Requests & approvals

A yes is bound to the words you read. Change them and it lapses.

Requests arrive with their questions already generated from the template they will fill. Approval chains assemble from your rules and bind to a version, a body hash and every clause fingerprint.

Requests · REQ-0142 · NDA · Brightline AnalyticsSalesDrafting
Request REQ-01420 of 6
Filed09:02Sam in Sales picked “NDA — mutual”. The request type is bound to Northwind NDA v4, so its six questions are the template’s own blanks.
Triaging09:24Routed by the rules on the request type. No one had to decide who owns an NDA at nine in the morning.
Drafting10:07Answers land in the blanks they were generated from. Nothing is re-typed, so nothing is re-typed wrongly.
Waiting on requester10:07One blank needs the counterparty’s signing entity. The clock stops here — this is Sam’s turn, not the desk’s.
Draftingnext day 09:47Sam answers. The clock restarts where it stopped, at 1h 05m of working time.
Done12:36Six of six playbook positions met, so no chain was required. Sent for signature.
Questions generated from the bound template’s own blanks…
SLA · 1 working day
Time on usRunning
0h 02m
Counted in the firm’s working week — evenings, weekends and holidays are not billed to the desk.drafting
Draft itReady
Six answers, six blanks. The request type is bound to Northwind NDA v4, so an answer already knows which words it fills — no second transcription, and nothing to re-key.
One endpoint owns every state changeThe clock pauses while we are waiting on you

The clock pauses while the desk waits on you

Two problems that look like one.

Work arriving badly, and work being agreed to loosely.

Legal · operations

Requests that arrive finished, not as an email saying “quick one”.

A request type is bound to a template, and its questions are that template’s own blanks — so “Draft it” fills the document rather than starting a second transcription.
One endpoint owns every state change. Seven endpoints that each set a state is seven ways to get the rules wrong.
A fourth role, requester, sees only their own requests and the drafts those produced. They never see the register.
Finance · the approvers

An approval you can still stand behind a month later.

Rules are an OR of ANDs: all matching rules apply, their steps concatenate, a person approves once, and the stricter SLA wins.
Approve in the app, from Slack, or from a signed one-time email link. Every channel carries the version and hash and is refused on mismatch.
A decision is undoable for thirty seconds — and an undo that reaches an already-notified next step sends a withdrawal rather than going quiet.
02Lapse

An approval does not outlive the wording it approved.

When a new version lands, every step decided against the old words lapses — and the approver is shown which clauses moved, with one tap to approve again. Nobody is asked to re-read the document to find out what changed.

Approvals · Acme Amendment 4 · v4
Chain · 2 rules matched3 steps
01Elena DuartewaitingCFO · rule · any contract over $250k
02Priya KaurwaitingCounsel · rule · liability cap below preferred
03Data protectionwaitingGroup · any one · rule · processes personal data
GateSend for signature is refused with 412 approval_required while no approved request binds the current body hash. The refusal names the step, not the document.
Bound to version · body hash · per-clause fingerprints · approve from here, Slack, or a signed one-time link
03Preflight

Two questions, asked separately.

Before a chain is worth building: is anything still a blank, and has every filled-in value been ruled on? One row used to answer only the second while claiming the first, so a draft nobody had answered sailed through and a draft where everything was answered was refused over six values already in the text.

Preflight · before a chain is builtAcme Amendment 4 · v5 · two questions, asked separately
FOUNDNothing is still a blank — the document nowhere says [OTHER PARTY]6 of 6YOUTwo proposed fills have not been ruled on by a personneeds youFOUNDSigning entity confirmed by the requesterREQ-0142NONENo approval rule names export for this counterparty · checked 4 rulesclaim
Both questions are asked, and answered, separately — a draft nobody has answered and a draft where everything is answered otherwise produce the same single count
04How it works

From a request to a binding yes.

Four steps, each with its own record.

01FileInternally, or through a public link that verifies an email address for real and refuses to file under an unconfirmed one.
02DraftAnswers fill the blanks they were generated from. The clock runs in your working week and pauses whenever the desk is waiting on the requester.
03ApproveMatching rules concatenate into one chain. Steps name a person or a group, resolved to its members at request time with any-one or all.
04GateSend for signature, send to counterparty and export are refused while no approved request binds the current body hash.
05Before · after

What an approval used to prove.

The same three people, the same contract.

The way it wasWith ClauseMinds
“Approved” is a reply in a thread, attached to whichever draft was open at the time.Approved against v4, body hash 9f3a·c17e, with the fingerprint of every clause it covered.
Someone edits the cap after the CFO said yes. The yes quietly still counts.The step lapses, and the CFO sees the two clauses that moved — not the whole document again.
The SLA says Legal took four days. Three of them were spent waiting for the requester.The clock pauses while the desk is waiting on you, and the paused time is recorded separately.
A rule that names no exception quietly guards everything.A condition that cannot be evaluated never matches, and the preflight says which question failed.
06When this happens

The awkward ones.

WhenTwo rules both match the same contract.ThenTheir steps concatenate into one chain. A person who appears twice approves once, at the earliest position, and the stricter of the two SLAs is the one that counts.OR of ANDs · earliest position wins
WhenSomeone approves in Slack from a stale message.ThenRefused. Three checks stand between a tap and a decision: the request was signed by this workspace’s app within five minutes, the person has a linked identity, and the wording they read is still the wording on the draft. A refused tap is a row, not a banner.version + hash on every channel
WhenAn approver changes their mind ten seconds later.ThenUndo. If the next step has already been notified, a withdrawal goes out rather than the notification simply going quiet — the failure that matters is somebody believing they approved something and being wrong.30-second undo · explicit withdrawal
07Principle

A chain is a claim about who agreed to what. It is only worth having if it can be wrong.

01The binding is to words, not to a file.Version, whole-body hash and per-clause fingerprints. That is what makes a lapse computable instead of a matter of somebody remembering.
02A condition that cannot be evaluated never matches.A rule that silently guards everything is worse than no rule, because it reads as coverage.
03The clock measures the desk, not the company.Time spent waiting on the requester is recorded, and recorded separately. A number that blames the wrong party gets gamed within a quarter.
08Said plainly

What it does not do.

It does not decide who should approve.You write the rules. The product concatenates the ones that match and refuses the actions they name — it has no opinion about whether a $250k threshold is the right threshold.
An approval is not a signature.It binds a person to a version inside your workspace. Execution is a separate step with its own rails — see Signature.
A public request form needs working mail.External requesters are verified by email. Where a deployment cannot send mail, the form refuses to file under an unconfirmed address rather than trusting what was typed.
Everything in the front half

What ships with requests & approvals

Request types bound to templatesQuestions generated from the template’s own blanks plus five standard ones, so an answer already knows which words it fills.
Working-hours SLACounted in your week and holidays, paused whenever the desk is waiting on the requester. Under 25% remaining is at-risk.
Public intake linkExternal requesters verified by a real email round-trip. Human-readable ids (REQ-0142) beside the UUID.
The requester roleScoped to their own requests and the drafts those produced — a fence on the aggregate router, not an argument every call site has to remember.
Rules as an OR of ANDsAll matching rules apply, steps concatenate, a person approves once at the earliest position, the stricter SLA wins, ad-hoc steps append.
Groups, not roles“Counsel”, “CFO”, “DPO” are assignment groups resolved to members at request time, with any-one or all.
Lapse on editA new version lapses every step decided against the old wording and shows the approver the clause fingerprints that moved.
Action gatesSend for signature, send to counterparty and export refuse with 412 approval_required while nothing approved binds the current body hash.
Approve anywhereIn the app, from Slack, or from a signed one-time email link. Every channel carries version and hash and is refused on mismatch.
Thirty-second undoReversible immediately after the fact, with an explicit withdrawal to anyone already notified.

Questions people ask

The binding. An approval is attached to the draft version, a sha256 of the whitespace-normalised body, and the per-clause fingerprints of that version. When a new version lands, every step that was decided against the old wording lapses automatically, and the approver is shown exactly which clauses moved with a one-tap Approve again. This is not a notification — the gate genuinely closes.
Yes, and from a signed one-time email link. Three checks stand between the tap and the decision: the request was signed by this workspace’s app within the last five minutes, the person tapping has a linked identity, and the wording they read is still the wording on the draft. A tap that fails any of them is refused and recorded as a row.
In your firm’s working hours, from the workspace’s timezone, working week and holiday list — and it pauses whenever the request is waiting on the person who asked. Without that pause the number measures how quickly the business answers Legal and then reports it as Legal being slow. The paused time is still recorded, separately.
Through a public link, once their email address is verified by a real round-trip. External requesters get the requester role, whose scope is their own requests and the drafts those produced — they never see the register the way a viewer does.
A condition that cannot be evaluated never matches, so a broken rule fails to apply rather than silently applying to everything. The preflight names which of its two questions failed — something still blank, or a filled-in value nobody has ruled on — instead of reporting one count for both.

Put one rule in writing. See what it catches.

Bind a request type to a template and watch the first draft arrive already filled.

14 days free · no card