The workflow most firms actually run
Produce the PDF, apply a signature image or digital stamp, attach it to an email, press
send. For operational teams issuing dozens of documents a month, this workflow is fast,
familiar, and fits every client's expectations. Nothing about it needs replacing for
delivery.
The gap appears later. When a document's date, contents, or currency is questioned —
months or years after issue — the email thread becomes the firm's evidence. And email
threads answer those questions badly.
Where the email trail falls short
Which version? A thread with six attachments named
report_final_v2_REV.pdf cannot show which file the recipient relied on, or
whether the file on someone's desktop matches any of them.
What date? Sent timestamps establish when a message left a mailbox —
not when the document existed in its current form, and not whether the attachment was
later swapped in a forwarded copy.
Still current? An emailed PDF carries no status. If a report was
superseded by a revised issue three weeks later, nothing about the original attachment
says so. Recipients act on stale documents in good faith.
Who issued it? Sender addresses and letterheads are straightforward to
imitate. An email's apparent origin is weak evidence of organisational issuance.
Adding a record without changing the workflow
The fix is not abandoning email — it is separating delivery from
evidence. The document still goes out the way it always has. What changes is
that, at issue time, the firm records the things that get contested later: verified
issuer attributes, a SHA-256 hash of the exact file, an RFC 3161 timestamp, and a live
status that can be updated if the document is revised or withdrawn.
A recipient — or anyone the document is passed to — checks the record through a
QR-linked page: no account, no software, no phone call to the issuing office. The
recorded hash changes if the file changes, so a mismatch is immediately visible.
Verified.Tools is testing this workflow with Australian and New Zealand engineering
firms in an invite-only private beta, alongside controlled document packages
(Envelope) for multi-document issues.
What this does and does not change
A verification record does not make a document's contents correct, and it is not a
substitute for professional sign-off, contractual delivery requirements, or legal
advice. It adds one specific capability the email workflow lacks: a recipient-accessible
answer to "is this the recorded file, from this issuer, at this time — and is it still
current?" For documents that carry professional weight, that is the question an inbox
cannot answer.
Related reading
How to verify a PDF document
What should a recipient be able to verify about an issued engineering PDF?