Hello,
In our account, we have the following settings enabled:
- Recipient Authentication Triggers: The first time a recipient accesses an envelope per device.
- Recipient Authentication Skip Option: Recipients cannot skip authentication when accessing subsequent envelopes from the same sender.
When utilizing in-person signing, the user is prompted to enter the access code to initially access the envelope to sign (on the hosted device). However, once all parties have signed the document, a completed email is sent to the signer where they can view the completed document. If the user clicks that link on a different device, they are not prompted to enter the access code and can view the contents of the document.
This is a major security concern if the wrong email was entered or the email was compromised - documents may contain NPPI. Why isn't the access code being prompted on subsequent access of viewing the completed envelope, even if switching the authentication trigger to: Every time a recipient accesses an envelope?