Step 1 — Prepare and freeze
The document, the field placement, the signer list and the version are fixed before anything is sent. From that point the content is not editable; if it needs to change, the envelope is superseded and reissued rather than patched.
Step 2 — Issue individual access
Each required signer receives their own access to the document. Sharing one link between parties destroys the ability to say who did what, and it lets one party complete another party's fields.
Access should be revocable, because a resend, a correction or a wrong recipient all require the old access to stop working.
Step 3 — Identity attestation and consent
The signer confirms who they are and agrees to sign electronically. It is worth being precise about what this proves: it establishes that whoever held the access asserted an identity and agreed to the electronic process. That is attestation plus access control — it is not verified government identity, and no ordinary e-sign flow should be described as if it were.
Step 4 — Sign and record
The signature is captured and the event recorded with its timestamp and the signer it belongs to. Signature images, access tokens and verification answers should stay out of general reporting and audit metadata — they are sensitive by nature.
Step 5 — Completion
When every required signer has completed, the finished document is produced once, together with a record of who signed and when, and distributed to the parties. Before that point there is no final document, because there is no completed agreement to produce one from.
The legal boundary
Electronic signature law varies by country and by state, and by the type of document being signed. Nothing here establishes that a particular signature is valid, binding or admissible in your situation. Treat this as an explanation of the operational workflow and take the legal question to counsel in your jurisdiction.