Account · For everyone
Electronic signatures in Norma
Signatures record chains and verification: sign a controlled record; read the chain; print export and verify. This is chapter 32 of the NormaQMS User Guide.
Sign a controlled record
- Open the record and identify the revision, baseline, or response you are signing.
- Review its content, change summary, file, and current approval request.
- Open the signature control and enter your password under Re-enter your password to sign. As it says, Signing uses your account password to prove it was you; if you signed in with an email link and never set one, set a password in Settings first.
- Choose the decision and signature meaning requested by the form. Approval and rejection meanings must agree with the decision.
- Submit. The password check is performed against your account and is consumed by exactly one signature, recorded in the same transaction.
- Confirm your name or account, decision, meaning, and timestamp appear on the record.
A failed password does not create a successful signature; failed verification attempts can appear in the record chain. Document signatures bind the file hash and revision presented to the signer. A saved draft, note, supplier upload, or ordinary button click should not be described as an electronic signature unless the workflow actually performs one.
Read the chain
Open Record chain from the record or its side rail. The chain lists actions, actors, times, and retained payloads in order. Verification checks that the stored chain links agree. Consultant entries preserve the capacity in which the person acted at that time.
Use the chain to answer practical questions: Who required the approver? Which file was signed? When did a revision become effective? Who changed an owner or date? What happened after an ineffective CAPA check?
The chain cannot be edited like a note. Correct facts through a new supported action, revision, amendment, or controlled exception. The next entry explains the correction while preserving the original history.
Print export and verify
Use the chain's print control or browser printing for a readable copy and its JSON export for machine-readable evidence. Keep the source record and associated file together with the chain when assembling an evidence package.
For a public check, open the site's Verify a record hash page, paste the full 64-character record-chain hash, and choose Verify. The result reports whether it is a Norma record-chain entry and whether its chain currently verifies intact. A file's SHA-256 fingerprint is not necessarily a record-chain-entry hash; use the hash identified for chain verification.
Public verification does not disclose the underlying record contents or normally identify the organization unless it has a published Quality Passport. It also does not certify that the content was technically correct. If verification reports a broken chain, preserve the evidence, record the affected reference and time, and escalate to support before relying on that chain for an external attestation.
In the user guide
This article is chapter 32, "Signatures record chains and verification", of the NormaQMS User Guide (NORMA-UG-001), which is under Help > User guide. Chapter numbers in the text refer to that guide.