll be able to do
- Explain retrieval-augmented generation as a mechanism — retrieve from stored sources → put the passages in the window → answer with a pointer — and predict its failure modes: the retrieval miss, the wrong passage, and the model answering from prior knowledge anyway.
- Build a grounded workspace on a free tier — a NotebookLM notebook or a ChatGPT/Claude Project — over a real bundle of authorities, with an instruction set that requires paragraph citations and 'not in the sources' answers.
- Interrogate it like a lawyer: trace a doctrine through the bundle with pinpoints, test it with a trap question its sources cannot answer, and verify a sample of its citations against the documents.
- State the limits and the law: retrieval is not verification, a workspace is only as current as its bundle, grounded tools still err — and what may never go into a consumer workspace, with the statutory and professional reasons why.
On the syllabus
- What did you just paste? — the opening vote, and what actually happens to what you type
- RAG drawn: retrieve → window → answer with a pointer — and the three ways the clerk fails
- The harness zoo: custom instructions, Projects, Gems, notebooks — what each actually changes
- The instruction set as office policy: cite paragraphs, admit 'not in the sources', keep a log
- The live build: the electronic-evidence bundle, interrogated, trapped, and caught out of date
- The limits and the law: retrieval is not verification; staleness; and what never goes in a workspace
In short
Session 4 is the course's biggest practical gift. It starts by drawing RAG as a mechanism a student can picture — a filing clerk who fetches passages and hands them to the reader, with every failure mode a clerk could have — and then shows that the 'Projects' and notebooks already sitting inside the free consumer tools are exactly this machine, waiting to be pointed at a law student's real work. The class then builds one, live, over a bundle the course has been quietly assembling since Session 3: the electronic-evidence line, from Navjot Sandhu through Anvar and Shafhi to Arjun Panditrao, plus the BSA's s.63 — and interrogates it with pinpoint citations, watches it decline a trap question, and then catches its most important limit when a 2026 Supreme Court order the bundle does not contain changes the answer. The confidentiality thread stops being a warning and becomes doctrine: what persists in a workspace is a disclosure that persists, so judgments go in and clients never do. The lab hands every student a working research assistant over a second bundle or their own moot problem — the single deliverable most likely to still be in use a year after the course ends.
Why it matters for using AI well
You leave owning a research assistant scoped to your actual work — your moot bundle, your seminar sources, your internship's statutes — that cites paragraphs, admits ignorance, and costs nothing. From tonight, 'let me check my notebook' replaces 'let me ask ChatGPT', and the difference between those sentences is the difference between grounded and guessing.
What you can do on Monday
Tonight, build one for real: your moot problem plus its authorities, or your seminar paper's sources, into a NotebookLM notebook or a free Project, with the instruction set from the lab. Ask it your three hardest questions and check one pinpoint per answer.
What they leave with
The skill
Build the grounded workspace: a real bundle, an instruction set that forces paragraph citations and 'not in the sources', a trap question to test it, and a bundle-currency check before you rely on it.
The insight
A workspace is a snapshot of the law, not a subscription to it — grounding buys you pointers instead of guesses, and in exchange you inherit a new duty: keeping the bundle as current as the matter.
The moment they remember
The staleness catch. The room's own freshly-built workspace answers the expert-certificate question confidently and — as of May 2026 — incompletely, because its newest source predates the Supreme Court's clarification. The order is dropped into the bundle live, the question re-asked, and the answer visibly changes, new pinpoint and all. The workspace was never wrong; it was faithful to a bundle that had gone stale — and every student who watches the answer change understands, in one beat, both why grounding works and why it can never replace a lawyer keeping current.
In this session
- 01
The opening mirror, and what it teaches: a realistic junior's prompt about a live matter goes up — names, amounts, a diagnosis-shaped fact — and the room votes on whether it is safe to send. Then the identifiers are highlighted, and the abstraction move is performed live: the same question asked about 'a licensee' and 'a sum' gets the same quality of answer with nobody's client in it. The mechanism behind the rule: consumer free tiers log conversations and, by default, most train on them — the opt-out switches exist and the lab flips them — and a workspace makes the stakes permanent, because what you upload persists by design.
- 02
RAG, drawn once and drawn properly: your documents are stored and indexed; at each question, a retriever fetches the passages that look most relevant; those passages go into the window; the model answers from them, ideally with a pointer to where. Every strength follows (the corpus can be far bigger than any window; answers come with addresses; the model is reshaping, not recalling) — and every failure mode is a clerk's failure: the retrieval miss (the right passage never fetched, so the answer rests on the wrong ones), the wrong pointer (a citation to a passage that says something adjacent), and the override (the model answering from its training anyway, especially when the sources contradict what it 'remembers'). Grounded is better; grounded is not true: the Stanford benchmark of professional legal-research tools found even citator-backed systems hallucinating on roughly one query in six.
- 03
The harness zoo, demystified — four artefacts, one mechanical question each: what persists? Custom instructions: a standing preamble to every chat (free on the major tiers; small; the right home for 'always cite paragraph numbers; flag anything unverified'). A Project (ChatGPT: free tier, five files per project; Claude: free tier, five projects): instructions plus files plus chats, in one container — a small RAG over your bundle. A Gem (Gemini, free): a saved instruction set with optional knowledge files. NotebookLM (free, 50 sources per notebook, each source up to half a million words): the purest of the four — source-grounded by design, every answer carrying inline citations that click through to the passage, and, unusually for a free consumer tool, not training on your uploads. One closed door named honestly: building a custom GPT is no longer a free-tier exercise (at the time of checking, the vendor's own pages disagreed about which paid plans still allow it) — the free-tier route is Projects, Gems and notebooks, and it is enough. One opened door worth knowing: ChatGPT Projects can now be shared, even on free accounts — a moot team can work one workspace together — with the caveat that a shared project trains on members' data unless every member has turned training off.
- 04
The instruction set is where a law student's training shows. The workspace's standing orders, written like office policy: answer only from the sources in this workspace; cite the document and paragraph for every proposition; where the sources do not address the question, say 'not in the sources' — do not supplement from general knowledge; where sources conflict, say which is later and which is higher; maintain the running research log when asked. Each line exists because Session 1 taught you what the machine does without it. This is harness engineering: not code, but policy — the same skill as drafting instructions for a junior who is brilliant, literal, and constitutionally incapable of saying 'I don't know' unless ordered to.
- 05
The live build, on the bundle the course has been assembling all along: State v. Navjot Sandhu, Anvar P.V. v. P.K. Basheer, Shafhi Mohammad, Arjun Panditrao Khotkar, and the text of s.63 of the Bharatiya Sakshya Adhiniyam — the electronic-evidence line, which is simultaneously a doctrine-tracing exercise (watch the certificate requirement fall, rise, waver and settle across four cases, with pinpoints) and the exact law Session 7 will need. Then the trap question — one the bundle cannot answer — and the workspace, under its instruction set, says 'not in the sources', which is the most professionally reassuring sentence a machine can produce.
- 06
Then the moment the session is really for: the staleness catch. The workspace is asked who may sign the s.63(4) expert certificate — and answers from its newest source as if the law stopped there, because for this workspace, it did. The room is then shown Pune Bar Association v. Union of India (SC, 22 May 2026), which upheld the certificate regime and read 'expert' beyond the notified s.79A examiners; the order is added to the bundle live; the same question is re-asked; the answer changes, with a new pinpoint. A workspace is a snapshot, not a subscription: it knows nothing it was not given, including last month's law — updating the bundle is now part of updating the matter, and 'is my bundle current?' joins 'is it still good law?' in the standing checklist.
- 07
What never goes in, now as doctrine rather than caution: a consumer workspace is a standing disclosure to a third party, so client documents, instructions and identifying facts stay out — full stop. The legal frame, previewed here and completed in Session 7: privilege under s.132 BSA belongs to the client and is not yours to waive into a training corpus; the professional rules make the client's confidence your standing duty; the DPDP Act — its substantive obligations commencing May 2027 — will make the advocate a data fiduciary engaging an unbriefed processor the moment client data is pasted; and In Re: Summoning Advocates (2025 INSC 1275) has already shown the Supreme Court thinking hard about exactly what a shared repository of a lawyer's files exposes. The working rule the course will not soften: published law in, clients never — and the enterprise-grade exceptions are a thing firms buy, not a thing free tiers give.
- 08
When not to build one: a workspace earns its keep on recurring work over a stable bundle — a moot, a seminar paper, an internship's running matter, exam revision over a course's readings. For a one-off question, Session 3's paste-and-ask beats it. The diagnostic vocabulary grows one more word: alongside the prompt ceiling and the model ceiling there is a tool ceiling — and last session's two-hundred-page judgment, which defeated the free chat window, fits inside a single free NotebookLM source with room to spare. Sometimes the answer is not a better model; it is a better-shaped tool, and it is free.
The build-along
Build it with the room. Leave holding it.
The class constructs the thing alongside the presenter — the prompt, the workspace, the pipeline — with the mechanism explained as it is built, and a named skill at the end.
Why this shape
A build-along wearing one short mirror as its opening: the 'what did you just paste?' vote has to sting before the confidentiality rule feels earned, and it frames what a workspace is — a place where documents persist, which is exactly why what goes into one is a legal decision. Everything else is construction: the class builds the workspace alongside the presenter and leaves owning one. This is the session the brief called the most immediately useful thing in the course, and it is built, not described.
What did you just paste?
Experiment on the classOn the class
A realistic junior's prompt about a live matter goes on screen — party names, an amount, one fact that identifies the client to anyone in the sector — and the room votes: safe to send to a free chatbot?
In the model
A consumer model is a third party with a memory: conversations are logged, most free tiers train on them by default, and a workspace keeps what it is given. The paste is a disclosure; a workspace makes it a standing one.
Live on the model
The identifiers are highlighted, the prompt is rewritten live as an abstracted fact pattern, and both versions run — the answers are equally useful, and only one of them contains a client.
The skill
Abstract before you prompt, always. If the abstraction genuinely cannot be done, that is the sign you need a tool with a contract, not a consumer app with a free tier.
The ten-minute research assistant
Build-alongThe task
The room dictates the build: which five documents go in, and — line by line, argued and voted — the instruction set: cite paragraphs; answer only from the sources; say 'not in the sources'; prefer the later and higher authority; keep the log.
Why it works
A workspace is retrieval with your name on it: persistent files, persistent instructions, answers with addresses. The instruction set is what turns a clever toy into something with office discipline.
Built live
The electronic-evidence bundle goes into a fresh notebook; the doctrine is traced through it with clickable pinpoints; the trap question comes back 'not in the sources' — and the room hears a machine decline to guess for the first time.
The skill
Bundle, instructions, trap test. Ten minutes, free, and yours — the single most reusable thing this course builds.
The staleness catch
DemonstrationThe room predicts
The room is asked: our workspace was built from sources ending in 2023 — who may sign the s.63(4) expert certificate? Commit to whether the workspace's confident answer is the current law.
What is going on
A grounded workspace is faithful to its bundle, including the bundle's cut-off date. It does not know the law moved, because for it, the law is the bundle.
Shown live
Pune Bar Association (SC, 22 May 2026) is added to the notebook live; the identical question re-asked; the answer changes on screen, new pinpoint attached.
The skill
Date your bundle and check its currency like you check a citator. 'Is my bundle current?' is now part of 'is it still good law?'
The legal thread
This is where the confidentiality thread becomes doctrine. A workspace persists, so what enters it is a disclosure that persists: under s.132 BSA the privilege you would be leaking belongs to the client, not to you; the professional rules make the confidence a standing duty; and the DPDP Act's fiduciary-and-processor structure — substantive obligations from May 2027 — is the statutory frame arriving on top. Published law in, clients never — and Session 7 completes the frame, including what In Re: Summoning Advocates means for in-house counsel and shared repositories.
Hands-on · 30 minutes · on your own laptop
The Ten-Minute Research Assistant
Build your own: a grounded workspace over a fresh bundle, with the class instruction set, interrogated with pinpoint-cited questions, tested with a trap, and verified by opening two citations against the documents. Use the supplied second bundle or — better — your own moot problem and its authorities, so you walk out with the tool you will actually use this term.
1 · Watch — the instructor demonstrates
On
Google NotebookLM (free; sign in with a Google account) — or a ChatGPT free-tier Project for anyone without one
The exact prompt
Instruction set for the notebook (paste as the standing prompt / first message): You are a research assistant for an Indian law student. Answer only from the sources in this notebook. Cite the source and paragraph for every proposition. If the sources do not address the question, reply 'Not in the sources' — do not answer from general knowledge. Where sources conflict, state which is later and which is the higher court, and prefer it. First question: trace how the certificate requirement for electronic evidence developed across these sources, in date order, citing the paragraph where each case states its rule.
Point at
Click one inline citation live and let the room watch it land on the actual passage — that click is the whole difference between grounded and guessing. Then point at the doctrine trace's date order, and at the first 'Not in the sources' when the trap question runs.
Roughly what comes back
A date-ordered trace with clickable pinpoints, mostly accurate; occasionally a pointer lands on an adjacent passage — open it, show the mismatch, and log it as the 'wrong pointer' failure mode doing its cameo. The trap question ('What does this bundle say about call-recording consent?') should return a refusal to answer from outside the sources.
If it misbehaves
A pre-built duplicate notebook, already loaded and tested that morning (share-screen from it if the live build hits an upload error or the wifi chokes on sixty simultaneous uploads — and stagger the room's uploads in thirds regardless).
2 · Your turn — a variant, not a copy
Your turn, on a different corpus: the supplied second bundle — the liquidated-damages line (Fateh Chand, Maula Bux, ONGC v. Saw Pipes, Kailash Nath, with ss.73–74 Contract Act) — or your own moot problem plus its authorities if you have them as text PDFs. Build the workspace, paste the instruction set, ask three real questions and one trap, and open two citations to verify the pointers actually support the propositions.
Free tier
NotebookLM's free tier (50 queries/day, 50 sources/notebook) holds this lab several times over, needs no phone number, admits students under 18, and does not train on uploads; ChatGPT's free Project (5 files) fits the five-document bundle exactly. If uploads jam on the shared network, work in pairs on one notebook — the instruction set and the verification are the assessed craft, not the clicking.
3 · The reveal
Phones tally three things: did your trap question hold ('not in the sources' vs. an invented answer), did your two checked pointers survive, and — the honest one — did anyone catch the workspace answering from outside its bundle? Each 'yes' on the last goes on screen as a live specimen of the override failure mode, which is exactly what Session 6's check exists to catch.
Deliverable
A working grounded workspace — bundle, instruction set, and a Q&A log with two verified pinpoints and the trap result — the founding artefact of the assessed Grounded Workspace, which you will extend with a critic pass in Session 5 and a limits note before submission.
Run of show · 30 minutes
- 0–10 min — Watch: bundle in, instruction set pasted, doctrine traced with clickable pinpoints, trap question declined, and the staleness catch performed.
- 10–15 min — Your turn: create the notebook or Project, upload your bundle (staggered by rows), paste the instruction set.
- 15–23 min — Interrogate: three real questions with pinpoints demanded, one trap question the bundle cannot answer.
- 23–27 min — Verify: open two cited passages against the documents; log any wrong pointer or outside-the-bundle answer.
- 27–30 min — Reveal: trap results, pointer survival and override catches tallied on screen.
For the instructor · before the session
- Pre-build the demo notebook and a duplicate; test both accounts that morning; screenshot the doctrine trace and the trap refusal as fallbacks.
- Have the Pune Bar Association order PDF staged for the staleness catch — the demonstration fails if it is already in the bundle.
- Post both bundles (electronic-evidence; liquidated-damages) as text-layer PDFs with direct links, plus the instruction set as copyable text.
- Plan the upload stagger (rows A/B/C, three minutes apart) and say it on the slide — sixty simultaneous uploads from one campus IP is the predictable failure.
- Verify the liquidated-damages bundle's citations to source before class — Fateh Chand, Maula Bux, ONGC v. Saw Pipes and Kailash Nath enter the codebook with this session.
- Launch the Session 4 poll deck; the paste vote opens the hour and the trap/pointer tallies close the lab.
Key sources & cases
Google NotebookLM / Gemini Notebook (free tier, checked 2026-08-27)
The lab's primary tool: 100 notebooks, 50 sources per notebook, each source up to 500,000 words or 200 MB; 50 chat queries a day; inline citations that click through to the source passage; uploads not used for model training by default. All limits from vendor help pages — RE-CHECK EACH COHORT, and note the product was being renamed 'Gemini Notebook' at the time of checking.
ChatGPT Projects and Claude Projects (free tiers, checked 2026-08-27)
The alternates: ChatGPT Projects on the free tier — unlimited projects, five files each, project-level instructions, and 'project-only memory' which walls a matter off from your other chats (choose it at creation; a default-memory project can leak context between matters); shareable with up to five collaborators on free since Oct 2025. Claude's free tier allows five projects (18+ only, phone-verified — a first-year at 17 cannot lawfully hold a Claude account, which is why the lab defaults to NotebookLM/Gemini). Custom-GPT creation is not a free-tier feature. Vendor pages read 2026-08-27, partly via archives; re-check each cohort.
Magesh, Surani, Dahl, Suzgun, Manning & Ho, 'Hallucination-Free? Assessing the Reliability of Leading AI Legal Research Tools', J. Empirical Legal Studies (2025)
The Stanford evaluation: professional grounded legal-research tools still hallucinated on roughly one query in six (Lexis+ AI ≈17%) to one in three (Westlaw AI-AR ≈33%), against ≈43% for a bare generalist model — and against a vendor claim of '100% hallucination-free'. Teach the numbers and the vendor contestation together. Verified 2026-08-26; the White Paper cites the same study at p.56.
The electronic-evidence bundle: State v. Navjot Sandhu (2005); Anvar P.V. v. P.K. Basheer (2014) 10 SCC 473; Shafhi Mohammad (2018) 2 SCC 801; Arjun Panditrao Khotkar (2020) 7 SCC 1; Bharatiya Sakshya Adhiniyam 2023, s.63
The build's corpus, chosen because tracing the certificate requirement through it is a genuine doctrine exercise and because Session 7 stands on the same law. Anvar, Arjun Panditrao and s.63 verified 2026-08-26 (codebook); Navjot Sandhu and Shafhi enter the codebook with this session — VERIFY TO SOURCE before teaching from them.
Pune Bar Association v. Union of India, W.P. (C) No. 599/2026 (SC, 22 May 2026)
The staleness catch's payload: a three-judge order upholding s.63(4) and the Schedule — the hash-value requirement has a rational nexus with integrity, and 'expert' for Part B is not confined to s.79A-notified examiners — expressly noting that authenticity challenges are 'accentuated with the advent of artificial intelligence and deepfake technology'. Read to the signed order 2026-08-27 (LiveLaw-hosted copy); an order disposing of the petition without notice, not a full judgment after contest — teach it as exactly that.
In Re: Summoning Advocates, 2025 INSC 1275 (SC, 31 Oct 2025); Digital Personal Data Protection Act, 2023 (+ Rules, 2025)
The legal thread's anchors, previewed here and taught fully in Session 7: privilege under s.132 BSA is the client's; in-house counsel sit outside s.132 with only s.134's narrower cover; the DPDP Act's fiduciary/processor structure and its penalties are the statutory reason client data never enters a consumer tool. Both verified as recorded in the codebook; DPDP obligations were phasing in as of Aug 2026 — re-check commencement each cohort.
Readings
- Magesh et al., 'Hallucination-Free?' (JELS 2025) — the abstract and Table 1; the numbers behind 'grounded is not true'
- Anvar P.V. v. P.K. Basheer (2014) 10 SCC 473 — re-read the certificate paragraphs; your workspace will be quizzed on them
- Pune Bar Association v. Union of India (SC, 22 May 2026) — the order; five pages, and the reason your bundle needs a date
- In Re: Summoning Advocates, 2025 INSC 1275 — paragraphs on s.132 and in-house counsel (the legal thread's preview; Session 7 completes it)
- NotebookLM help: 'About your notebook sources' — the current limits page, read the week of the session
- Two 2026 follow-ups, abstracts only: Das et al., 'How Much Do Legal RAG Systems Still Hallucinate?' (still pervasive — under 10% for the best, near half for the worst); Schwarcz et al., the first randomised trial on law students (quality up, productivity up 50–130% — the honest positive case)
Sixteen hours, one professional discipline.
Using AI well is not a knack — it is craft, competence and verification, practised until they are habits you could defend in court.