Xirag CLM
Just need a signature?
Contract Lifecycle Management

The contract that keeps working after it's signed.

Approve it, stamp it, dispatch it, sign it, certify it — then track what it obligates you to and when it comes back around for renewal. Every step writes to a tamper-evident chain, so "what actually happened" is never a matter of who remembers correctly.

Tamper-evident audit chain · Per-tenant document encryption · Playbook-checked approvals
Lifecycle console

One record, six stages, no spreadsheet on the side

Every contract moves through the same pipeline — and every stage it passes through is a real, tested operation, not a status label someone forgot to update.

Master Services Agreement · Acme Corp
1 Draft document uploaded
2 Approve playbook-checked, step-up MFA if severity requires it
3 Stamp idempotency-keyed procurement
4 Dispatch OTP step-up + per-recipient watermark
5 Sign Aadhaar eSign or Class 3 DSC
6 Certify Certificate of Completion, chain verified
Simulating…
outcome
 

Illustrative playback of five real contracts moving through the pipeline — the outcomes shown (escalation, idempotent retry, watermarking) are real, tested backend behavior, replayed here rather than queried live.

Approval modes

Sequential, escalating, or delegated — per step

An approval step never has just one way to move forward.

  1. 1Dept. Sub-AdminPreferred severityApproved
  2. 2Legal OpsMedium severityApproved
  3. 3Tenant AdminHigh severityPending

Each step's required approver is resolved from a real authority grant — re-checked from the database on every call, never trusted from the button that was clicked.

Step assigned to Priya Sharma — 46h idle
Auto-escalated to backup approver — after 48h with no decision
Falls back to tenant admin/owner — if no escalation seat is configured

This codebase has no manager/reporting-line concept yet, so "the tenant admin" is the honest default escalation target — not a real org-chart walk.

Priya SharmaOn leave — original assignee
Rohan MehtaActing delegate

Delegation never rewrites who was actually accountable — the original assignee stays on the record even while someone else decides.

Obligations & renewals

Alerts anchored to the due date, not "soon"

Every obligation's alert date is computed as due date − its own notice period — never a hard-coded 30 days, which is how deadlines quietly get missed in spreadsheets.

62
14
48
Governance

A deviation doesn't just get logged — it gets decided

When a clause departs from the playbook, that's recorded with a severity, and it moves through a real decision path before anyone acts on it.

1
FlaggedRecorded against the exact playbook version that was live at review time — never silently re-graded against a later edit.
2
EscalatedRouted to whoever holds an approval-authority grant matching the severity — a plain grant table, re-derived every call.
3
DecidedAbove "preferred" severity, the decision itself requires a fresh step-up MFA challenge — gated on the action, not just on button visibility.

Recording that a deviation exists and how severe it is, is real and enforced. Automatically finding it in a document's text is not built yet — a person still identifies it.

Everything else that comes with it

The rest of the console

Counterparty 360

Every contract, obligation, and signer tied to one counterparty, on one screen — with bulk amendments for changes that touch a dozen agreements at once.

Ask CLM

A real tool-using agent over your contract data. It can only ever see what you could see through the ordinary UI — the same visibility check runs before every tool call.

Extraction assist

Suggested metadata and obligation candidates, each with the model's own confidence attached — never presented as fact, nothing written until a person confirms it.

Webhooks

Real outbound webhooks, HMAC-signed, delivered off the request path so a slow subscriber never slows down the action that triggered it.

Export & restore

A genuine tenant-to-tenant round trip — decrypted document plaintext and an embedded chain-verification result, not a stub.

Certificate of Completion

A rendered certificate proving this system computed this exact content at this moment — stated as a self-issued attestation on the certificate itself, not an independent trusted timestamp.

Security & reliability

Reliable because it's built to survive being checked

Every durable action writes an entry to a tamper-evident audit chain — each entry cryptographically linked to the one before it.

Chain intact

Per-tenant document encryption

Every tenant's documents are encrypted under their own key, with real rotation mechanics — not one shared key protecting everyone.

Tenant isolation on every query

Every database access runs through one tenant-scoped path — isolation is enforced by the database itself, not every call site remembering to filter correctly.

Idempotent, retried, never doubled

Every vendor call is wrapped in retry-with-backoff and idempotency keys, so a network blip retries safely instead of stamping a document twice.

Step-up MFA where it matters

Approving above "preferred" severity requires a fresh MFA challenge — gated on the action itself, not just whether a button is visible.

Legal hold & retention, enforced

A hold means a document stays no matter what a retention schedule says — enforced by a dedicated deletion executor.

A public, checkable chain

Chain verification isn't a private admin tool — a public endpoint re-walks a tenant's audit chain and confirms nothing has been altered.

Stated plainly

Roadmap

Said outright, the same way the rest of Xirag's product docs work.

Some vendor integrations are mocked, clearly marked as such

Stamping authority, per-tenant key management, and Aadhaar eSign/DSC each sit behind a real interface with a Mock/Dev implementation until the corresponding vendor is empanelled. Everything around each seam — retry, idempotency, certificate attachment, evidence capture — is real and tested; only the vendor call itself is standing in.

No DOCX round-trip, redlining, or negotiation yet

A final contract is stored as an opaque document today. A canonical editable document model, in-app redlining, and templates all depend on that being built first — deliberately deferred until there's a real counterparty document corpus to build it against.

Deviation matching is human-flagged, not auto-detected

Recording that a clause deviates from the playbook — and how severe it is — is real and enforced. Automatically finding that deviation in a document's text is not built yet.

No legacy contract migration or OCR

Bringing in years of existing contracts as searchable, structured records needs a real OCR vendor — that gate hasn't been opened yet.

Every stage, provable. Every step, checked.

One console for the whole lifecycle — not a spreadsheet quietly out of sync with the PDF.

Just need a signature? See Xirag eSign →