← All guides
Contents & other guides

People

Letters & e-signature guide

The letters your office issues on its own paper — contracts, offers, warnings, certificates of employment — written once as a template, generated with a person's real values, filed on their record where nobody can quietly edit them afterwards, and where it matters, signed: by staff in their portal, by someone standing at your desk, or by a person outside the company through a private one-time link.

This is the guide HumanR users read inside the product, published as-is. It is written for someone with the screen in front of them, so it describes buttons you cannot click from here — which is rather the point: you can check how the product behaves before you commit to it.

What this module is

Three jobs that are usually three separate products live here as one:

  • A designer — the wording of each letter your company issues, kept in one place instead of in a folder with four versions of the same contract in it.
  • A generator — that letter as a PDF on your letterhead, with a real person's details in it, filed against their record and given a reference number.
  • E-signature — the letter put in front of the people who must sign it, with the evidence of who signed what, when and from where kept alongside the document.
This is a switchable module. Where it is on you will see Letter templates under Admin, Signature requests under Employees, a Generate letter button in the Documents fold of each employee's card, and My signatures in the staff portal. Where it is off, none of it appears and nothing else about the app changes.

Templates & placeholders

Admin › Letter templates is the gallery. Seven templates ship with the app — offer of employment, employment confirmation, the three warning letters, a certificate of employment and a blank custom letter — and you can add your own. Each one is a name, a key (its identifier), a kind, and a body of plain text.

The kind is deliberately coarse: it decides which token vocabulary the letter can bind and which picker offers it — a warning letter is offered on an approved disciplinary case, and everything else on an employee's documents. Wording lives in the body, so a new letter almost never needs a new kind.

  • Plain text, not a word processor. A blank line starts a new paragraph. The only things the app adds are the letterhead at the top, the reference-and-date line under it, and the page-x-of-y footer — the closing ("Yours sincerely", the issuer's name and title) is body text like everything else, because it is wording and wording belongs to you.
  • {{Placeholder}} tokens are replaced with the person's real values when the letter is generated — name, staff number, designation, department, joining date, salary, service period and the rest. The editor lists every token that binds for that kind; a token it does not know renders as nothing rather than printing braces on a legal document.
  • {{Issuer:Name}} and {{Issuer:Title}} are typed at generation, so the same template can be signed off by whoever is issuing it that day.
  • {{Signature:1}}, {{Signature:2}} mark where e-signature parties sign, in signing order. They also decide the signing requirement: a request on this letter asks for exactly as many parties as the body has distinct markers, and HR only says who fills each one.

Preview PDF renders the template against sample values, so you can read the finished page — letterhead and all — before anybody receives it.

Customized, reset & new templates

Shipped templates are maintained by the app: their wording is kept up to date on every start until the first time you edit one. That edit marks the row Customized and freezes it, which is what stops an update overwriting your legal wording. Reset to the shipped default restores the original body and hands maintenance back.

New template adds one of your own — optionally starting from an existing body — and gives it a key derived from the name. Your own templates are never touched by an update.

Delete is only for templates you added, and it is safe: letters already generated from it are untouched, because an issued letter is its own filed PDF and its provenance is recorded as text, not as a link that could dangle. A request still out for signature is safe too. A shipped template cannot be deleted — the app would simply recreate it — so reset it instead.

Letterhead & reference numbers

The letterhead belongs to the company, not to the letters module: a group running several entities issues letters under each one's own identity, so it is set per company from Admin › Reference data › Companies. It holds the logo, the registered name and address block, and the footer line, and it has its own preview — a one-paragraph sample letter on the real letterhead, so whoever sets it up sees the printed result without generating anything. Where you run one entity, set it once; where you run several, the page offers to apply the same block to the others.

Every issued letter also carries a reference number printed on the page — LTR/2026/1234 out of the box, and configurable like the app's other numbering series. A letter's number comes from its own filed record, so numbers are unique and always ascending, but not contiguous: gaps are normal and are not missing letters.

Issuing a letter

Open an employee's card, expand the Documents fold and choose Generate letter. (Two other doors lead to the same place: an approved disciplinary case offers its warning letters, and an offboarding clearance offers the certificate.) The flow is always the same:

  1. Pick the template. The preview shows the letter with this person's real values already in it — nothing is stored yet, so read it and fix the template if the wording is wrong.
  2. Type the issuer name and title that will appear at the foot.
  3. Generate composes the PDF and files it on the person's record.
A filed letter is immutable. It is stored as the exact bytes that were issued, and its remarks carry the provenance — which template, the fingerprint of the template body at that moment, and who generated it. There is no edit: a letter that was wrong is superseded by a new one and both stay on the record. That is what makes it evidence years later.

A letter whose body prints {{Salary}} — the offer and the employment confirmation do — can only be generated by someone cleared to see pay, and the app says so plainly rather than printing a blank where the figure belongs. That is the reason the certificate of employment deliberately carries no salary token: it is routinely issued by people without that clearance.

Certificate of employment

The letter most often asked for at the counter — for a bank, an embassy or a next employer — ships as its own template. It certifies the role, the department and the service period, and that period is a phrase rather than a date pair, so one body reads correctly in both states: "from 12 Mar 2024 to 30 Jun 2026" for someone who has left, "since 12 Mar 2024" for someone still serving. {{Tenure}} is there too if you want the length of service stated outright.

Issue it from the employee's Documents fold like any other letter — or, for a leaver, from the Certificate button on their offboarding clearance, which is where it is actually asked for. A staff member who has left is still offered by the picker on purpose: theirs is the commonest request of all.

Sending it for signature

A filed letter carrying {{Signature:N}} markers shows a sign link on its row in the Documents fold. You name one party per marker, in order, and may set a sign-by date. Each party is either an employee — chosen by staff number, so a typo cannot address the letter to a colleague — or an external signer given by name and email.

The request then travels one party at a time: the second is notified only once the first has signed, which is what makes a countersignature mean what it says.

Employees › Signature requests lists every request, newest first, searchable by signer, employee or letter and filterable by state: In progress, Completed, Declined, Expired or Cancelled. Cancelling withdraws whatever is still pending; signatures already given keep their evidence, because a signature that happened cannot be made not to have happened.

The three signing channels

ChannelWho it is for, and how it works
The portal An employee with a login signs under My signatures in self-service, where they can read the letter first. They see only their own rows.
The desk (kiosk) For staff with no login: you open a full-screen signing page on your own machine and hand it over. The signer enters their staff number, which must be the one the letter was sent to — so the signature lands on their record and not on the account of whoever is signed in at the desk.
An emailed link For anybody outside the company — a counterparty, a guarantor, a candidate. They get a private one-time link, valid 7 days, needing no account and nothing installed. The link is nowhere on any screen: it exists only in that email.

Whichever channel, the signer does the same three things: types their name, draws their signature, and ticks the consent line. The typed name is checked against the party the letter was sent to — parts of a longer name may be left out, but a name that is not theirs is refused, and an emailed link closes for good after 5 failed attempts. Every channel can also decline with a reason: "I will not sign this" is an answer worth recording, and silence is not.

An expired or exhausted link is replaced from the request page with Resend link, which mints a fresh one and kills the old.

The drawn signature is placed on the letter itself, at the marker the template put there — not stapled to a cover page. Until that party signs, their marker prints as a blank pen line with their name under it.

Evidence & verification

Open any request to get its evidence trail: each party, the channel they used, the address a link went to, their typed name and drawn signature, the timestamp, and the device and network they signed from. When the last party signs, the app files a signed document and certificate — the letter with the ink on it, followed by the evidence — as one PDF on the same record, with a reference number of its own.

The fingerprint check is the point. The evidence page re-reads the stored file and compares it against what the parties actually signed, live, every time you open it. A verified fingerprint means the document on file today is byte-for-byte the one that was signed; anything else is flagged rather than quietly accepted.

Candidate offers

The same machinery signs a job offer, except the signer is not an employee yet. Sending an offer from the candidate board generates the offer letter, files it against the application and emails the candidate a one-time signing link — and their signature is the acceptance: the offer turns to Accepted on its own and the Hire button opens. That flow is covered where it belongs, in the Recruitment & onboarding guide.

Permissions & gotchas

  • Communications · Manage — write, add, reset and delete letter templates, and set a company's letterhead. It is the wording every letter goes out in, so it is an admin-level grant.
  • Documents · Manage — generate and file letters, send them for signature, cancel a request, re-issue an external link, run the kiosk.
  • Documents · View — read the signature-request list and the evidence pages.
  • Discipline · Manage — generate the warning letters from a case; those are gated with the case rather than with documents.
  • Sensitive · Pay — generate a letter whose body prints the salary. Sensitive · Personal — open a filed letter from the employee's card.
  • Signers need no permission at all: an employee signs in their own portal, and an external party holds only their link.

Worth remembering

  • The number of {{Signature:N}} markers in the template decides how many parties a request asks for — change the count by editing the letter, not the request.
  • Parties sign in order; the next one is notified only when the previous has signed.
  • A filed letter is never edited — supersede it with a new one and keep both.
  • An emailed link lives 7 days, closes after 5 wrong names, and appears on no screen — resend it if it is lost.
  • Editing a shipped template freezes it against app updates; resetting hands that back.
  • Reference numbers ascend but skip — a gap is not a missing letter.
  • A letterhead change applies to letters issued from then on; ones already filed keep the page they actually went out on.

Questions this guide did not answer?

Ask us directly. We answer product questions in plain language, including the ones where the answer is “not yet”.

No credit card. No sales call required. A real login, emailed to you.