# Configure SignPlus

SignPlus has two settings screens. A site administrator sets the defaults, and decides setting by
setting whether a space may change it. A space administrator then changes only what the site has
left open.

| Screen | Where | Who | Tabs |
|---|---|---|---|
| **SignPlus global configuration** | Confluence **Settings**, at the bottom of the menu under **Apps** | Confluence administrators | Dokobit settings, App settings, Dokobit token, Export styling, API access, Webhooks, Logs, Help |
| **SignPlus space configuration** | **Space settings**, under **Integrations** | Space administrators | Dokobit settings, App settings, Export styling, Help |

Each tab groups its settings into sections that open one at a time. **A change saves as soon as
you make it**, and a **Settings saved** message names the setting. Export styling is the
exception: it has its own **Save export styling** button, because a document's look is several
settings that belong together.

## Before the first real signing

<Steps
  items={[
    {
      title: 'Choose the signing mode',
      body: 'Dokobit token, then Signing mode. A new installation is on Test, which produces watermarked documents with no legal effect.',
    },
    {
      title: 'Check the Dokobit settings',
      body: 'Signature level, the formats a signing may use and the signing methods on offer.',
    },
    {
      title: 'Decide what each space may change',
      body: 'Every setting on Dokobit settings and App settings has a switch under Spaces may change.',
    },
    {
      title: 'Style the exported document',
      body: 'Export styling. At the least, put your logo on the first page or in the header.',
    },
  ]}
/>

## Signing mode

**Dokobit token**, then **Signing mode**. It decides which Dokobit environment every signing on
the site goes to, and only a site administrator can set it.

| Mode | Signs on | What to know |
|---|---|---|
| **Test** | Oktul's account in Dokobit's test environment | The default, and the way to try SignPlus before you have a Dokobit account. Documents come back watermarked by Dokobit, can only be signed with Dokobit's test identities, and are not legally binding |
| **Your own token** | Your own Dokobit account | The only way to sign for real. Enter the API token from your Dokobit account. Your volume and price are agreed with Dokobit, and invitation emails can be styled in your Dokobit account |

A token you enter is stored encrypted in Forge's secret storage and is never shown again.
Oktul does not provide production signing: a legally binding signature is always made on your
own Dokobit account.

<Aside type="caution" title="Test mode produces documents that look signed">
Everything signed while Test is active carries Dokobit's watermark and has no legal effect. The
mode starts on Test so that a site nobody has configured cannot produce a document that looks
binding. Change it before the first real signing.
</Aside>

## What a space may change

Every setting on **Dokobit settings** and **App settings** has its own switch in the **Spaces may
change** column: *Let each space set this for itself*. Leave it off and the setting reads **Set
for the whole site** on every space's screen. Turn it on and a space administrator can choose a
different value for their space.

Every signing is checked against its space's settings when it starts, whichever way it was
started: from the page, from an automation rule or through the REST API. A rule or an
integration cannot ask for something the space has ruled out.

## Dokobit settings

What Dokobit asks of a signer and how the signed file is produced. Defaults in bold.

### Signatures

| Setting | Options |
|---|---|
| **E-signature levels** | **QES only**, or QES and AdES |
| **Disabled signing methods** | **None**, or any of the methods Dokobit offers: Mobile SK, Mobile Audkenni, Smart-ID, Smart card, eParaksts Mobile, BankID (Norway), BankID (Sweden), Audkenni App, FTN, MitID, Electronic ID, itsme, iDIN, Swisscom, SMS OTP and NBID |
| **Signing with video identification** | **Disabled**, or Enabled |

QES is a qualified electronic signature, which eIDAS gives the same legal effect as a handwritten
one. AdES is an advanced electronic signature, a lower level.

### Document format

| Setting | Options |
|---|---|
| **Document formats** | Which formats a signing may use: **ASiC-E** and **PDF**, plus BDoc, EDoc, ADoc BeDOC and ADoc CeDOC |
| **Default document format** | **ASiC-E** |

ASiC-E keeps the PDF and its signatures together in one container, the `.asice` file the Estonian
DigiDoc4 client opens. A PDF carries the signatures inside the PDF itself.

### Signature annotation

What Dokobit stamps onto a signed PDF. It applies to the PDF format only.

| Setting | Options |
|---|---|
| **Annotation position (PDF only)** | **First page (top)**, first page (bottom), last page (top), last page (bottom), or no annotation |
| **Personal code in the annotation (PDF only)** | **Not visible**, or Visible |

## App settings

What the person starting a signing sees, and what happens to the page. Defaults in bold.

Several settings take one of three values. **Can be selected** leaves the choice to the person
starting the signing. **Always** and **Never** decide it for them, and the signing form then says
what will happen under **While this signing runs** instead of offering a switch.

### Deadlines

| Setting | Options |
|---|---|
| **Signing deadline** | **Optional**, Required or Disabled. Participants who have not signed get one email reminder 24 hours before the deadline |
| **Strict deadline** | **Can be selected**, Always or Never. When strict, the document cannot be signed after the deadline |

### The page while it is signed

| Setting | Options |
|---|---|
| **Make page read-only** | **Can be selected**, Always or Never. Only SignPlus can edit the page once the signing starts |
| **Restrict page viewing to signers and viewers** | **Can be selected**, Always or Never. Only the person who started it and the people added to it can open the page while it runs |

The two restrictions end at different times, on purpose. **A declined signing lifts both.** **A
completed signing lifts the viewing restriction and keeps the edit lock**, because the lock is
there so that what people signed cannot change. A space administrator can always remove either
by hand. See [what happens to the page](../after-signing/#what-happens-to-the-page).

### What goes in the document

| Setting | Options |
|---|---|
| **Let space administrators style exported documents** | **Disabled**, or Enabled. The master switch for the space overrides described in [export styling](../export-styling/#what-a-space-may-change) |
| **Include attachments** | **Can be selected**, Always or Never. When the choice is left open, the signing form offers it switched on |

### Dates and times

| Setting | Options |
|---|---|
| **Date and time format** | **Confluence default**, which follows each reader's own Confluence language, or a specific language and country |
| **First day of the week** | **Monday**, or any other day |

### The signing form

| Setting | Options |
|---|---|
| **Add the initiator as a viewer automatically** | **Enabled**, or Disabled. The person who starts a signing is then told when it completes |
| **Message to signers** | **Optional**, Required or Disabled. The message goes in Dokobit's invitation email |
| **Default message** | The text the message starts with. `{{initiator}}` inserts the name of the person who started the signing |

### Deleting signings

| Setting | Options |
|---|---|
| **Who else can delete a finished signing** | **Empty**, or any of: Space administrators, People who can edit the page, The person who started the signing |

A finished signing's record is what says the page was signed and whether it has changed since, so
by default **only a Confluence administrator can delete one**. This setting widens that, and it is
decided for the whole site: no space can change it, and it does not appear on a space's screen.

Cancelling a signing that is still running is a different act with its own rule: the person who
started it, or anyone who can edit the page. See
[cancelling or deleting a signing](../after-signing/#cancelling-or-deleting-a-signing).

## The other tabs

- **Export styling:** the typeface, page, first page, header and footer of every exported
  document. See [style the exported document](../export-styling/).
- **API access:** the address the REST API answers on for this site, how to get a credential, and
  a reference of every endpoint. See [REST API](../rest-api/).
- **Webhooks:** where to send a notification when a signing completes or a signed page is edited.
  See [automation and webhooks](../automation/#webhooks).
- **Logs:** every REST API request, every notification SignPlus sent onwards and every automation
  action on this site, newest first, with the credential and the account it acted as and the
  outcome. Never a token. The most recent 500 entries are kept.
- **Help:** links to this documentation, to the Help Center and to oktul.com.

<Aside type="note" title="When Jira is not connected">
SignPlus installs into Confluence. Until Jira is connected to it, the top of the global screen
says so and links to Atlassian Administration. See [connecting Jira](../install/#connecting-jira).
</Aside>

## Related

- [Sign a page](../sign-a-page/)
- [Style the exported document](../export-styling/)
- [Install the app](../install/)

---

A problem or a question? Write to [support@oktul.com](mailto:support@oktul.com) or open a request in the [Help Center](https://oktul.atlassian.net/servicedesk/customer/portals). Both reach the same service desk, so either way the request gets a reference and an SLA measuring the response.
