Skip to main content

Release notes

TrueSign changes, most recent first.

:::info Current version TrueSign 1.19.0, released on 3 August 2026. Upgrades happen in place from 1.17.0 or later: no uninstall, no data loss. :::

1.19.0 — 3 August 2026

  • An empty source field no longer cancels the send. A read-only merge field whose source record field was empty made Yousign reject the entire envelope (400 parameters_not_valid), behind a message naming only a field number that could not be traced back to the field concerned. Value-less fields are now dropped at call time: empty data is ordinary data, not a misconfiguration. weSign templates receive the mapping unchanged.
  • "Attach signed PDF to the record" is visible and editable again. The setting existed and was correctly applied, but the template editor exposed it neither for reading nor for writing: a template left on "no" could never be switched back from inside the product, and the signed PDF stayed attached to the signature request instead of the customer record. Guide

1.18.0 — 3 August 2026 · security hardening

  • Signing links are no longer readable by the read-only role. The signing link carries the signer's authentication: that role, described for reporting, could enumerate the org's live links and sign on anyone's behalf.
  • The package no longer forces access to all records. "View all" permissions are removed from the read permission set. If your org tightens sharing to Private to separate its business units, TrueSign no longer reopens everything silently.
  • GDPR minimisation — a signer's phone number is no longer readable by the read-only role; the email is enough to identify them.
  • Install APIs exposed to the org now require an administrator. They allowed log purge jobs to be delayed or interrupted, and therefore audit-trail retention to be manipulated.
  • Test switches are no longer honoured in production — three classes, including the emergency approval right and admin access to the Gen configuration.
  • Publishing the OTP event is explicitly denied: it triggered a code re-delivery.

Security architecture

1.17.0 — 3 August 2026

  • Setup links the TrueSign documentation. The Home screen and the Help section offered only Yousign links — a third party's API reference, of no use to an admin who has just installed the package. Home now points to Quick start, Administrator guide, Release notes and Support; Help gains a nine-entry TrueSign card, placed ahead of the provider's resources, which are kept for diagnosing a raw API call.
  • Component tiles regain their "Go to documentation" link — 9 components out of 11. The two AI components no page covers show no link rather than a dead one.
  • Links follow the user's language, with no duplicated URL table.

1.16.0 — 3 August 2026

  • A PowerPoint or Excel Gen template opens again.
  • Tag Builder buttons no longer collapse.

1.15.0 — 3 August 2026

  • The Gen templates list is usable again beyond 30 templates.

1.14.0 — 31 July 2026

  • Revocation of weSign public links already issued. The 1.13.0 fix correctly stopped new public links from being created, but every envelope processed before the upgrade still carried a live link, downloadable with no Salesforce session, no weSign token and no OTP. The upgrade now deletes those links and clears the matching field on every affected envelope. The leftover read path that still served this URL is removed: the document is still served safely, bound to the signing token.

1.13.0 — 31 July 2026

  • Six Security Review fixes, verified in an org: reading the settings is restricted to administrators (it exposed masked API credentials); a signer's token and OTP code are no longer readable or editable through permission sets, where they were forgeable; a 60-second cooldown closes the OTP resend lockout bypass; the status component checks the origin of the messages it receives; raw provider responses no longer reach the logs.
  • Personal-data masking in logs now covers key-name variants and numeric values.

1.12.0 — 30 July 2026

  • Tab placement no longer fails on a field carrying an AI prompt template. The property no API can write back is stripped before the page is saved, and the administrator is told which field was affected.
  • The template editor shows the real reason a save was refused — a provider, level or authentication mismatch — instead of a generic message.

1.11.0 — 29 July 2026

  • A template's Description field is kept.
  • "Resend failed rows", in bulk send, no longer silently drops an invalid recipient. Guide
  • Approve and Reject buttons on a request pending approval, straight from the envelopes list. Guide
  • The "My signature requests" widget displays Document, Object, Status and Signatures again.

1.10.0 — 29 July 2026

  • The wizard refuses to create a Tab on an object with no Lightning record page, instead of failing later in the flow.

1.9.0 — 27 July 2026

  • The template's provider is re-read at send time, rather than taken from the composer screen. Guide

1.8.0 — 27 July 2026

  • A template's signature provider becomes visible and editable. It drives the signature level and authentication lists from each backend's declared capabilities, and the server refuses impossible pairings. Guide
  • The signed document is no longer lost: "Reattach signed PDF" decides where the document goes, not whether it exists.

1.7.0 — 26 July 2026

  • The public Site is resolved by real guest access to the ceremony page, no longer by its name — signing links and webhook.
  • SMS OTP requires a phone number: UI, server and CSV import.
  • Explicit access mode — rights enforced by the platform, bound queries, and personal-data redaction in logs.
  • The Gen picker stops offering other objects' templates.

1.0.0 → 1.6.0 — 17 to 26 July 2026 · managed package foundation

  • 2GP managed package under the truesign namespace, rebuilt without 23 dead components.
  • Zero-config installation — admin permission set assigned to the installer, 5 maintenance jobs scheduling themselves, network access packaged, jobs health card in the Setup. Guide
  • Access hardening: explicit mode on configuration reads, bound queries, personal-data redaction.
  • weSign — formula field and official stamp.
  • Fixes: in-person recipient dropped on save, guard on a missing Gen file.

The functional foundation

The capabilities built during this cycle, validated by a full test campaign (82 scenarios, then a browser run of 56 PASS and 0 failures):

  • weSign — signing inside your own org SES: a second provider, with no third-party account and no external call, the whole journey hosted by your Salesforce — an org can even run 100% weSign, with no Yousign key. Yousign remains the provider for AES/QES signatures; the choice is made per org, per template or per send. Guide
  • Approval workflow — internal approval before anything is sent: sequential chain up to 3 levels, multi-criteria conditional routing with parenthesised filter logic, reminders and SLA escalation (manager, next level or named user), emergency reassignment. The engine ships inside TrueSign, with no dependency on Salesforce's native approval process. Guide
  • Auto-provisioned webhook — one click in Settings creates the webhook at Yousign and syncs the secret; a "Webhook intake" card tracks every event received. Guide
  • Event-driven tracking — components refresh themselves the moment a signature lands, with no periodic polling. Guide
  • Level guardrails — under AES, only SMS OTP is offered; sequential order is enforced in in-person signing too. Guide
  • Delegated sending — a template can designate a fixed sender: requests go out on that user's behalf, including from automations and Flows. Guide
  • Signing group administration — creation, members, activation. Guide
  • Visual placement editor — click-to-place on the page, aiming crosshair, draggable boxes. Guide
  • Per-signer customization — language (7 languages), email subject and message, private note. Guide
  • TrueSign Connect — writeback configuration in the template editor. Guide
  • In-person signing — no email sent to the signer, Sign Now button with a session link. Guide
  • Signed document download — direct button on all three components. Guide
  • Bulk send — automatic E.164 phone normalization, provider errors surfaced in the form. Guide
  • Einstein NBA Flow — ready-to-use "Send for Signature" action, with duplicate protection.
  • Full internationalization — translated interface (fr/en), help tooltips on every field.
  • Dashboard — pagination, column sorting, automatic refresh after a bulk send.

v1.0 — MVP

PDF sending for AES signature via Yousign, real-time webhook, signed PDF auto-attached to the record.

Roadmap

StepContents
AppExchange listingSecurity Review — the submission package is assembled and the hardening passes are shipped (1.13.0, 1.14.0, 1.18.0)
LaterCustom branding (logo, colors, emails), multi-org