Group Signer in BoldSign: Secure Team-Based Signing with Directories

How BoldSign Decides Who Can Sign When You Use Group Signers
How BoldSign Decides Who Can Sign When You Use Group Signers

Table of Contents

Sign Docs 3x Faster

Send, sign, and manage documents securely and efficiently.

Summarize the blog post with:

TL;DR: Group Signers in BoldSign are controlled using directories attached to Contact Groups. A directory is a simple label that tells BoldSign which groups are allowed to sign for a request. This approach is built for systems where the signing authority belongs to a team instead of an individual, preventing the wrong people from signing and removing the need for custom signer checks in application code. 

BoldSign controls who can sign as a group by enforcing directory‑based rules at runtime.
Group Signers are validated using directories attached to Contact Groups, ensuring only authorized teams and only their members can sign. This prevents incorrect signers, removes fragile UI‑level checks, and keeps group‑based signing secure even as teams and tenants change.

Why group signing breaks

Group signing often starts with a basic idea: send a document to a team and let anyone from that team sign. Over time, this stops working. Teams change, members rotate, and embedded signing flows allow users to choose signers dynamically. When access rules exist only in the UI or application logic, documents can reach the wrong group and be signed by the wrong person.

BoldSign avoids this by enforcing signing rules at runtime. Each Contact Group has a directory, which is a label that tells BoldSign whether the group is allowed to participate in signing. BoldSign checks this label every time a document is sent or signed, so only approved groups and their members are allowed to proceed.

How group signers are checked

When a document is sent using a Group Signer, BoldSign does not assign the document to a specific person. It first validates the Contact Group included in the request.

BoldSign checks whether the Contact Group has at least one directory and whether any of those directories are allowed for the request. If the group fails this check, the API request is rejected and the document is not sent. If the group passes, the document continues without assigning an individual signer yet.

This validation happens every time a document is sent or a template is created using a Group Signer.

Why contact groups without directories are rejected

A Contact Group without a directory cannot be used as a Group Signer.

If a GroupId without a directory is included in an API request, BoldSign rejects the request immediately. No signer is created and no document is sent. This ensures every Group Signer is intentionally scoped and prevents accidental use of unrestricted or legacy contact groups.

What happens at signing time

An individual signer is decided only when the document reaches the signing stage.

At that point, BoldSign looks at the Contact Group linked to the Group Signer and allows only members of that group to sign. Even if someone outside the group gains access to the signing link, they cannot complete the signing action.

This ensures directory checks control not just which groups are valid, but also who can actually sign the document.

How do developers control which groups are allowed?

Developers control which Contact Groups BoldSign can use when sending a document or creating a template by specifying allowed directories.

With this configuration:

  • BoldSign accepts only Contact Groups tagged with the SalesTeam directory.
  • Any request that references a group outside this directory is rejected.
  • Only members of the allowed groups can become the signer at signing time.
Note: In multi‑tenant systems, use UUID v4 values (e.g., 550e8400-e29b-41d4-a716-446655440000) instead of human‑readable names to prevent directory name collisions across tenants. 

What happens in embedded signing workflows?

In embedded signing workflows, users often search for and select signer groups.

When group signer settings are enabled, embedded signing workflows allow users to search for and select eligible signer groups. This prevents accidental signer selection and removes the need for client‑side filtering logic.

How are directories assigned to contact groups?

Directories are assigned when Contact Groups are created or updated using the API. They cannot be managed through the UI, which keeps signer rules centralized and consistent across environments.

Contact group API endpoints

Directories are assigned and managed exclusively through the Contact Groups API:

TaskMethodEndpoint
Create a contact group with directories  POST /v1/contactGroups/create
Update an existing contact group to add directories  PUT /v1/contactGroups/update
Get a list of contact groups with access to the specified account GET /v1/contactGroups/list
Delete a contact group based on the contact group ID provided. DELETE /v1/contactGroups/delete
Get group contact details based on the contact group ID provided.  GET /v1/contactGroups/get

Who is directory‑based group signing designed for?

This behavior is designed for systems where the signing authority belongs to teams, departments, or roles rather than individuals. It works especially well for embedded signing platforms, internal approval workflows, and multi‑tenant applications where users should not see or use every available signer group.

If the rule is that someone from a specific team must sign, BoldSign enforces that rule automatically.

Real‑world use cases for group signers with directories

Below are practical, real‑world use cases that highlight how directories enable and enhance group signing workflows. 

ScenarioHow Group Signing WorksWhy Directories Matter
Department ApprovalsDocuments are sent to a department group so any authorized member can sign on behalf of the team.Ensures only the intended department can sign, blocking other teams completely.
HR Policy Acknowledgements & ComplianceHR sends policies to employee groups for acknowledgement.Prevents non‑HR groups from signing or accessing sensitive policies.
Procurement and Vendor ContractsContracts are routed to procurement or compliance teams for approval.Blocks unrelated departments from signing contracts.
Regional or Branch AuthorizationsDocuments are sent to region‑specific groups for approval.Keeps regions isolated so one branch cannot sign for another.
IT and Security Access RequestsAccess requests are approved by IT or security groups.Ensures only approved technical teams can authorize access.
Multi‑Tenant SaaS WorkflowsEach tenant has its own signing groups within a shared system.Prevents any cross‑tenant visibility or signing.

How BoldSign keeps teams and tenants isolated

BoldSign checks directories for every request.

Only Contact Groups that belong to allowed directories are accepted. Groups outside those directories are fully blocked, and their members can never become signers. This isolation applies even when multiple teams or tenants share the same infrastructure.

Final takeaways: Secure group signers in BoldSign API workflows

BoldSign treats Group Signers as a runtime decision, not a UI shortcut. When a document is sent or signed, the system validates the Contact Group, blocks unauthorized access, and assigns signing rights only to approved group members. This removes the need for user‑level permission logic and keeps group signing workflows reliable as teams and systems change.

Ready to secure group signing with directories? Sign up for a free sandbox account  and explore what BoldSign can do for you.  

Need assistance? Contact our support team via the support portal  or schedule a personalized demo today.  

FAQs

What happens if I try to use a GroupId without a directory? 

The request will fail. A Contact Group must have at least one directory to be used as a Group Signer. 


Can I manage directories through the BoldSign UI? 

No. Directories are managed only via the Contact Groups API. 


How many directories can a Contact Group have? 

Up to 5 Directories per Contact Group. 


Are directories required for all signers? 

No. Directories are required only for Contact Groups used as Group Signers, not for individual signers. 


Why use UUIDs for directories in multi‑tenant systems? 

UUIDs prevent naming collisions that could unintentionally expand access across teams or tenants. 


Do directories affect embedded signer selection? 

Yes. AllowedDirectories strictly controls which Contact Groups appear in embedded selection flows.

Like what you see? Share with a friend.

Latest blog posts

How UCC Consignment Affects Cash Flow and Credit Risk

How UCC Consignment Affects Cash Flow and Credit Risk

Learn how UCC consignment helps manage cash flow, inventory costs, filing requirements, breach exposure, and bankruptcy risk for businesses online today.

How to Fill Out a Vehicle Bill of Sale and Sign Online

How to Fill Out a Vehicle Bill of Sale and Sign Online

Fill out a vehicle bill of sale, avoid VIN and odometer mistakes, & collect secure online signatures with an audit trail for both parties. Start signing today.

The Future of Joint Venture Agreements: Governance, Compliance, and Digital Transformation

The Future of Joint Venture Agreements: Governance, Compliance, and Digital Transformation

Explore how AI, blockchain, smart contracts, and digital governance are transforming joint venture agreements through better compliance and collaboration.

Sign up for your free trial today!

  • Yes
    30-day free trial
  • Yes
    No credit card required
  • Yes
    30-day free trial
  • Yes
    No credit card required
Sign up for BoldSign free trial