Nametag Integration for Docusign
Require Nametag identity verification before a recipient can sign a Docusign envelope.
Overview
Nametag for Docusign requires a signer to prove who they are β with a government ID and a selfie β before Docusign lets them sign the workflows you protect. Nametag verifies the signer is the specific intended human (Deepfake Defenseβ’: government ID + Spatial Selfieβ’), and Docusign only releases the envelope on a pass. No personal data is stored in Docusign by default β only a pass/fail signal.
It closes the impersonation and proxy-signing gap on high-stakes envelopes: wire-authorization and payoff letters, M&A and board consents, executive/finance approvals, real-estate closings, healthcare consent, and regulated disclosures.
What this integration does
Requires Nametag identity verification before a recipient can sign a Docusign envelope in the workflows you protect. Verification alone isn’t enough β Nametag also checks that the verified name matches the recipient name the envelope was addressed to, so a different verified person can’t sign in place of the intended recipient. No personal data is stored in Docusign under the default policy β only a pass/fail signal.
Before you start (have these ready)
- Admin access to your Nametag console (you’ll already be signed in).
- Admin access to your Docusign account on a plan with API access (Business Pro, Enterprise/Advanced Solutions, or an IAM plan).
- Ability to approve an OAuth consent in Docusign for your account.
- The template IDs or sender addresses of the signing workflows you want to protect (or choose “all high-value envelopes”).
Setup β five steps (the wizard shows all of them up front)
- Add the integration. In the console, open Add Integration, choose the Docusign card, and start the wizard.
- Connect Docusign. Select Connect Docusign. You’ll be redirected to Docusign to approve access for your account, then returned to the console. You never enter a Nametag key anywhere β you’re already signed in to Nametag, and this step authorizes Docusign.
- Choose what to protect (scope). Select the templates and/or senders that require verification, or toggle all high-value envelopes.
- Choose when verification fires (rules & mode). Pick the enforcement mode: Send-time gate (default β the envelope is held until the signer verifies) or Embedded-signing gate (the signing screen only opens after verification). Set the name-match strictness and write-back policy.
- Review & activate. Confirm the summary and activate. The integration is enabled for your tenant via a feature flag; nothing is live until you complete this step.
Managing the connection
The connected detail view shows connection status, the Docusign account, protected scope, enforcement mode, and recent activity. From here you can edit the scope/rules, rotate the Connect webhook secret, or disconnect.
Good to know
- The signer must match the intended recipient. A clear match releases the envelope; a mismatch is blocked and flagged to you; a borderline/near match is held for your review. You can tune how strict the match is (or turn it off for organization/entity signers).
- Name match is enforced by default. The check is tolerant of ordinary variations (case, accents, middle names, common nicknames like Bob/Robert), but a genuine mismatch fails the verification β the signer can’t sign, and you’re alerted. This is separate from write-back β it runs whatever your write-back policy is.
- What Docusign receives depends on your write-back policy. Default (Reference only) sends a pass/fail signal, assurance level, timestamp, and an opaque Nametag reference β no personal data. You can optionally switch a scope to Include verified identity, which additionally writes the signer’s verified name, the verification location (GPS), and a link to the verification record onto the envelope.
- Before turning on “Include verified identity,” know where it goes. These fields appear in the Certificate of Completion, which is shared with all parties and is court-admissible; they also flow through Connect webhooks, and location is treated as sensitive personal data under GDPR/CCPA. You’ll be asked to acknowledge this before it can be enabled. Prefer city-level location unless you specifically need precise. (ID numbers, ID images, and date of birth are never written to Docusign under any policy β they stay with Nametag.)
- Verification requests expire (~168 hours). An expired request never counts as a pass; the signer re-verifies.
- Direct sends. Envelopes sent through this integration are gated up front. Envelopes sent directly in the Docusign web app outside a protected workflow are handled after the fact (corrected or voided with an alert). For inline enforcement everywhere, ask your Nametag contact about the native Docusign Identify method (roadmap).
- Mobile-only verification. Signers verify on a phone (QR/link); webcams and desktop browsers are not used, by design.
Troubleshooting
- “Docusign card isn’t in Add Integration.” The
docusignfeature flag isn’t enabled for your tenant β contact Nametag. - “Connect failed.” Re-run step 2; ensure you approved the Docusign consent with an account that has API access.
- “Signer says they can’t sign.” Check the binding in the detail view β verification may be pending, failed, or expired, or the verified name may not match the name on the envelope (a name mismatch fails verification by design). If the addressed name was mistyped, correct the recipient name and resend.