User guide › Apps › Contracts & e-sign
Two different things called "signature"
Read this first — picking the wrong one wastes an afternoon.
| You want | Use | Where |
|---|---|---|
| Send a document out to someone outside your workspace and have them sign it | The Contracts app — an envelope with recipients, placed fields and a signing link | This page |
| Capture a scribbled signature on a record — a delivery slip, a sign-off box on a job sheet | The signature field type on an entity | Building your workspace |
The field type draws a signature straight onto one record and stores it as an image. There's no recipient, no link, no audit chain, no certificate. It's the right tool for a courier signing on a phone; it is not the tool for a contract. Everything below is the app.
One thing to sign is one envelope — the document, the people who
have to sign it, where each of them signs, and the record of what happened.
Everything lives at /esign, under Contracts in the menu.
The list has two tabs: Documents and Templates.
Preparing a document
New document asks for a Document title and then gives you three ways to get a document in.
| Start from | When |
|---|---|
| Upload a PDF | The contract already exists as a PDF. "Sign an existing PDF document." |
| Upload Word (.docx) | You have a Word file. It's imported so you can edit it in-app, then sign. |
| Write a document | You're drafting from scratch. Type it in the editor — headings, paragraphs and lists become a formatted PDF when you press Generate document. |
Written and imported documents stay editable: Edit text reopens the text and regenerates the PDF. Every edit snapshots the previous state into Version history, where you can read an earlier version and restore it — restoring snapshots the current document first, so nothing is lost either way.
If you try to upload something that isn't a PDF or a .docx, the app says Only PDF files can be signed. Convert it first, or paste the text into Write a document.
Adding recipients
Open the document and use Add recipient in the Recipients panel. Each recipient carries:
- Full name — appears on the signing page and in the certificate.
- Email, or Phone (for SMS / WhatsApp) — whichever channel you pick needs its own contact detail filled in.
- Channel — Email, SMS or WhatsApp. This is how their signing link is delivered.
- Role (optional) — a label like Client or Witness, useful on templates.
- A signing-order number, shown as #1, #2 and so on.
+ Add me puts you in the list as a signer — that's the counter-sign case, where you sign your own contract too. Once the document is out, your own row gets a Sign now button so you can sign in-app without going through a link.
Removing a recipient warns you first: Remove this recipient? Their placed fields will be unassigned. The boxes stay on the page but belong to nobody until you reassign them.
Signing order
An envelope routes one of two ways.
| Routing | What happens |
|---|---|
| Sequential (the default) | Only the current order group is notified. When they've all signed, the next group gets its links. Someone whose turn hasn't come yet and who opens their link early sees Not your turn yet. |
| Parallel | Everyone is notified at once and can sign in any order. |
The order number is what makes sequential routing work. Give two recipients the same number and they're one group — they get their links together. Give them #1 and #2 and the second one waits for the first.
Placing fields
A recipient with no fields has nothing to fill in, so this step isn't optional. The Place fields panel walks you through it:
- Pick who you're placing for Select a recipient above, then drop fields for them. Each recipient gets their own colour so you can see at a glance whose boxes are whose.
- Pick a field kind Pick a field, then click the page to place it. Five kinds are available: signature, initial, date, text and checkbox.
- Click where it goes Click the page to place the field. Drop it on the right page, in the right spot. Repeat for every place that person has to touch. The counter shows how many are placed.
Fields can be marked required. A recipient can't finish until every required field of theirs is filled — the signing page tells them Please complete all required fields.
Sending it out
Send for signature dispatches the envelope. If the button is disabled the hint says why: Add at least one recipient and one field first.
On send, each recipient in the active group gets their own unguessable signing link over their chosen channel, and the source PDF is fingerprinted so any later change to it is detectable. The status moves from Draft to Out for signature.
After sending you'll see one of two messages. The good one: Sent — recipients were emailed their signing link. You can also copy each link below. The other: Sent, but workspace email isn't connected — recipients were NOT emailed. Copy each signing link below and share it manually. In that case use Copy signing link under Signing links and send each one yourself. Connecting mail is covered in Integrations.
Copy signing link is also useful when someone says they never got the email — you can paste their link into a chat rather than re-sending. Each link is tied to one recipient; don't hand recipient #1's link to recipient #2.
Sending the same document to many people
Open a draft and use Save as template to park it under the Templates tab. Use makes a fresh copy — document, recipient roles and field placements all come across — for one-off sends.
Bulk send fans a template out instead: paste one recipient per line as Name <email>, Name, email, or just an email address. Each person gets their own separate copy to sign, not a shared one. The app tells you how many valid recipients it found before you commit, and confirms with Sent to N recipient(s).
What the signer sees
The link opens a page at /sign/<workspace>/<token>. There is no
login and no account — the token in the link is the credential. The page shows the
document with only that person's fields highlighted:
Sign here, Initial, Date, Type here.
- They read the document The whole PDF renders in the browser, scrollable, on phone or desktop.
- They fill their fields Tapping a signature box opens a pad — Add your signature / Add your initials — where they draw with a finger or mouse. Date, text and checkbox fields are filled inline.
- They tick the consent box A checkbox in the footer states they agree to sign electronically. It is mandatory: without it the app answers Please accept the consent checkbox.
- Finish & Sign The button stays disabled until consent is ticked and every required field is filled. After submitting they see Thank you. All parties will receive a copy once everyone has signed.
Signers can also Decline. They're offered a reason — Optionally tell us why you're declining — and the envelope halts at Declined. Nobody further down the order is asked to sign.
The signing page carries two more things a signer can do without signing: Comments & questions lets them ask something and notifies you, and on documents you authored in-app Suggest edits lets them mark up the text. Their edits come back tracked and attributed rather than applied.
Messages a signer may hit instead of the document: This signing link is invalid. · This signing request has expired. · Not your turn yet (with You'll be emailed when it's your turn to sign.) · You have already signed this document. · This document was cancelled by the sender.
Negotiating before you sign
For documents written in-app, Track changes is a Word-style suggesting mode: Edit inline — your changes are tracked (insertions underlined, deletions struck) and attributed. Accept or reject each, then Apply to update the document. When the other side has sent suggestions back, a banner reads Proposed changes are pending in this document and Review changes opens them.
Sending is blocked until every tracked change is accepted or rejected: Resolve all tracked changes before sending — open Track changes and accept/reject each. Same for Apply to document — it only enables at zero remaining changes. This is deliberate: the thing people sign is always clean text, never a marked-up draft.
Accept/reject only works on a draft. If suggestions arrive on a document that's already out for signature, use Correct first — Revert to draft so you can edit and re-send (only before anyone signs). It warns that the current signing links will stop working, which is the point: the old links can't sign the new text.
Comments are the internal side of the same conversation. Each comment is Private (Internal — only your team can see this) or Public (Visible to the signer / customer), so you can argue about price in the same thread the client is reading, without them seeing it.
Statuses
| Document status | Means |
|---|---|
| Draft | Being prepared. Editable, deletable, nothing sent. |
| Out for signature | Sent; at least one recipient still hasn't signed. |
| Completed | Everyone signed. The signed PDF and certificate exist. |
| Declined | A recipient refused. Halted. |
| Voided | You cancelled it. |
| Expired | It passed its expiry date before everyone signed. |
Each recipient carries their own status inside the document:
| Recipient status | Means |
|---|---|
| Waiting | Not notified yet — their turn hasn't come in a sequential envelope. |
| Sent | Their invitation went out; the link is live. |
| Viewed | They opened the signing page. |
| Signed | They completed all their required fields. |
| Declined | They refused. |
Viewed versus Sent is the useful distinction when chasing: it tells you whether the delivery failed or the person is simply sitting on it.
Chasing, correcting, cancelling
- Remind — re-sends the signing link to whoever is currently holding things up. A document can also carry a reminder cadence so it nudges on its own.
- Correct — reverts a sent document to draft so you can fix a typo, move a field or swap a recipient, then re-send. Only before anyone has signed, and it kills the existing links.
- Void — kills the envelope for good. It confirms first: Cancel this envelope? No further signatures will be accepted. There's no un-void; the record stays, marked Voided.
- Delete — only for drafts, and it warns Delete this draft document? This cannot be undone.
Once a document has gone out, voiding is the way to stop it. That keeps the trail of who was asked, who opened it and when it was cancelled. Deleting is reserved for drafts that never left the building.
What happens when the last person signs
The moment the final recipient submits, the app does all of this automatically:
- The fields are burned into the PDF Every signature, initial, date, text entry and checkbox is drawn permanently onto the document. Drawn signatures are embedded as images at the exact spot they were placed. The result is a flat, finished PDF.
- A Certificate of Completion is generated A separate PDF with three sections — Document integrity, Signers and Audit trail.
- The audit chain is sealed The event history is closed off and its final hash stored on the document.
- Everyone gets a copy All parties are emailed a link to download the signed document.
The document flips to Completed and locks. Two buttons appear on it: Download signed for the finished PDF, and Certificate for the completion certificate. That's where completed documents live — in the Documents list, permanently, with both files attached. There's nothing to file elsewhere.
The audit trail
Every envelope keeps an append-only record of what happened to it: created, sent, reminded, viewed, each field filled, signed, declined, completed, voided, expired, corrected. Each entry stores who acted, when, and the network address and browser they acted from. Entries are hash-chained to each other, so an entry cannot be altered, removed or back-dated without breaking the chain.
The document shows this as Tamper-evident audit chain with a verdict of Verified or Tampered. The same history is printed into the Certificate of Completion alongside the signer identities and the document fingerprint.
This describes what the software records and stores. Whether an electronic signature is sufficient for a particular contract, in a particular jurisdiction, is a legal question — ask your lawyer, not your ERP.
Signing as a step in something bigger
Signature requests don't have to start from the Contracts screen. Two actions are available to automations, journeys and approval steps:
- Request signature — takes a PDF already attached to a record and sends it out.
- Send contract — renders a rich-text field on a record into a PDF and sends that.
So "when this deal reaches Won, send the client the agreement" is a rule, not a person remembering. Building rules like that is covered in Automations & logic.
Installing the app also seeds a Contracts entity — a normal table with Title, Body, Counterparty, Email and Status. Drafting there gets you the full record experience (comments, versions, presence, other people editing alongside you), and Send contract is the bridge from that draft to a signature request.
Who can do what
Access to the app lets a member draft and view documents. Two further capabilities are granted per role under Settings → Module Access; admins pass everything.
| Capability | Unlocks |
|---|---|
| Send for signature | Sending, reminding, correcting and bulk-sending. Without it a member can draft and view but not dispatch. |
| Void envelopes | Cancelling documents that are already out for signature — deliberately separate, because it's higher-stakes than sending. |
The useful split is a junior who prepares documents and a manager who sends them. Grant app access widely and Send for signature narrowly. Background on how the two permission layers stack is in Permissions & access.
When something goes wrong
| What you see | What it means |
|---|---|
| Send for signature is greyed out | Add at least one recipient and one field first. An envelope with nobody to sign it, or nowhere to sign, can't go anywhere. |
| Send is blocked with a tracked-changes message | The document still has unresolved insertions or deletions. Open Track changes and accept or reject each one. |
| Sent, but workspace email isn't connected | Nothing was emailed. Copy each signing link and share it yourself, then connect mail — see Integrations. |
| The signer says the link is invalid | Either it's the wrong link, or the document was corrected or voided since — both invalidate old links. Copy the current one from Signing links. |
| A recipient sees Not your turn yet | Sequential routing, and someone ahead of them hasn't signed. They'll be emailed when it's their turn. Give them the same order number as the earlier signer if they should have gone together. |
| Only PDF files can be signed. | The file you picked isn't a PDF. Use the Word import, or write the document in-app. |
| The audit chain reads Tampered | The stored history doesn't match its own hashes. Don't rely on that document — raise it. |
WhatsApp is offered as a channel, but invitations on it are currently delivered by email instead. If a recipient has to be reached on WhatsApp, use Copy signing link and send it to them yourself.