A signed document is not one more file
A signed contract is the most sensitive artefact a company holds. It carries a negotiated price, a term, an exit clause, sometimes an exclusivity, and the names of the people who committed. Some signature requests also carry a proof of identity, because verifying the signer required one.
So the connector never goes looking for the document. None of its calls leads to the signed file, and this is not an option an administrator could switch on, because the path that would fetch it exists nowhere in the connector. Four reads exist and no more, and none of them descends to the bytes of a document.
What it reads sits one layer above, the layer that says a commitment exists. The name of the request, its state, the names of the files it holds, their nature and their page count, plus the tally of signers who have signed and those still waiting. An AI can therefore answer a question about where a matter stands without any access to what was negotiated.
Yousign's workspaces are a genuine partition
Yousign offers workspaces so that a company can reflect its own organisation, its departments, its subsidiaries, its branches, and those workspaces already keep documents confidential between users. That is a real partition rather than a filing label, and the connector leans on it instead of inventing a division of its own.
Every request carries the identifier of its workspace, so the filing is decided request by request. An administrator maps a workspace to a department, and the requests in that workspace become readable by the people of that department. A workspace they have not mapped is readable by nobody, with no quiet fallback to a default department.
If they would rather not map workspaces one by one, they can designate a single legal department for the whole account. That department has to genuinely exist in your organisation, failing which the requests stay on hold pending their decision. There is no case in which a contract becomes readable by the whole company, and that refusal is written into the connector.
What comes in from a signature request, and what stays out
The list is the connector's own, field by field, as it is written there.
The name of a request and the name of a file do come in, and that is a deliberate choice. A label such as “Amendment Martin Group 2026” identifies a contract without handing over its content, and it is what lets an AI know that a commitment exists. If your naming convention slips an amount in there, that amount comes in as well, which is worth knowing before you connect.
Four questions legal teams ask
These are the four objections that come back when a team evaluates this connector. The fourth is the one we would have an interest in keeping quiet.
Can an AI read the contract itself?
No. The signed document is never downloaded, and the connector has no call that would make it possible. An AI plugged into your Kastel learns that a contract goes by a given name, that it runs to a given number of pages and that it has been signed. It learns neither its price, nor its term, nor its clauses, because none of that has been read.
Does it see who signed?
It sees how many signers a request has and where each of them stands, as a tally by state. The names, email addresses and phone numbers of signers are never read. The only person named is the internal sender of the request, because knowing which department set a signature in motion is part of the company's context.
What about the signature link sent to the signer?
It is written nowhere, and it is the most dangerous field in this interface. That link amounts to a power of attorney, since anyone who opens it can sign in the signer's place. The connector does not read it, so it cannot end up inside content an AI would later read. The custom accompanying message is excluded for a related reason, its free text being able to hold the context of the negotiation.
Are all my requests seen?
Not by default, and this is the most important point on the page. Yousign's interface filters requests by origin, and its default value only returns those created programmatically. Requests started by hand from Yousign, often the majority, are read only once an administrator has explicitly declared that origin. Until the list of origins is declared complete, the connector prefers to read less and refuses to conclude that a missing request has been deleted. What we put up against that kind of choice is written down rather than left to discovery.
A cancelled request is still a piece of information
A request that has been cancelled, has expired or has been declined carries on appearing in Yousign with its new state. The connector rereads it and rewrites its record, rather than treating it as a disappearance. The fact that a contract sat unsigned for three months is a piece of management information in its own right, and it is worth as much as a signature obtained.
Every request is reread on every pass, because Yousign exposes no single last-modified filter and spreads its state changes across as many dates as there are states. When pagination repeats itself instead of advancing, the pass stops on an error, which avoids mistaking an incomplete read for a complete inventory. The other signature tools in the catalogue follow the same metadata discipline, with partitions of their own.
What this connector does not do
It gets nobody to sign. It creates no request, chases no signer, downloads no document. The key requested from Yousign is a read key, so there is no write path towards your signature journeys.
The name of a request and the name of a document are text your teams write. If your naming convention puts a client's name, an amount or a project code in there, that information comes in with the request. It is the reason those records are readable by nobody before a workspace or a department has been mapped.
By default, the connector only sees requests created programmatically. A company whose signatures go out from Yousign's own interface will therefore have almost nothing in its Kastel until an administrator declares that origin. And the deletion reconciliation stays switched off until that list is declared complete, because a partial view would mark requests that are very much alive as gone.
A request permanently deleted in Yousign is not erased from your Kastel. It remains under a gone-at-the-source note, readable by the people who were already reading it, until an administrator's erasure decision.
Let us talk about your contracts before you connect anything.
Electronic signature is the kind of source where you want to know exactly what is read before saying yes. Describe your workspaces and your practices to us, and we will tell you what this connector reads and what it leaves out.
Get in touch