# What a signer sees

A signer never needs SignPlus, and does not need a Confluence account either. Everything they do
happens in an email and on Dokobit's signing page. This page is what to send someone who asks what
the invitation is.

## Is this a real signature?

Yes, when it is made with a qualified eID. The signing happens on Dokobit's page, with your own
Smart-ID, ID card or another eID, and SignPlus and Oktul never see your personal code or PIN.
A signature made with an eID that carries a qualified certificate is a qualified electronic
signature, which Article 25(2) of
[eIDAS](https://eur-lex.europa.eu/eli/reg/2014/910/oj) gives the legal effect of a handwritten
signature across the EU. [Dokobit's list of eIDs](https://www.dokobit.com/eids) says which methods
produce one.

Dokobit is a qualified trust service provider for validating electronic signatures and seals, on
the [EU Trusted List](https://eidas.ec.europa.eu/efda/tl-browser/#/screen/tl/LT), and states that
it keeps documents and signer details in the EU/EEA. Its
[compliance page](https://www.dokobit.com/compliance) has the certificates, and its
[privacy policy](https://www.dokobit.com/compliance/privacy-policy) covers what it does with your
name and email address.

## The invitation

Dokobit sends each signer an email. The sender is shown as **Dokobit**, and the subject names the
organisation and the document: *Your Company has invited you to sign the document "Service
agreement"*.

The organisation named is the holder of the Dokobit account the signing ran on. With
[Your own token](../configure/#signing-mode) that is your organisation. With **Test** or **Managed
by Oktul** it is Oktul.

The email carries the document name, the message from the person who started the signing if
there is one, and a **Review and sign** button. Signers with the **Viewer** role get no invitation,
only the notice once everyone has signed.

## Signing

<Steps
  items={[
    {
      title: 'Select Review and sign',
      body: 'Dokobit’s signing page opens with the document on the left, every page of it, and the signing steps on the right.',
    },
    {
      title: 'Read the document',
      body: 'Scroll through it in the viewer. It is the page as it was when the signing was sent, with the site’s first page, header and footer.',
    },
    {
      title: 'Choose a country and a signing method',
      body: 'The methods on offer depend on the country, and on what the site allows. In Estonia, for example: Smart-ID, Mobile-ID or an ID card.',
    },
    {
      title: 'Select Continue, and identify yourself',
      body: 'For Smart-ID, enter your personal code and select Sign document. Dokobit shows a verification code.',
    },
    {
      title: 'Confirm on your device',
      body: 'Check that the code on your phone matches the one on screen, then enter your PIN in the Smart-ID or Mobile-ID app, or on the card reader for an ID card.',
    },
  ]}
/>

The page then says **You have successfully signed the document**, and offers a download of the
file as it stands with your signature in it.

A signer who does not want to sign selects **Decline** instead. The signing is then declined for
everyone: the panel on the page says so, and SignPlus lifts the page restrictions it set.

<Aside type="note" title="When the order matters">
If the signing was started with **Signers must sign in the order listed**, each signer can sign
only after the one before them has signed.
</Aside>

## When everyone has signed

Dokobit tells SignPlus, and SignPlus downloads the signed file and attaches it to the Confluence
page. Viewers, and the person who started the signing if they were added as a viewer, get
Dokobit's notice that the document is signed.

SignPlus does not believe Dokobit's notice on its own word. It asks Dokobit for the signed file and
marks the signing complete only once it has it. If a notice never arrives, SignPlus asks Dokobit
itself once an hour about every signing that has been quiet for an hour.

## Checking a signed file

The signed file can be checked by anyone who has it, without SignPlus and without Confluence.

| Format | Open it with |
|---|---|
| **ASiC-E** (`.asice`) | DigiDoc4, the Estonian state's free client, or any other eIDAS validation tool. It lists the files in the container and each signature with its signer, time and validity |
| **PDF** | Any PDF reader that shows signatures, such as Adobe Acrobat Reader. The signatures are inside the PDF |

Dokobit's own validation, run as a qualified service, reads both formats and reports whether each
signature is qualified or advanced. [How to validate a signed document](https://dokobit.support.signicat.com/hc/en-us/articles/19932798495004-How-to-validate-signed-documents)
is Dokobit's guide to it.

<Aside type="caution" title="A document signed in test mode is not signed">
Documents signed while the site is in **Test** mode carry Dokobit's watermark across every page
and can only be signed with Dokobit's test identities. They have no legal effect.
</Aside>

## Related

- [Sign a page](../sign-a-page/)
- [After signing: check, download, cancel](../after-signing/)
- [Privacy and data handling](../privacy/): what Dokobit receives and how long it keeps it

---

A problem or a question? Write to [support@oktul.com](mailto:support@oktul.com) or open a request in the [Help Center](https://oktul.atlassian.net/servicedesk/customer/portals). Both reach the same service desk, so either way the request gets a reference and an SLA measuring the response.
