The digital signature allows you to sign electronic documents ensuring that the content has not been modified and that the signer is who they claim to be. It is based on advanced cryptography and a qualified certificate stored in a secure device (smart card or token). According to Italian and European regulations (eIDAS), it has the same legal value as a handwritten signature on paper.
The Authorization Workflows, Register and Digital Signature module solves the organizational and operational issues related to the control, authorization, and signing of documents in Italian SMEs. It requires the presence of the Database Link license, which constitutes the underlying integration platform.
Manage authorization workflows, job roles, and signature registers in a single module
Authorization Workflows, Register and Digital Signature allows you to manage in a simple and reliable way the electronic authentication of documents, job roles and authorization cycles, optimally organizing signature registers by individual user and function.
Customized device configuration for each user
For each user, you can configure smart-card information and everything needed to start the digital-signature process: device type, certificates and local keys, timestamps, storage path for signed documents, and signed file format.
The module supports several signing methods. You can sign with qualified certificates using smart cards and USB tokens compatible with the PKCS#11 standard, ensuring digital signatures that fully comply with Italian and European regulations. You can also use certificates and keys stored in files (CER/CRT/PEM or PFX/P12 formats), ideal for internal authorization workflows where a qualified signature is not required, while still preserving security and traceability.
Assign roles and delegations with precision
Each user can be assigned up to five different roles.
For each role, you can define a delegate with equal signing authority, active within the defined delegation period.
By associating company roles with document classes, you can design the authorization stages required to organize the signature register correctly.
Configurable authorization cycles for each document class
For each document class, you can configure one or more authorization stages, collectively called authorization cycles, arranged in sequence and linked to the roles responsible for signing.
For each stage, you can define the stage code and subcode, the approval-type description, and the role required to sign (with up to three alternatives).
From Database Link, you can also view, edit, copy, and cancel the authorization stages for each individual document.
The Signature Register: documents to be signed, always under control
The Signature Register is automatically populated whenever a document is generated, either manually or automatically. Each user sees all documents awaiting their signature in their own register, selectable through a dedicated dashboard, and can sign them individually or in bulk.
When documents are waiting for signature, the user is notified through a pop-up that provides direct access to the register.
Documents can be filtered by attachment description, authorization stage, signature status (original, signed, excluded, and more), and time period.
What you can do with Digital Signature
The module is compliant with the requirements of the Agency for Digital Italy (AgID) and allows you to:
- Digitally sign individual documents in the standard CAdES format with P7M extension
- Batch sign entire folders of documents
- Timestamp individual documents
- Sign and timestamp in batch mode
- Apply multiple signatures and timestamps to the same document through co-signing or counter-signing
- Verify signatures and timestamps present in a document
Timestamps guarantee certain date and time at the moment of application and can be purchased online and applied through a dedicated module function.
How digital signature works
Digital signature is based on asymmetric cryptography. Each holder has a key pair: a private one, stored on a secure device (smart card, token, or HSM) and protected by PIN, and a public one, stored and published by the Certification Authority for signature verification. The two keys are uniquely correlated, but it is impossible to derive the private key from the public key.
The presence of the Certification Authority, a trusted third party, guarantees the unique association between the public key and the holder of the private key, through the issuance of a digital certificate released only after certain identification of the applicant.
To obtain a digital signature, it is necessary to contact Accredited Certifiers, public and private entities authorized to carry out this activity, whose list is published by law on the AgID website.
Guaranteed regulatory compliance
Article 2 of D.M. 17.06.2014 establishes that digital documents relevant for tax purposes, even if dematerialized, must meet the requirements of immutability, integrity, authenticity, and readability. The Authorization Workflows, Register and Digital Signature module is designed to ensure compliance with all these requirements.
Prerequisites
- webgate400
Evolution, not revolution
In nearly 25 years, the principle has never changed: don’t become a company forced to chase technology, remain a company competent in your sector
Our job is to give you tools to remain competitive, modern, secure, and scalable, without losing what already works today.