All help topics
Managing documents

Read the audit trail and audit certificate

The Activity tab logs every action on an envelope while it is live. The Certificate of Completion turns that log into a signed record you can hand to a lawyer.

Updated Open in app
The Activity tab of a Document eSign envelope showing the event feed with timestamps and IP addresses

Every envelope keeps its own record. While it is live you read that record on the Activity tab, and once it completes the same history is rendered as a Certificate of Completion you can download, print or send to a lawyer.

Where to find each one

Open a document from Documents and pick the Activity tab. Entries run newest first, each one naming the person, what they did, the date and time in your workspace time zone, and the IP address the action came from.

The Activity tab showing signing events with timestamps and IP addresses

The certificate is a download rather than a screen. It appears as an Audit PDF button once the envelope reaches an end, whether that end is everyone signing, a refusal or a cancellation.

What each entry means

What the feed saysWhat actually happened
sent the envelopeThe signing request left the workspace and the first invitation email went out
openedA recipient loaded the signing page for the first time
agreed to e-signThe signer accepted the electronic record consent before being allowed to sign
requested an OTP / verified OTPA one-time code was emailed to the signer and then entered correctly
signedThat recipient completed and submitted their fields
signed - awaiting othersA signature landed on a document that still needs someone else
finalized the envelopeThe last signature arrived and the sealed copy was produced
sent a reminderA nudge went to a recipient who had not signed, by hand or on schedule
declined to signA recipient refused. Signing stops for everyone at that point
forwarded the requestThe recipient passed their turn to a different person and named them
reassigned to someone elseThe sender moved the signing turn to a different address
updated the documentThe underlying file was changed while the envelope was still a draft
cancelled the envelopeThe sender stopped signing before it completed
envelope expiredThe signing deadline passed with signatures still outstanding

Entries are written as things happen. No screen anywhere in the product edits or removes one, and that is deliberate.

What is inside the certificate

The PDF opens on a cover page titled Certificate of Completion, with the outcome and the completion timestamp under it, then a summary grid:

  • Sender and Organization, so the record names who sent it and from where.
  • Sent on and Completed on, both in the workspace time zone, which is printed alongside them as Time zone.
  • Sign order, reading either Sequential or Parallel, plus a Delivery line when part of the envelope was signed face to face.
  • Signers and Recipients counts, so a reader can tell copy holders from people who actually signed.
  • Document ID and a SHA-256 fingerprint of the sealed file.

After the cover comes one card per recipient. Each carries their role and final status, name and email, an image of the signature they drew or typed, and the timestamps for when the request reached them, when they opened it and when they signed. Down the right edge sits the verification line: Verified by email, Verified by email & PIN when you protected the document with a code, or Signed in person with the host named underneath.

Then the document history, the same events as the on-screen feed laid out as a dated log with the IP address on each row. The last page or two is the electronic record and signature disclosure, the same consent copy the signer read before signing.

What it proves

Three things, in practice. It shows a specific email address was sent the document and opened it, which is the identity link behind most e-signatures and the part the legality rules lean on. It timestamps each step against a stated time zone, so a dispute about "when" has an answer. And the SHA-256 fingerprint ties the certificate to one exact sealed file, so a PDF that has been edited since no longer matches what the certificate describes.

Admins on Growth and above can decide what goes in. Under Settings > Policies you can drop the event log or the legal disclosure from the certificate, and choose whether it is appended to the signed PDF, sent as a separate attachment, or both. See plans and pricing for what your workspace includes.

If something goes wrong

  • The feed is empty. The document is still a draft, and nothing is recorded until you send it.
  • A signer swears they never opened it, but there is an "opened" entry. Some corporate mail scanners follow links before the person does. The timestamps around it usually make the pattern obvious.
  • No IP on an entry. Actions the system performs on its own, an expiry or a scheduled reminder, have no browser behind them and therefore no address.
  • The certificate is missing sections you expected. An admin has switched off the event log or the disclosure in the workspace policies.
  • Timestamps look hours off. They are rendered in the workspace time zone, which an admin sets, not in the reader's local one.
FAQ

Frequently asked questions

What does the "awaiting others" line in the feed mean?

That signer finished their part, but the envelope still needs at least one more signature before it can complete. You will see one of these lines per signer on a multi-party document, then a final entry when the last one lands and the sealed copy is produced.

Why does an entry say System instead of a person's name?

Some things happen without anyone clicking. A deadline passing, an automatic reminder going out, the envelope being finalized after the last signature. Those carry System as the actor because no human triggered them, and they are recorded with a timestamp exactly like the rest.

Is the IP address in the feed reliable proof of location?

It is proof of the network the action came from, not a street address. Mobile networks and company VPNs routinely show an IP hundreds of miles from the person holding the phone. Treat it as one signal among the timestamps, the email verification and the signature itself.

Can anyone change the audit trail after the fact?

No. Entries are written as actions happen and there is no edit or delete control anywhere in the product, for admins included. The certificate also carries a SHA-256 fingerprint of the sealed PDF, so an altered file no longer matches the record.

Does the certificate come with the signed document automatically?

By default it arrives twice over, appended to the end of the signed PDF and sent alongside it as a separate attachment. Workspaces on Growth and above can change that under Settings > Policies, picking append only, attach only, or leaving both switched on as they are.

Why is there no Activity for a draft?

Nothing has happened to it yet. The feed starts filling once you send the envelope, so a draft that has never left your account shows an empty state. Upload and edit actions on a live envelope do get recorded as document updates.

Related

Keep going

Did not find what you needed?Send us a message