Finance
Review and complete an agreement signing envelope
Product documentation · Reviewed
Named signing invitations let each client respond to the same frozen proposal or contract. An optional business countersignature completes the document after all clients finish. Existing single-signer records stay readable and retain their original hashes.
Prepare the document and signers
Open a project's Money → Contracts & proposals → Manage signers & document history. Edit the document before issuing it. Choose one to eight named client signers, each with a separate private link. You can also assign one active workspace operator as the business countersigner. Its email must match that member's verified workspace account.
Every signer has one signature field. Add initials fields where needed, assign each to a signer and include the exact clause they must initial. Choose a signing deadline in UTC, then save the configuration. Saving disables the older single-signature form on the shared couple page. Review the exact document, names, emails, fields, deadline and billing effect before issuing invitations.
Issuing freezes the terms and signing setup. Copy each private link from the confirmation panel and send it to its intended signer through your chosen channel. Copy invitation / reminder draft prepares text only; no message is sent automatically. Links are not retained in readable form. If an unsigned client loses a link, replace it with a reason; the previous link immediately stops working. Revoking a link closes that client's access without deleting the document.
Respond and complete
Each signer reviews the document and their assigned fields. They may type their full signer name or draw a signature, add any required initials and explicitly confirm the electronic-record consent. A keyboard-accessible typed alternative is always available. The assigned name and email must match the invitation.
Clients can respond in parallel. A business countersigner must sign in to the assigned workspace account and wait until every client finishes. Invoices and the final execution record are created only when all required signers complete. Signing-relative payment dates resolve at that final completion time. If a proposal requests a deposit, the booking is confirmed after the deposit is recorded as paid.
Client names and emails are self-declared by the holder of the private invitation. The invitation does not independently verify identity. An open signal records that the document was opened; it is not proof that it was read or accepted. This feature does not make claims about a document's legal sufficiency or offer legal advice.
A client may decline with a reason. This closes the other signing invitations and preserves earlier responses without marking the document executed. Expired invitations reject new responses immediately, even if the background expiry job has not run yet.
If a request is interrupted, leave its details unchanged and use Check original response or Check original request. The retry resolves that exact saved operation; it does not create another signature, deposit or installment schedule.
Void and reissue
An issued document cannot be edited in place. Mark document void closes signing and retains prior responses and execution records. Create replacement additionally makes a separate editable document and links it to the old version. Earlier signatures never transfer to the replacement.
These actions do not cancel invoices, refund settled money or revoke automatic payment authorizations. Review those separately in Finance. When a predecessor has existing billing, the replacement must keep its monetary terms, prices and payment schedule unchanged. Its execution creates no duplicate deposit or installment invoices. New monetary terms require a separately reviewed proposal and explicit handling of old billing.
Retain records
The owner can download the document, signing responses and activity as JSON. Once all required signers finish, every active signer link can download the complete immutable execution record with its SHA-256 hash. This jointly executed record includes every signer's name, email and signature or initials; the earlier invitation view shows only the current signer's email. Private workspace identity IDs and request metadata stay in the owner's audit trail. A later void decision is reported separately from the unchanged signed document. The print view supports saving a local PDF; it is not a provider-stamped archival certificate.
Reviewed automatic reminders, completed-record email copies and executed PDF downloads are described below. Independent identity verification, notarization and arbitrary uploaded-PDF field placement remain outside this signing workflow. Provider activation and outbound messaging rehearsal remain coordinated launch work.
Export and check a retained record
Open Export activity (CSV) on the agreement to download ordered lifecycle events, actor references, document and request hashes, and the original event detail/result JSON. Spreadsheet formula prefixes are escaped. The export checks current workspace access and contains up to 10,000 events; larger histories require a support archive.
Use Verify a retained record to select the executed JSON export and compare its canonical signed-record SHA-256 on your own device. The document is never uploaded. Paste a separately retained hash for an independent comparison; the embedded hash alone only checks consistency within the file. A match does not establish signer identity, legal validity, current void/reissue status or the bytes of a printed PDF.
Schedule reminders and deliver completed copies
Open the agreement’s Reminders and completed copies section. Review every named recipient and approve an automatic delivery policy. Choose up to six distinct day offsets after issuance, from day 0 through day 90. Day 0 can deliver the initial signing invitation. When several offsets are already due, the worker queues only the latest one, rather than sending a backlog.
A client reminder stops when that signer signs or declines, their current link is revoked or replaced, the envelope expires or is voided, the policy is paused, the authorizing operator loses access, or a booking-experience step is no longer current. Business countersignature reminders wait until all client signers finish. Queued messages are checked against current recipient, policy, document and access again immediately before sending.
After the final required signature, an approved completed-copy policy emails each named signer the same retained PDF, including the original signed JSON as an embedded attachment. It does not send an incomplete record. Later void or reissue decisions remain separate; the original file is never rewritten to pretend the earlier signature did not occur. A revoked client invitation stops new automated copies. Copies already delivered cannot be recalled.
Delivery remains gated by coordinated Resend sender/webhook setup, the worker and the agreementDelivery deployment feature. Reminder links are encrypted with the integration key when an invitation is issued or rotated. Earlier invitations and booking-experience links can be pasted into Retain verified link for reminders after setup; the service verifies the exact current recipient and token generation. Completed-copy attachment delivery can operate without a retained link, while reminders require one.
The delivery history distinguishes queued work, provider acceptance, confirmed provider delivery, failures and superseded work. Signed provider callbacks may arrive before the send response; the original provider identity is retained. Unknown attempts retry only within 23 hours of their first recorded attempt, under the same provider idempotency key. A changed sending account or elapsed safe retry window requires reconciliation of the original request. Do not create a new request to work around an uncertain delivery.
Download an executed PDF
After everyone signs, choose Download executed PDF from the private signer page or the agreement management screen. The renderer uses the original hash-verified signed snapshot, including typed/drawn signatures, initials, consent, signers, agreed amounts and retained installment dates. It embeds signed-agreement.json so the original record remains available for independent verification. The PDF is a rendered record, not a certificate-based digital signature.
During development before private storage activation, downloads render from the retained signed snapshot. They are clearly distinguished from an archived PDF. After storage activation, the first PDF is stored once through a recoverable artifact intent pinned to the original signature hash and renderer version. Subsequent downloads read the stored bytes and verify their checksum. General file deletion cannot remove these archived executed PDFs. Authorization is checked again after preparing or fetching a download; only the active business or a current authorized signer link can retrieve it.
A PDF over 14 MB is held from automatic email delivery; use the authorized download. Unsupported characters in the installed document font fail visibly rather than changing signed text. The original JSON export remains available. Real email delivery, callback ordering, private storage recovery and retention require the combined integration rehearsal before launch.