
Rules
Part of 6 honest notes on contracts and disclosure
Is signature really the hard part of a disclosure record?
Best contracts and disclosure platforms 2027: what a compliance record has to hold, why signature is the easy half, and how to test a system before relying on it.
Signing is the part every system does well. The part that decides whether you can answer a question in eighteen months is everything around the signature: which version was accepted, what was actually published, who looked at it, and when.
This page is about that record. No products are named, because the properties below outlive any particular one. The obligations the record has to evidence are in contracts and disclosure.
What to take away
- A compliance file that holds the approved asset and no evidence of the published post is missing the half that gets asked about.
- Version identity matters more than storage. You need to be able to say which document each party accepted and on what date.
- Assume you will leave the system. Design the record so that leaving costs you nothing but effort.
What the record has to contain
| Item | Why it is needed | The usual gap |
|---|---|---|
| The executed agreement, with a version identity | To show what was agreed, not what the template said | Only the latest template is stored |
| Evidence of acceptance and its date | To answer when each party agreed | Signature captured, timing not |
| The brief and its versions | To show what was asked for | The brief lives somewhere else entirely |
| The approved asset | To show what was signed off | Present, and usually the only thing present |
| A capture of the published post | To show what a viewer actually saw | Missing, because nobody thought of it |
| A dated disclosure check, with a named checker | To show the check happened | An assertion in a policy document |
| Re-use records | Because a repost or an advertisement can strip a label | Absent by design |
| The usage expiry date | Because rights end quietly | Nowhere at all |
The fifth row separates a real file from a filing cabinet. Disclosure is a property of a published context: how it renders in a feed, on a phone, with the description collapsed, in audio. An approved video file cannot show any of that.
What good looks like on prominence is set out in the FTC's material on effective disclosures in digital advertising. The check has to be made against the live post, not against the deliverable.
Signature: the parts that matter
Electronic signature is well established and the technical question is rarely the interesting one. The interesting ones are procedural. The procedural questions above are the same ones a buyer should ask when comparing contracts and disclosure tools before committing.
Does the system record which document version was presented, rather than which one is current? A record that always shows the latest template is not a record.
Can it show that the person who signed had authority? For an individual creator this is usually trivial. For a company it is not, and it is the point at which agreements get disputed.
Does it capture the counterparty's copy? Both sides should end up with the same artifact. The moment one side's copy is only viewable inside a service, that side has less than they think.
Where a written record is legally required at all is jurisdiction-specific. The doctrine that decides it in some systems is described under the statute of frauds. Take that as vocabulary rather than as an answer; the answer comes from a lawyer where the agreement is enforced.
Monitoring and its limits
Automated checks can tell you that a post exists, that a label is present in metadata, and that certain words appear in a caption. That is worth having and it is not the check.
What it cannot do is decide whether an ordinary viewer would notice. Prominence is contextual: the same caption reads differently above and below a fold, and a spoken disclosure at second forty of a video is not the same as one at second three. Any system that reports a percentage of compliant posts is reporting on the part it can measure, which is not the part that matters most.
Use monitoring for coverage, to find the posts nobody checked. Use a person for prominence, on a sample, on a phone.
Retention and access
Decide, in advance, how long the record is kept and who can reach it after the campaign ends and after the agency relationship ends. The commonest failure is not deletion; it is that the record survives inside an account nobody has credentials for.
Test the exit before you commit. Export everything, open it somewhere else, and see what is missing. Do this at the start rather than at the end, because at the end you will be doing it under time pressure and with a counterparty who has stopped caring.
Where the review evidence is generated in the first place is a workflow question rather than a storage one, and it belongs with content approvals. What has to be recorded during the campaign so that the results can be read later is in measurement and ROI.
A short test for any system
- Show me an agreement from a completed campaign, the brief it came from, the published post, and the dated disclosure check. If the four cannot be shown together, the system is storing documents rather than keeping a record.
- Change a template, then show me a contract signed before the change. If it now displays the new wording, stop.
- Export a campaign. Open the export with nothing installed.
- Ask what happens to the record when a person leaves and when a vendor contract ends.
Bottom line
Judge a system by what it can prove after the campaign, not by how smoothly it collects a signature. It has to hold the agreement with a version identity, the brief, the published post, a dated and attributed disclosure check, any re-use, and the date the rights expire. Test the export before you depend on it, and use people rather than automation to judge whether a disclosure is actually prominent. The scope it all inherits starts at campaign briefs.
Common questions
Is a shared drive enough?
It can be, if someone maintains a convention for versions and dates and someone actually captures published posts. Most of the value is discipline rather than software.
How do you capture a published post usefully?
A screen capture on a phone, dated, plus the link. The point is to show what the surface looked like, not to archive the asset again.
Should the creator hold the same record?
Yes. Both parties benefit from being able to show what was agreed and what was published, and the creator is often the one asked first.
Does an automated compliance score mean anything?
It means coverage was checked. It says little about prominence, which is where the real failures are.
What is the single most useful thing to add to an existing process?
A dated check of the live post by a named person, stored beside the contract. It is cheap and it is the item most often absent.







