Document Signing
Send your MSA, NDA and onboarding paperwork for signature from inside the same system that runs the account — and keep the evidence of who signed what.
The problem
A new client says yes on Thursday. The MSA is a Word file on somebody’s laptop, the NDA came from a template a partner sent in 2019, and the signed PDFs end up in an email thread and a shared drive folder nobody has opened since. Six months later an auditor, or a dispute, asks a simple question — who signed this, on what day, and was it this version of the document? — and the honest answer is that nobody can tell.
What Solidlio does about it
Your contract templates live in Solidlio, versioned, with merge fields that pull the client’s legal name and address straight from their account record. You pick the documents for a client, Solidlio renders them, and the client’s contact gets one link. They read, they sign or they decline with a reason, and no login is involved. Every signature is written with the signer, the timestamp, the originating IP, the browser, and a tamper-evident fingerprint of the exact bytes that were on screen — so any time afterwards you can re-hash the stored file and see whether it still matches.
Capabilities
| Capability | What it does |
|---|---|
| Template library | Store PDF, DOCX and DOC contracts up to 25 MB, or write them in a built-in rich-text editor |
| Starter templates | Copy Tridacom-published MSA, NDA, SOW, SLA, AUP and DPA samples into your library and edit them |
| Version history | Every content save writes a revision with author and note; view any version, restore it as a new one |
| Merge fields | A 20-field catalog across MSP, client, agreement and custom groups; MSP, client and effective-date fields fill from records at build time |
| Document packages | Bundle several documents for one client, send them as a single request, track them as one unit |
| One link per signer | A signer signs every document they were designated for through the single link they were emailed |
| Typed or drawn signature | Capture either; the document hash is computed server-side, never supplied by the browser |
| Decline with a reason | A signer can refuse and say why; the reason is recorded and the package is cancelled |
| Automatic reminders | Two chase emails on your own cadence to every signer still outstanding, then the onboarding tracker flags stalled |
| Expiry and void | Unsigned packages expire on your schedule; cancelling voids every outstanding link immediately |
| Signature tracking | One screen for every package the account has sent, filtered by status |
| Integrity re-check | Re-hash a stored document on demand and compare it against what each signature was bound to |
Built for MSPs and their clients
| Client | MSP | |
|---|---|---|
| Getting the documents | Receives one emailed link; no account, no password | Chooses templates, sends, resends, cancels |
| Signing | Types or draws a signature per document | Cannot sign on the client’s behalf — the token is bound to the signer |
| Refusing | Declines with a reason, which cancels the package | Sees the reason on the package’s audit trail |
| Keeping a copy | Downloads executed copies from their signing link | Downloads originals and executed copies from Signature Tracking |
| Evidence | — | Sees signer, role, method, time, IP, user agent and document hash |
An MSP can send documents to any client organization it owns or services, and a package is visible only inside the account that created it.
How it works
- Build the template. Copy a starter or upload your own. Rich-text templates are edited in Solidlio and versioned on every save.
- Drop in merge fields. MSP company name and address, client company name and address, primary contact, effective date. Fields with no source — payment terms, term length — print as bracketed blanks for a human to complete rather than being guessed.
- Assemble a package. Pick the documents for one client. Solidlio renders each rich-text document into a per-client PDF and stores it privately.
- Send. Each signer gets one link, valid for the window you configured (30 days by default). Sending is refused if any document that needs a signature has no file behind it, so a client never receives a link to something they cannot sign.
- The client responds. They review each document, then sign or decline. A decline needs a reason and cancels the package.
- Solidlio records it. Signer, role, capture method, timestamp, IP, user agent, a tamper-evident fingerprint of the signed document. The executed copy is stored privately and both sides can download it.
- Both sides are told. Every signer gets a confirmation, the staff member who created the package gets a completion notice, and for onboarding packages that were gating portal access the client’s invitation is released automatically.
Audit and evidence
For every package, Signature Tracking reconstructs:
- Who was asked — each designated signer, their role on each document, when they were invited, and whether their link is still live or has been used.
- Who signed — name and email, signer role,
BUILT_INcapture method, typed or drawn, and the exact timestamp. - From where — the originating IP address and the full user-agent string, captured server-side at the moment of signing.
- What they signed — the tamper-evident fingerprint of the document bytes at signing time. Solidlio refuses to record a signature it cannot hash, so there is no such thing as a stored signature with no content binding.
- Whether it still matches — an on-demand re-hash of the stored file. The verdict is matches, changed since signing, or not checkable right now when storage is unreachable; the third is never reported as tampering.
- Who did what on the package — creating, sending, cancelling and resending are written to the platform audit log with actor, IP and user agent, as are template create, edit, delete, restore and PDF generation.
Original and executed documents are stored in private object storage, scoped to the client organization so a tenant erasure request reaches them. They are never exposed as a public URL and are always streamed through an authorized request.
Solidlio does not assert conformance with any electronic-signature statute and does not issue a certificate of completion. Whether a given signature is enforceable in a given jurisdiction is a question for your counsel; what Solidlio provides is the record described above.
Editions
| Capability | Free | Starter | Growth | Scale | Enterprise |
|---|---|---|---|---|---|
| Template library | ● | ● | ● | ● | ● |
| Starter templates | ● | ● | ● | ● | ● |
| Rich-text editor + merge fields | ● | ● | ● | ● | ● |
| Version history | ● | ● | ● | ● | ● |
| Document packages | ● | ● | ● | ● | ● |
| Signing, decline, reminders | ● | ● | ● | ● | ● |
| Signature audit trail | ● | ● | ● | ● | ● |
Document Signing carries no plan gate and no usage cap. Every tier gets all of it.
Contracts signed where the account already lives, with the evidence kept alongside it.