Document Vault

Signed, sealed, delivered, It's yours!

Document Vault is a separate platform capability for collecting, storing, signing and governing employee documents across all of CapoFine's products.

Document Vault within the CapoFine Platform
CapoFinePlatform
Super secure Fort Nox VaultDocument VaultSeparate infrastructure and security boundary
HireRecruitment workflows
OnboardEmployee journeys
GrowLearning workflows

Authorised document access across all three products

One document record

Keep the document connected as the employee journey continues.

Hire, Onboard and Grow can request documents and signing workflows without maintaining separate document stores or signing systems. Each product owns its workflow. Document Vault owns the document, its state and its evidence.

Employment agreementCanonical document recordOne controlled record across the employee journey
Creator and originCurrent stateImmutable versionsSigner and identity evidencePermissionsComplete event history
HireOnboardGrow

Signing belongs to the Vault

One signing process, available to every product.

Document Vault controls the exact version presented for signing, the signer and assurance route, the resulting signed artifact and the complete evidence trail.

  1. CreatedTemplate, source and creator recorded
  2. ReadyExact version approved for signing
  3. SigningSigner and assurance route bound
  4. SignedSigned artifact and evidence preserved
  5. StoredImmutable record available by permission
Hire
Offer letter

Signed offer saved to the canonical candidate record

Onboard
NDA

Identity-verified signing evidence kept separately

Grow
Certificate

Programmatically signed and stored with the learner record

Origin-to-end historyEvery state change stays attached to the record.

Creator, requesting product, approver, signer, identity-assurance route, timestamps, exact version, signed artifact and later access remain visible according to permission.

Standard electronic signing, identity-verified signing, cosigners and signing order follow the configured document workflow and selected signing method.

Secure from upload

Inspect files before they enter trusted storage.

Every upload enters an isolated quarantine path first. Only files that pass the required security and policy checks are accepted into the Vault.

A controlled path into trusted storage
  1. UploadFile received
  2. QuarantineIsolated from trusted storage
  3. InspectionPolicy and security checks
  4. VaultAccepted into trusted storage

Inspection can cover malware, suspicious content, unsupported file structures, file integrity and organisation policy.

Separate by design

Keep employee documents apart from ordinary product data.

CapoFine products request authorised access through the platform document layer. They do not need direct access to the underlying object storage, signing-provider infrastructure or identity-verification systems.

Dedicated infrastructure

Document files are stored on infrastructure separated from recruiting, onboarding, learning and general employee application data.

Controlled transactions

Server-side authorisation, short-lived access and authenticated platform services control how documents are viewed or used.

Residency boundaries

Entity-level jurisdiction choices can govern application servers, stored data and backups according to package and implementation scope.

Document governance

Control the record, not only the file.

Versions, approvals, signatures and access history remain connected to the exact document involved.

Immutable versions

A new version does not erase the previous one. Signed artifacts remain distinct from the source version presented for signing.

Granular access

Separate capabilities can govern viewing, downloading, uploading, reviewing, approving, exporting and access to signing evidence.

Traceable evidence

Relevant records can identify the creator, signer, purpose, timestamp, origin, version, file hash, event identifier and evidence supplied by the signing method.

Signing routes

Document workflows can support wet-ink, in-person and provider-supported electronic signing routes, with availability determined by configuration and package.

Document workflows

Request, review, approve and sign in the right context.

Document work can stay attached to the candidate or employee journey while the Vault maintains the controlled record underneath.

  1. 01Request or prepare

    Collect an employee upload or create a company document.

  2. 02Review and approve

    Route the document through the organisation's configured owners.

  3. 03Sign where required

    Lock the exact version and preserve the resulting artifact and evidence.

  4. 04Continue the journey

    Use authorised status or document facts in the relevant CapoFine workflow.

Templates, generated documents, structured document facts, approval workflows, multiple signers and identity-verified signing depend on configuration and rollout.

Templates and deterministic facts

Generate documents once, then use approved facts across the journey.

Templates combine controlled wording with static organisation values and deterministic employee or workflow values. The finished document remains authoritative while selected facts can be made available to authorised workflows.

Controlled template

Employment agreement

  • Approved legal text
  • Legal entity and signatories
  • Role and employee values
  • Versioned template source
Deterministic document facts
Start date
1 September 2026
End of probation
1 December 2026
Job title
Compliance Analyst
Employment type
Permanent
Authorised product event

Onboard schedules the journey

The start date and end of probation can schedule relevant journey moments without copying or reinterpreting the source document.

Document facts come from defined template fields or deterministic processing. They keep their source and provenance and do not replace the original document.

Document Vault security review

Map your document workflows and controls.

Bring your document types, access model, signing requirements and residency needs. We will separate current core capabilities from configuration-dependent workflow options.