Feature

Onboarding paperwork that finishes itself.

The handbook nobody signed. The form the new hire swears they filled out. The certificate that expired in March and nobody noticed until an inspection. HR paperwork doesn't fail because people refuse — it fails because the chase is manual and the filing is somebody's inbox. This is a document library, three ways to complete a document, and a record of exactly what each person saw when they signed it.

01 — The library

Documents with merge fields, categories, and an order

You write a document once, with placeholders. Every employee gets their own filled-in version — name, date of birth, company name, the details that make a template into an agreement.

  • Merge fields, with a cheat-sheetFields are typed into the document body and rendered live as the person reads it. The editor carries a list of what's available, because a merge field nobody can remember the name of is a merge field nobody uses.
  • Scope decides who owes itA document applies to everyone, to a class of worker, to a packet, or to a specific job. “Unsigned” is then a computed list rather than a spreadsheet someone maintains.
  • Packets for day oneBundle the handbook, the policies and the forms into a packet and track progress through it per person. Onboarding stops being a list of separate chases and becomes one completion number.
  • Categories and manual orderingPolicies group into categories and sit in the order you put them in, moved with arrows. The order you hand someone a handbook in is a real editorial decision and alphabetical is not it.

02 — Three ways to complete

Digital, wet ink, or upload a file

Every HR paperwork tool assumes everything can be e-signed. Real files aren't like that — some documents genuinely need a pen, and some aren't documents at all but a copy of a certificate. So completion mode is set per document, and all three land in the same place.

Sign digitally. The employee reads their merged version and signs. Done, filed, timestamped.

Print and wet-ink. The document prints already merged, the employee signs it by hand, and it goes on an “awaiting scan-back” list until somebody uploads the scan — at which point it files against the same record as a real signature marked as a wet one. A paper document becomes a tracked state instead of a hole in the file.

Upload a file. Some requirements are satisfied by a document you don't own: a licence, a certification, a form from somewhere else. That mode collects a file — from the office or from the employee's own phone, where it shows up as “we need a document from you” — and stores it against the requirement with an optional expiry date.

03 — Chasing and proving

Links that expire, snapshots that don't

Hit notify on a document and everyone unsigned in its scope gets an email with their own single-use signing link, good for seven days. No account, no password, no app to install — which is the only version of this that works for a counter associate on a shared family laptop. Employees who use the phone portal see the same outstanding items as a badge on a Docs tab, so the link is a nudge rather than the only route.

Then the part that matters if anything is ever disputed: every signature stores a snapshot of the rendered document body as that person saw it, merge fields already filled. Edit the master document next year and the old signature still shows the old text, because it is not re-rendered — it was captured. There's a viewer that opens any signature and displays that snapshot. “We sent them the handbook” is not evidence. “Here is the page they signed, with their name in it” is.

Write-ups run through the same machinery. A verbal, written or final warning is issued on a form that mirrors the paper one — offence type, corrective plan, consequences — and the employee acknowledges it from their phone via a sign link, recording the name they typed and when. The manager who issued it doesn't have to hunt anybody down for a countersignature in the morning.

And for anything with an expiry date, reminder emails go out at 60, 30 and 7 days. They're ledgered before sending so a retry can't double-send, they fire in the morning in store time rather than whenever a cron happens to wake up, and there's one setting that turns the whole thing off. Expiry-aware compliance also feeds the worker-by-job check used on construction jobs, where “is this person cleared for this site today” is a question with a legal answer.

04 — Questions

Straight answers.

How do you prove what somebody actually signed?

Every signature stores a snapshot of the rendered document body as it appeared to that person, with their merge fields already filled in. Editing the master document later never changes what an existing signature shows. There is a viewer that opens any signature and displays that stored snapshot.

What if a document legally needs a wet signature?

Set that document to wet mode. It prints the merged version for the employee to sign by hand, tracks it as awaiting scan-back, and files the scan against the same record when it comes in — so a paper document is a tracked state rather than a gap in the file.

How do employees get their documents?

Two ways. Their phone portal shows a Docs tab with a badge for anything outstanding, or you hit notify on a document and everyone unsigned in its scope is emailed a single-use signing link that expires in 7 days. No account, no password, no app.

Does it track certificates that expire?

Yes. An uploaded file can carry an expiry date, and reminder emails go out at 60, 30 and 7 days before it. Sends are ledgered before they go so a retry can never double-send, they fire once a day in the morning in store time, and there is a single setting that switches them off.

05 — Next step

Bring your handbook.

Twenty minutes. We'll load a real policy with merge fields, send a signing link to a phone, sign it, and open the stored snapshot of what that phone displayed.

Workforce & ops pricing is quoted per site and headcount — see pricing · no contracts