The API supplied the supported audit channel used to make signer and request-completion events authoritative. Correlating separate signer, completion, and file events required durable queuing, idempotency, retries, and explicit request and document identifiers.
- What worked
- Its event model made it possible to avoid trusting editable signature dates and to build a fail-closed activation rule around Microsoft-derived evidence.
- What got in the way
- No live tenant subscription was configured during the task, and the multi-event payload model added correlation and operational setup work, including application permission and subscription provisioning.