Contracts & signing
Author and send agreements (offer letters, NDAs, MSAs, contractor agreements) for in-app or magic-link signature.
State machine
Side states (off the happy path):

Two delivery modes
In-app signing
/contracts/mine after a notification email with a deep link.Magic-link signing
Same audit trail either way: typed name, IP (redacted prefix), user-agent, body hash SHA-256 of the body at sign time so auditors can prove what was signed.
body_hash matching the contract's body at sign time. The hash is on the PDF's appended audit page — viewers can verify the signature was made against the exact text they're looking at, not a later-edited version.Template library
Built-in
Tenant-owned
Templates use {placeholder} tokens that auto-fill at compose time (recipientName, companyName, todayDate, etc.). Custom tokens become form inputs.
(expires_at − reminder_days_before_expiry) ≤ today and hasn't already been reminded. Bulk-stamps the per- contract last_reminder_sent_at post-send so a re-fire never spams the recipient.Send + Resend dialog — Cc + personal note
Both the "Send for Signature" and "Resend" buttons open a shared dialog with three fields: the recipient (locked to the contract's target), a Cc field that pre-populates from the tenant's Contract email Cc setting (with a "Cc me" chip that appends the caller's own email), and an optional 2000-char personal note rendered as an emerald card above the sign CTA. The note text itself is deliberately NOT persisted — it's transient courtesy text that may carry PII. Audit metadata records the Cc list + hasPersonalNote + personalNoteLength. Auto-reminders deliberately skip Cc + notes (no admin in the loop).