A signature is only as good as what you can prove about it

Signing is the easy part. Somebody puts a finger on a screen in a crew office, the document turns green, and the task disappears from a list. The hard part arrives two years later, when a claim is being argued or an auditor asks how a particular acknowledgement came to be on file, and the only thing anyone can produce is an image of a signature on a PDF.
At that point the signature itself is nearly worthless. What matters is everything that was, or was not, recorded around it.
A signature is a claim about three things
It asserts that a specific person, at a specific moment, saw a specific document and agreed to it. Strip any one of those away and what remains does not carry much. A signature with no reliable identity behind it is a drawing. One with no timestamp cannot be placed against a sequence of events. And one that is not bound to an exact revision of the document is the weakest of the three, because it invites the only question that really damages a record: how do we know that is what they signed?
This is why capturing a signature and storing a document are not the same job. The signature has to be fastened to the bytes that were on the screen, in a way that makes later substitution visible rather than merely unlikely.
"Nobody disputes a signature while it is being given. The dispute arrives years later, and by then the only thing you have is what you thought to record at the time."
The revision problem
Documents in an operator's estate are living things. A policy acknowledgement is reissued when the policy changes. A contract addendum supersedes a clause. A standing order is revised after an incident. If the signing system stores a pointer to "the crew handbook" rather than to a fixed revision of it, then every historical signature quietly re-points at the current text, and the record now says something that never happened.
The fix is unglamorous: treat the signed artefact as immutable and version it explicitly, so that a signature from March refers to the March text forever, whatever the document becomes afterwards. It is the same discipline that makes a survey and inspection trail worth keeping — the value is in the record being fixed, not merely digital.
Signing where the link is not
Crew sign things at sea, which means a signature frequently has to be captured with no route to shore. That is a solved problem in the sense that the platform is built to work without a connection, but it puts a specific requirement on the signing flow: everything needed to make the signature complete has to be gathered at the moment of signing, on the device, rather than stitched on when the record eventually reaches shore.
A timestamp taken when the record syncs is not the time of signing. An identity resolved later against a shore directory is not the identity of the person who was standing there. If those are filled in on arrival, the record has a gap precisely where the argument will land. The signature and its context travel together, or the context is fiction.
Where documents live and how signing fits the rest of crew administration is covered on the modules page, and the access and audit-trail side is on security. We will not tell you in a blog post whether an electronic signature satisfies a particular jurisdiction or contract — that is a question for your own counsel, and any vendor answering it confidently in marketing copy is telling you something about the vendor.
What is worth asking, of us or anyone else, is narrower and more revealing: show me a signature captured eighteen months ago, the exact document revision it was given against, and who it was. If that takes a database query rather than a click, the system was built to collect signatures, not to keep them. If that is a question you are working through for your own document estate, it is a good one to bring to a walkthrough.
Luis Manuel leads the engineering behind CruiseControl, from the shared core to shipboard reliability.


