Each transaction during the document signing process is securely stored. Once a document is completed, this log is translated into an Audit Trail and attached to your final PDF. You can also access the Audit Trail for any completed document by navigating to your Completed Documents list and clicking Audit Trail from the actions menu on the right.

About IP Addresses in the Audit Log
You may notice unfamiliar IP addresses in your audit log. This can happen because some email clients include virus scanners that automatically open links in emails to scan for malware. If a scanner opens the signing link, it will appear in the audit log as a "document viewed" entry with the scanner's IP address rather than the signer's.
Tip: To prevent unknown IP addresses in the Audit Trail, enable the Signer Authentication feature. This restricts access to the document until the authentication code is entered, ensuring only the intended signer can open it.
Audit Log Event Types
Document creation events
- document created - Occurs every time a document is created.
- document sent - Occurs every time a document is sent to a signer. Created once per signer, even if the signer is the document owner.
- signer authentication - Occurs when signer authentication via SMS is enabled for a signer.
Signer-triggered events
- document viewed - Occurs when the document is viewed by a signer.
- document signed - Occurs when a signer signs the document. If this was the last required signer, this is followed by "document completed."
- document declined - Occurs when a signer declines to sign. An optional decline reason may be stored. This is followed by "document cancelled."
- signer bounced - Occurs when email delivery fails for a signer. This is followed by "document cancelled."
- signer removed - Occurs when a signer is removed from the signer list (only possible if the document has optional signers). If all signers are removed, this is followed by "document cancelled."
- document forwarded - Occurs when a signer forwards the document to another person for signing. Includes the name and email of the new signer, and optionally a forwarding reason. This is followed by a "document sent" log for the new signer. Note: Forwarding is not available when 2FA is enabled.
Team member-triggered events
- signer removed - Occurs when a team member with sufficient permissions removes a signer from the list.
- document revoked - Occurs when the document is cancelled by the owner or a team member with cancellation privileges. This is followed by "document cancelled."
System-triggered events
- document expired - Occurs automatically if the document is not completed within the expiry time frame.
Document end-state events
- document completed - Occurs when the document is successfully completed by all required signers.
- document cancelled - Occurs when the document is cancelled for any reason.
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article