Documents & E-Signatures

Uploading Documents

The three upload modes — file into a folder, send for signature, or send a review document — plus accepted file types, size limits, and how plan document limits are counted.

Uploading Documents

Uploading in BookYourPTO has three distinct intents, and choosing the right one matters because they behave differently. The upload page has a mode switch at the top:

ModeUse it when
Upload to folderFiling a document. No signature is requested.
Send for signatureOne or more people need to e-sign it.
Review documentA signed review form that belongs to a performance review.
The (?) beside the page title explains what the selected mode does to the document, and how to switch away from it. The page subtitle names the mode in one line; the detail is behind the question mark.

Mode 1 — Store ("Upload to folder")

Use Store when you just need to file a document — a passport scan, a signed PDF you received elsewhere, a tax form. It goes straight into a folder. No signature is requested.

Accepted files

PropertyValue
File typesPDF, DOC, DOCX, PNG, JPG / JPEG
Max size25 MB
Type checkMagic-byte sniffing — a file's real contents must match its extension

Fields

FieldRequiredNotes
CategoryYesOne of the 13 built-in categories
FolderOptionalA custom folder within the drawer
Expiry dateOptionalTriggers expiry reminders — see below
TagsOptionalFree-text labels for search and grouping

Expiry reminders

If you set an expiry date on a stored document (passport, visa, certificate), BookYourPTO sends reminders at 60, 30, 7, and 0 days before it expires. The reminders go to the document owner (always) plus a role-based audience (admins / execs / HR). This is separate from signing-deadline reminders covered in E-signatures.

Mode 2 — Sign ("Send for signature")

Use Sign when a document needs one or more people to sign it. This launches the recipient + field-placement flow described in detail under E-signatures.

Whose document it is

Every recipient signs the document and finds it in their own documents, but it is filed under one of them: that person owns it, and it belongs on their profile. With more than one recipient, the page asks Whose document is this and offers the recipients you have added. A salary letter signed by a manager and then the employee is the employee's, so choose the employee — it is filed under them whatever order the signatures are collected in.

The person you choose must be one of the recipients. With a single recipient the question does not appear, because the document is plainly theirs. Adding a second recipient asks it, and the document cannot be sent until it is answered.

A document's owner is set when it is sent. Documents sent before this question existed were filed under whoever was added first, and keep that owner.

Accepted files

PropertyValue
File typePDF only
Max size10 MB
Min size1 KB (rejects empty/zero-byte files)
Why PDF-only for signing. Signature fields are placed at exact page coordinates and a certificate page is appended to the finished file. That only works reliably on a fixed-layout format — so signing accepts PDF only, while plain filing accepts the broader Office/image set.

Mode 3 — Review document

Use Review document for a signed review form, a development plan, or a letter that belongs to a performance review. It is the signature flow plus one extra fact: which review the document belongs to. Afterwards it opens from that person's Performance tab instead of having to be found in the documents list.

The mode pill appears only when a review cycle is currently running. With none, the flow would dead-end on its own first question, so it is not offered — see Performance.

It asks four things, in this order:

  1. Review cycle — which review the document belongs to. Only running cycles are offered; a draft, or one whose window has closed, is not.
  2. The document — PDF, same limits as Send for signature.
  3. Recipients — everyone who needs to sign, added exactly as in Send for signature.
  4. Who is being reviewed — which of those recipients the review is about.

The due date is worked out for whoever is being reviewed, from that cycle's schedule — the same date their Performance tab shows. If the cycle does not cover that person, the page says so rather than going blank.

Every review the person is scheduled for counts, not only ones already recorded. A cycle's dates are derived, so an active cycle covering somebody is a real review even with nothing stored against it yet; the record is created as the document is sent.

Who the document belongs to

A review form is routinely countersigned by the department head first and the employee second. Whose review it is and who signs in what order are separate questions:

  • The employee being reviewed owns the document. It appears on their profile and their Performance tab whatever order the signatures were collected in.
  • The signing order is set the same way as on any other document — all at once, or one after another.

The person being reviewed must also be one of the recipients. Ticking I also need to sign this document adds you to the recipients, so you can also be the subject where that is allowed.

With a single recipient there is nothing to decide and the answer fills itself in. Adding a second recipient clears it and asks again, rather than leaving the first person marked as the subject.

Sending a review document follows the same permission rule as the rest of performance: an executive may do it for anyone including themselves, an administrator for anyone except themselves, and a department head for their own department. Who may reach the mode at all is the same as who may send any document — see Roles & permissions below.

Previewing a document

FileWhat you see
PDFThe document, in the browser's viewer
DOCXThe document rendered as pages, in the browser
PNG / JPGThe image
DOC (older binary format)A note that it cannot be previewed, and a download button

Word documents are rendered in your browser — the file is not sent to a conversion service.

The older .doc format predates the current one and no browser can render it. Downloading it works normally, and re-saving it as .docx from Word makes it previewable.

A file that will not open. If a document was truncated while uploading, the preview says so and offers the download rather than showing the browser's own error. If the download is also unreadable, the file did not arrive intact — upload it again.

Deactivated employees

A deactivated employee has no account to sign with, so a signature request to them could never be completed or declined — it would sit in their Action Required for ever. They are therefore not offered as recipients in Send for signature or Review document, and the request is refused if one is sent anyway.

Filing still works. Putting a leaver's final paperwork into their folder asks nothing of them, so they remain available in Upload to folder, and their existing documents stay where they are. Opening such a person from the by-employee view shows them with a Deactivated label.

The same rule applies to Bulk Send: a spreadsheet row naming a deactivated employee is reported as a failed row rather than creating a request nobody can action.

Not the only way to send

Add a document always uploads a fresh file. When the document already exists as a reusable template, use one of these instead — both are linked from the header of the upload page:

RouteUse it when
TemplatesSending a saved template to one or a few people
Bulk SendSending one template to many people from a spreadsheet

Plan document limits

Documents count against your plan's allowance. The counting rule is what trips people up:

  • A single upload counts as 1 (the file) + 1 per recipient (each signer assignment).
  • A bulk send counts 2 × recipients.
PlanDocument limit
Free50
Pro50
Business100
EnterpriseUnlimited
Worked example. Sending one contract to 3 people for signature consumes 4 of your allowance (1 file + 3 assignments), not 1. A 3-recipient bulk send consumes 6.

Security at upload

  • Magic-byte sniffing inspects the actual bytes of the file, so a .exe renamed to .pdf (a spoofed type) is rejected even though the extension looks valid.
  • Once stored, the file is encrypted at rest (AES-256-GCM) and a SHA-256 checksum is recorded — see Overview.

Roles & permissions

RoleUpload to own drawerUpload to others' drawersSend for signature
EMPLOYEEYesNoTo self / as allowed
DEPARTMENT_HEADYesReports / departmentYes (department scope)
ADMINISTRATORYesAnyoneAnyone
EXECUTIVEYesAnyoneAnyone

Troubleshooting

Error / symptomCauseFix
File ended up un-signed when you wanted signatures (or the reverse)Wrong upload modeUse the mode switch; the page subtitle names the active mode, and the (?) beside the title explains it
Review document is not offeredNo review cycle is currently runningCreate one, or re-open an ended one, under Settings → Performance
The page says the cycle does not cover that personThe cycle's scope excludes themCheck whether it is set to everyone, a department, or named people
"Document limit reached"Allowance hit — recipients count, bulk send counts doubleRemove old documents, reduce recipients, or upgrade your plan
File rejected on uploadType/size out of boundsStore: PDF/DOC/DOCX/PNG/JPG ≤ 25 MB. Sign: PDF ≤ 10 MB (≥ 1 KB)
"Invalid file type" despite a .pdf nameSpoofed type — bytes don't match the extensionRe-export a genuine PDF and upload again
Expiry reminders never arriveNo expiry date was set, or document was sent for signature (not stored)Add an expiry date in Store mode