Microsoft Entra and Active Directory

Active Directory should not be a front-door convenience. It should remain an authority signal.

SignumEra uses Microsoft Entra ID as the organizational identity anchor. Entra application roles can express enterprise assignment; SignumEra normalizes those claims and enforces permissions server-side through preparation, ceremony control, finalization, administration and billing.

Key controls

One organizational principal. Multiple controlled actions.

Authentication, role assignment and application authorization remain distinct controls. Microsoft Graph is requested only for Microsoft workflows that actually need it.

Microsoft Entra organizational identity

Use the identity system your enterprise already governs as the organizational authentication anchor.

Entra application roles

Assign SignumEra.Admin, SignumEra.User or SignumEra.Auditor to users or groups; external claims are normalized into SignumEra roles.

Server-authoritative authorization

Rust—not menu visibility—enforces sensitive actions. Owner, Admin, Member and Auditor permissions remain application controls.

Graph only when the workflow needs it

Microsoft sign-in can use OIDC without broad Graph consent. Additional Graph permissions are requested only for deliberate Microsoft 365 workflows.

External signers stay isolated

Recipients use private SignLinks and ceremony-specific assurance; they do not need access to the organizer’s tenant or collaboration files.

Low-friction adoption

Start with a real account. 20 signing credits. One year included.

Public Beta starts September 8th