Employee self-service
Documents and signatures
Employee-readable documents and signature actions. Downloads and signing links stay disabled until employee access can prove ownership.
Documents
Employee-readable packets returned by the documents projection.
Downloads
Download links are issued only by the document facade.
Signatures
Employee-safe signature requests returned by the signature facade.
Pending
Open signing tasks exclude provider payloads and raw envelopes.
Documents
Employee-readable packets
Each document row shows packet state, download status, and the safe reason when the action is unavailable.
No employee documents available
No employee documents are shown until scoped employee access is active and document ownership can be proven.
Route contract
Document boundary
The route asks for employee-safe document and signature projections only.
Projection
Access RequiredEmployee-readable documents and signature actions.
Services
No route-local storage or provider SDK calls.
Resources
Only employee-readable packets and signature requests.
Privacy boundary
Employee-safe guardrails
These checks are visible on every employee page so the surface never blurs employee, client, candidate, and internal contexts.
No personal record selected
SafeThe page does not infer an employee from route params, email, or client membership.
No direct lifecycle reads
SafeRoute components consume this page adapter and contract metadata only.
No private internals
SafeInternal notes, client-only commentary, provider payloads, and raw audit rows are outside the employee-safe contract.