D
Docusign Agreement Manager

Docusign Agreement Manager is the intelligent agreement repository inside Docusign's Intelligent Agreement Management platform, sitting in the manage phase after agreements are prepared and signed. It consolidates executed agreements into a single store and uses AI to turn them into structured, searchable data: extracting parties, dates, financial terms, renewal conditions, termination provisions and governing law, together with custom extractions a customer defines for its own agreement types.

Around that sit reports and AI-generated worksheets for portfolio-level analysis, search across both full text and extracted provisions, renewal and obligation tracking with automation, permissions that control which users reach which agreements, and built-in activity tracking for audit. Docusign agents can be delegated tasks that analyse agreements, follow the customer's policies and work across connected tools, with answers the company says are traceable to cited sources.

The product was previously sold as Docusign Navigator and was built on technology from the company's May 2024 acquisition of Lexion, whose founders met at the Allen Institute for AI; the Lexion entity, DocuSmart Inc., still appears as a named subprocessor for extraction work. The AI itself is branded Docusign Iris and runs across the platform rather than in this product alone. Docusign publishes an unusually complete account of what sits underneath it: the subprocessor list names Azure OpenAI Service and Azure AI Document Intelligence from Microsoft, Google Gemini and Model Armor on Google Cloud Vertex AI, and DocuSmart, each mapped to the specific feature it powers and to the regions in which it runs.

Agreement Manager is included in selected IAM plans rather than sold on its own, alongside eSignature, Contract Lifecycle Management, Agreement Preparation, Workflow Builder, Web Forms, Notary and the App Center, and IAM is sold to sales, customer experience, human resources, procurement and legal departments rather than to legal buyers alone. Docusign, Inc. is a public company listed on Nasdaq as DOCU, headquartered at 221 Main Street in San Francisco, and reports 1.9 million customers.

Vendor siteSan Francisco, California, United States
Last verifiedSeptember 13, 2026
Compare with other vendors

Capability grades

All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.

BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

The models are the engine of a core capability layered on a product that would function without them as a document system, which is the B band. What the AI does here is substantial and named. Docusign Iris drives AI-powered data extractions including custom extractions defined by the customer, AI-generated worksheets for portfolio analysis, and agents that analyse agreements, follow the customer's policies and work across connected tools.

The company describes the current release as the next evolution of Iris, with agents that transform how agreements are managed. What keeps it off A is that the product underneath is a repository. Remove the models and Agreement Manager still consolidates executed agreements into a single searchable store, still runs permissions and audit tracking, still tracks renewals and obligations against dates, and still reports.

The extraction layer converts documents into structured data faster than manual entry did, which is a large improvement to a system that existed before it and not the reason the system exists. The product's own positioning supports that reading: it is sold as the manage phase of a lifecycle whose other phases are preparation, signature and workflow, and it is included in selected IAM plans rather than sold as an AI product in its own right.

Recorded for the history: the capability came in with the May 2024 acquisition of Lexion, whose entity DocuSmart Inc. still appears as a named subprocessor for extraction, and the product was itself called Docusign Navigator until the rename to Agreement Manager. Verified 13 September 2026.

Source: Vendor Published
BB on Citation Accuracy and Hallucination DisclosureGrounding is real and documented, with linked primary sources and a described retrieval method, short of published accuracy figures an outsider can test.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

Grounding is real and documented and no measured accuracy is published, which is the B band. The grounding claim is specific to what this product does: the AI reads the customer's own executed agreements rather than a legal corpus, and agent output is described as traceable to cited sources, so a user can follow an extracted provision or an agent's answer back to the agreement it came from. Around that sit two published quality mechanisms that are more than assertion.

The AI Trust page states that diverse datasets and thorough checks are used to correct skewed outputs and ensure quality before model deployment, which is a pre-release testing statement, and that content filtering is applied for harmful outputs. The subprocessor list independently corroborates part of it by naming Google's Model Armor as an AI security and content moderation service in the IAM stack, which is an unusually concrete disclosure of a safety control.

What is absent is measurement. The AI Trust page states that customers can trust that AI outputs have been tested for accuracy, and no figure, error rate, test set, evaluation or third-party validation is published anywhere for extraction precision, agent answers or worksheets. Third-party write-ups cite a 15 per cent precision advantage over general-purpose models on extraction; that is not published first-party and is not credited.

R15 governs the citator and primary-authority limbs, which do not apply to a product that cites the customer's own contracts rather than law. Verified 13 September 2026.

Source: Vendor Published
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

A written commitment that the models work alongside the customer with a real review surface, short of the full control structure, which is the B band. The commitment is explicit and sits on the vendor's own AI Trust page: the customer has the final say to approve outputs, so they meet the customer's standards. Around it, agents are described as following the customer's policies and returning answers traceable to cited sources, and the product publishes access controls and built-in activity tracking that would let an administrator see what was done.

Those are genuine oversight materials rather than a slogan. What the A band asks for is not published. No mode distinction is described between what an agent may do unattended and what requires approval, no confidence threshold, no statement of when an agent stops or escalates, and nothing on what happens after the system is wrong. That gap matters more on this record than on most in the lane, because the direction of travel is expressly toward autonomy: the company markets agents that do not just find data but take action, delegated complex tasks working across the customer's other tools, and an agentic layer launched at its 2026 user conference.

R124(2) was applied and no qualifying constraint was found: the final-say-on-outputs statement is a general assurance of human review, which R124(2) holds does not substitute for the threshold limb, and nothing attaches a stated boundary to a named agent or tier saying what that tier's output may not be used for. Verified 13 September 2026.

Source: Vendor Published
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

Real deployment evidence with substance, short of the dating and method the A band requires, which is the B band. The evidence is joined in a way this corpus rarely sees: four customer stories are published on the product page itself, each naming the organisation, attaching figures, and quoting a named individual with their title. Catchafire reports approximately 77 per cent less time spent processing agreements and a doubling of contracting capacity across sales and legal, quoted by its Deputy Director of Revenue Operations.

Greater Philadelphia YMCA reports 99 per cent of agreement requests entering through a single digital intake process and 50 per cent less time on initial agreement reviews, quoted by its Senior Vice President of Information Technology. Kindsight reports a sales cycle one week shorter and two to three days saved by its IT team, quoted by its Director of IT. The Law Offices of Mark T. Hurt, a law firm, is quoted by its Chief of Staff.

So named customers and figures are attached to each other rather than floating separately, which is the failure mode on most records. Two limbs of the A band are missing. Nothing is dated: no story states when the deployment happened or over what period the figures were measured. And no method is stated for any figure, so a reader cannot assess what 77 per cent less time was measured against or how. The individual story pages were not opened; under R25 they corroborate a grade that already stands on the product page, and they are what would move this row. Company scale is published separately at 1.9 million customers. Verified 13 September 2026.

Source: Vendor Published
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

Substantive published commitments on confidentiality, short of the full picture on training and silent on privilege, which is the B band. What is committed is contractual rather than promotional. The published Terms define Customer Data as data uploaded to the Docusign Services and deem it the customer's Confidential Information, which pulls it inside a mutual confidentiality regime requiring use solely for the purpose provided, disclosure only on a need-to-know basis to parties under equivalent obligations, and protection using no less than reasonable care.

Where disclosure is compelled by law the receiving party must give prompt written notice before disclosing unless legally prohibited, and must assist in obtaining a protective order where reasonably available. The position on third party model providers is the strongest limb and is answered better here than anywhere else in this corpus: the subprocessor list names Microsoft Azure OpenAI Service, Azure AI Document Intelligence, Google Gemini, Model Armor and DocuSmart, each against the specific feature it powers.

Encryption in transit and at rest is stated on the AI Trust page. Two limbs fail. Training on customer data is not excluded but permitted on a consent that the Terms describe as something to opt out of, which is graded on the training row and is the reason this axis cannot reach A. And privilege and work product are not addressed anywhere located, on a repository built to hold a company's executed agreements and, in at least one published customer story, a law firm's matter workflow.

Retention and deletion for AI inputs were not established; the AI Attachment governing them was not opened. Verified 13 September 2026.

Source: Vendor Published
DD on UPL and Professional Responsibility PostureNothing published on the advice line for a product that produces legal work, including where it is sold to people who are not lawyers.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.

Nothing published on the advice line was located for a product that produces legal work and is expressly sold to people who are not lawyers, which is the D band including its own parenthetical. The parenthetical is the point of this grade and is why R15 does not rescue it. Docusign IAM is marketed by department, with dedicated pages for Sales, Customer Experience, Human Resources, Procurement and Legal, and the published customer stories are led by revenue operations and IT rather than by counsel.

What the AI does for those buyers is legal work by any ordinary description: extracting governing law, indemnification clauses and liability caps; flagging high-risk clauses and recommending alignment to a company standard; and, through agents and the adjacent AI-Assisted Review, redlining and reviewing contracts. Nothing published states what the product is and is not, whether its output constitutes legal advice, whether a lawyer should review an agent's redline before it goes to a counterparty, or who inside a customer is expected to be accountable for it.

No competence or supervision statement was located and no jurisdiction limit is named for the AI. Recorded and expressly not credited, because each answers a different question: the Terms disclaim warranties and provide the service as is, which is a liability position and is graded there; the Legality Guide is a jurisdiction-by-jurisdiction resource on the legal validity of electronic signatures, not on AI output; and the restriction barring customers from using outputs to train competing systems protects the vendor rather than the customer's professional position. Verified 13 September 2026.

Source: Vendor Published
BB on AI Governance and Bias DisclosureA published governance framework with real substance, short of testing results or a named owner.

AI Governance and Bias Disclosure

Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

A published governance framework with real substance, short of testing results and a named owner, which is the B band. The substance is genuine and sits on surfaces built for it: Iris carries its own sub-navigation including an AI Innovation Principles page and an AI Trust page, which is more governance real estate than any other record in this pull. The AI Trust page publishes four capabilities with mechanisms attached rather than adjectives: encryption in transit and at rest; customer control over whether data is used for AI or ML training, with a consent that can be managed and, where given, aggregation and anonymisation before use; the use of diverse datasets and thorough checks to correct skewed outputs and ensure quality before model deployment, plus content filtering for harmful outputs; and a compliant storage and compute platform for data labelling and AI training, described as extensible so the company can adapt to evolving global standards, with the NIST AI framework named.

Naming an external framework and describing pre-deployment testing puts this comfortably above a principles page. Two A limbs are missing. No accountable owner is identified: no individual, committee or function inside Docusign is named as responsible for model behaviour. And nothing is disclosed about what the testing has found, so the correction of skewed outputs is asserted as a practice with no results attached and no statement of whether output is uneven across agreement types, languages or regions.

One access limit is recorded under R5: the page states that broader AI Trust capabilities require contacting a sales representative, so the published set is a summary. The AI Innovation Principles page was not opened and is what would move this row. Verified 13 September 2026.

Source: Vendor Published
BB on AI Safety and Data StewardshipSubstantive published policy covering most of the ground, short of the full set: commonly no named subprocessor list or no stated incident practice.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

Substantive published policy covering most of the ground, short of the full set on retention, which is the B band. Subprocessors are the strongest limb by a wide margin and are dealt with on the Model Supply Chain row as well: a dated list, last updated 11 August 2026, published as a web page and a downloadable document, itemised per Docusign Service so a buyer reads only the IAM section, naming entity, country, the exact feature each supplier powers and a contact address, and extending to eighteen named Docusign group entities and their locations.

Change management around it is real rather than nominal: updates are published to an RSS feed customers can subscribe to, the Data Protection Attachment commits to that mechanism, and customers may object to a new subprocessor by email on stated grounds. Access control and incident practice are both addressed: the Terms provide for prompt written notice before compelled disclosure and for suspension notice, and the Trust Center carries incident reporting, security alert and system status pages.

Encryption in transit and at rest is stated for Iris specifically. What is not established is retention. No retention period or deletion commitment for prompts, extracted provisions or agent outputs was located, and the AI Attachment that would govern it was not opened. Recorded because it cuts the other way and a buyer should weigh it: the Terms reserve Usage Data to Docusign, including insights derived from operation of the services, for purposes including benchmarking, analytics and product development, with disclosure de-identified and aggregated. Verified 13 September 2026.

Source: Vendor Published
BB on AI Liability and RecourseA real published position on liability, short of the full picture: commonly a stated indemnity without scope or caps.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

A real published position on liability, short of the full picture, which is the B band. The position is published in full and is unambiguous, which is more than most records manage, but it runs almost entirely one way. Warranties are disclaimed: the service and any information supplied are provided as is and as available, with all implied warranties of merchantability, fitness for purpose, quality, accuracy and title expressly excluded, and no warranty that the service will be error-free or meet the customer's requirements.

Liability is capped twice over: total liability for any cause of action arising out of the Docusign Services will not exceed the total paid for the service giving rise to the claim in the twelve months preceding the first event, or 100 dollars, whichever is greater, with the same cap restated for the services section and a flat 100 dollar cap during a free trial. Direct as well as consequential damages are disclaimed.

Indemnification runs from the customer to Docusign, covering use of the service, breach of the Terms and the substance of documents uploaded. So a buyer can read the allocation before signing and it is a published, specific and heavily vendor-favourable one. What is missing is anything running the other way on the AI. No vendor indemnity for AI output appears in these Terms; the only vendor indemnity located is an intellectual property indemnity in the supplemental terms for Australian consumers and small businesses.

No insurance is addressed, no service level accompanies the liability position here, and nothing addresses who bears the loss when an extraction is wrong or an agent acts on a mis-read obligation. Enterprise customers contract on a separate Master Services Agreement, which is published in archive form and was not opened. Verified 13 September 2026.

Source: Vendor Published
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

Real integrations exist and are documented, short of the depth the A band describes, which is the B band. The breadth is not in doubt and is unusual in this corpus: the company publishes an App Center for partner and ISV applications, advertises more than 1,000 pre-built integrations, runs a public Developer Center, and lists pre-built MCP connections as a filterable integration category, which is a route into agentic tooling that almost nothing else in this pull offers.

On the product page, integrations and data sharing is a named feature, described as connecting agreement data to existing tools via integrations, APIs and pre-built connectors so agreements are actionable without switching platforms, and a separate feature promises to extend agreement data across vetted tools and AI ecosystems while enforcing governance and security controls. Docusign Connect provides webhook events on envelope state changes.

What the A band requires is depth described: what syncs, in which direction, and what a firm must configure. That was not established from the surfaces read. No individual practice management, document management or matter management system is named as supported on the product page, no direction of flow is described for any named connection, and no configuration prerequisite is stated. The Developer Center and the App Center listings were not opened; under R25 they corroborate a grade that stands on the product page and the published integration count, and they are precisely what would move this row to A. Verified 13 September 2026.

Source: Vendor Published
BB on Deployment Model and Data ResidencyDeployment model is stated clearly with partial residency detail, or residency is offered without the processing location being addressed, or the tenancy model is stated on its own with no residency detail published.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Cloud delivery with region genuinely answered and tenancy not described, which under R38 is B because tenancy and region are co-equal limbs and publishing either clears C. Region is answered with more precision than a residency page alone would give, because the subprocessor list carries it per supplier and per service: Azure cloud hosting for IAM is provisioned in the United States, Australia, Canada, the European Union and Japan; Azure AI Services for IAM in the United States, Canada, the European Union, Australia and Japan; and Google Cloud Vertex AI for IAM in those regions plus Switzerland.

The list also states that applicability depends on data centre location, with EU-provisioned accounts using EU infrastructure subprocessors, and the trust estate states that customer documents are encrypted and stored in the data centre region of the account that sends them. A dedicated data residency page exists. Binding Corporate Rules approved by EU data protection authorities as both processor and controller, plus the EU Standard Contractual Clauses at Modules 2 and 3, give the cross-border position a contractual basis rather than a marketing one.

What is absent is tenancy. Nothing describes whether a customer's agreements sit in a shared or isolated environment, no separation model is published, and no single-tenant, private or on-premises option is offered or refused. Nothing states where inference runs relative to where documents are stored, which is the live question given AI processing is provisioned region by region and separately from hosting. Verified 13 September 2026.

Source: Vendor Published
AA on Security Certifications and Trust CenterCurrent independent attestation with named scope, reachable without a sales call: a trust center carrying reports, dates and the standards actually covered.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

Current independent attestation with named scope, reachable without a sales call, which is the A band met on every limb. The trust centre is a genuine estate rather than a page, with sections for Legal, Alerts, Compliance, Privacy, Security, System Status and a Trust Portal through which certifications and assessments are accessed. The standards are enumerated with versions and years rather than as logos: ISO 27001:2022, ISO 27017:2015 and ISO 27018:2019; PCI DSS version 4.0, with the company listed as a service provider on the Visa Global Registry; SOC 1 Type II and SOC 2 Type II against the AICPA Trust Services Criteria, with annual audits stated to cover all aspects of production operations including data centres; C5 Type II under the German BSI; Australian IRAP at PROTECTED level; DoD IL4 provisional authorisation; APEC Privacy Recognition for Processor; Binding Corporate Rules approved as both processor and controller; and Government of Canada Protected-B. Scope is stated per certification, which is what makes this an A rather than a long list, and it is stated precisely enough to cut both ways: FedRAMP Agency authorisation and GovRAMP authorisation both name Docusign Federal covering eSignature and IAM, so this product sits inside those scopes, while C5 is scoped to the eSignature product and DoD IL4 to eSignature and CLM, so this product does not sit inside those.

Independent verification is reachable without a sales conversation through public registries: the FedRAMP marketplace, the Visa registry, the EU Trusted List via ANSSI, the APEC certificate directory, and the CSA STAR registry, where the annual CAIQ is stated to be publicly accessible for viewing and download. Third-party risk assessments are completed annually under S&P Global KY3P, ProcessUnity and the Shared Assessments SIG. Verified 13 September 2026.

Source: Vendor Published
AA on Model Supply Chain DisclosureThe models underneath are named, their providers identified, where they run is stated, and the vendor commits to notifying customers when any of that changes.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

The models are named, their providers identified, where they run is stated, and the vendor commits to notifying customers when any of it changes. All four A limbs are met, and this is the most complete model supply chain disclosure located in this corpus. The disclosure lives in the subprocessor list, dated 11 August 2026, which is itemised per Docusign Service so the IAM section can be read on its own, and which carries a heading for Artificial Intelligence Suppliers.

Under it, three entries, each mapped to the specific feature it powers rather than listed generically. Microsoft Corporation, Azure AI Services: Azure OpenAI Service for AI extractions in Agreement Manager, AI agents, and AI-Assisted Review for IAM; Azure AI Document Intelligence for AI extractions in Agreement Manager and Agreement Desk AI agents. Google LLC, Google Cloud Platform Vertex AI: Google Gemini for AI extractions in Agreement Manager, Model Armor as an AI security and content moderation service, and Gemini global endpoints for AI-assisted web form creation.

DocuSmart Inc. trading as Lexion, a wholly owned Docusign subsidiary, for AI extractions in Agreement Manager, with its own subprocessor page linked. Each entry states the countries of service provisioning and a contact address. Change notification is committed and operational rather than promised: updates are published to an RSS feed customers can subscribe to, the Data Protection Attachment records that mechanism at clause 7.2, and customers may object to a new subprocessor on stated grounds.

What is not published, and is named so the A is read for what it is: no model version is given for any of the three, so a buyer knows which provider and which service but not which release, and nothing states what any provider may retain. Verified 13 September 2026.

Source: Vendor Published
BB on Commercial TransparencyReal pricing is published for part of the range, with enterprise tiers withheld, or the unit and structure are stated without the figure.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

Real pricing is published for part of the range with the enterprise tiers withheld, which is the B band. The commercial mechanics are published in unusual detail in the Terms and a buyer can read them before committing: subscription plans with entitlement units, automatic renewal unless cancelled at least five business days before the term ends, overage fees billed monthly in arrears at the per-unit rate in the plan, promotional codes applying only to the initial term with renewals at the undiscounted price, payments non-refundable subject to a good-faith consideration of refund requests made within the first thirty days of an annual term, thirty days' advance notice of fee changes, late payment interest at 1.5 per cent monthly, and taxes payable in addition.

The Terms also state that subscription plans may be generally published on the website, and self-serve plans and pricing pages exist for both eSignature and IAM. What holds this off A is that the rate card itself was not read and the product's own position is mixed. Agreement Manager is not sold on its own: the page states it is included in select IAM plans, and offers Explore IAM Plans alongside Contact Sales, so what a buyer pays for this capability depends on which plan carries it and that mapping was not established.

The IAM plans and pricing page at the ecommerce subdomain was not opened, and it is what would move this row to A. Recorded so the grade is read correctly: this is a limit on what was established, not a finding that the vendor withholds the number, and nothing suggests the page is gated. Verified 13 September 2026.

Source: Vendor Published
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Segment coverage is described with real substance and the boundaries are left open, which is the B band. The description is unusually systematic. Buyer segments are addressed department by department with a dedicated page each, covering Legal alongside Sales, Customer Experience, Human Resources and Procurement, plus an IAM Core page and a separate enterprise page. Industry coverage is addressed the same way, with pages for financial services, insurance, real estate, government, healthcare and life sciences, and the regulatory posture behind several of them is evidenced rather than claimed: FedRAMP and GovRAMP authorisations naming IAM support the government segment, 21 CFR Part 11 with an annual independent USDM assessment supports life sciences, and HIPAA support is stated.

Scale is published at 1.9 million customers. Legal buyers are addressed directly, with published material on agentic contract workflows for in-house legal teams and a law firm among the named customer stories. What is left open is the boundary in both directions. Nothing states which agreement types or practice areas the extraction models handle well or badly, and the AI is documented elsewhere as English-first for some extraction paths without that limit being stated on the product surface.

Nothing identifies a customer size floor or a segment out of scope. And the record should be read knowing legal is one buyer among five here rather than the buyer, which is a real difference from the specialist contract tools in this lane and is not a criticism of the product. Verified 13 September 2026.

Source: Vendor Published
Sources on file

6 public documents

The public pages on file for Docusign Agreement Manager, with the recorded signals each one supports and the date it was last read. Open any of them and check the reading against the record.

Pricing

No published figure

  • Docusign does not sell Agreement Manager on its own. It comes bundled into certain Intelligent Agreement Management plans, so what you pay depends on which IAM plan you buy rather than on the repository itself. There are published, self-serve plan and pricing pages for both eSignature and IAM, and the product page points you at them, but it also offers Contact Sales alongside, and larger customers are put onto a negotiated Master Services Agreement instead.
  • The commercial terms behind whatever plan you land on are published in full and are worth reading before you commit, because several of them bite.
  • Subscriptions renew automatically. To stop that you have to cancel at least five business days before the current term ends, or switch off auto-renew in the admin console.
  • You are sold entitlement units, and if you go over them you pay overage fees. Those are billed monthly in arrears at the per-unit rate in your plan and are due immediately on invoice.
  • Payments are non-refundable as a rule. The one softening is that if you cancel an annual plan within the first thirty days you can ask for a refund in writing, and Docusign says it will consider the request in good faith, with no obligation to grant it and an express carve-out if you have made substantial use.
  • If you took a promotional discount, it applies to your first term only. Renewals go back to the full price of the plan you originally ordered.
  • Docusign can change prices, but for existing subscribers a change only takes effect at renewal, and it commits to at least thirty days' notice before altering fees.
  • Billing disputes have a clock on them: raise anything within thirty days of it appearing on your invoice or you lose the right to contest it. Late payment carries interest at 1.5% a month.
  • Taxes are on top of every figure quoted.

Bundled product with published charging mechanics and no separately published rate. Agreement Manager is stated on its own product page to be included in select IAM plans and is not offered as a standalone purchase, so the unit of charge is the IAM subscription rather than the repository. Subscription plans are sold in entitlement units and the Terms state that plans may be generally published on the website, set out in an order form, or offered by email or in-product; self-serve plans and pricing pages exist at the ecommerce subdomain for eSignature and for IAM, and the product page routes to the IAM plans page and to Contact Sales in parallel.

Published mechanics from the Sites and Services Terms: automatic renewal for the same period unless cancelled at least five business days before the end of the then-current term or auto-renew is switched off in the administrative console; overage fees for use beyond purchased entitlement units, invoiced monthly in arrears at the per-unit rate in the plan then in effect and payable immediately on invoice, including pay-as-you-go fees; payments non-refundable, subject to a good-faith consideration without obligation of a written refund request made within the first thirty days of an initial annual term, expressly excluded where records show substantial productive use; promotional codes valid for the initial term only with renewals charged at the original undiscounted price; at least thirty days' advance notice before fees change, with changes to existing plans taking effect only on renewal; billing disputes waived if not raised within thirty days of appearing on an invoice; interest at 1.5 per cent monthly on late payment plus collection costs; fees stated exclusive of all taxes.

Free trials are available, with trial data permanently lost at the end unless a plan is purchased or the data exported, and liability during a trial capped at 100 dollars. Enterprise customers contract on a separate Master Services Agreement.

Confidentiality and data terms: HIPAA support is stated and is configuration-dependent rather than automatic: Docusign supports HIPAA compliance through a signed business associate agreement and correct configuration, and HIPAA is not an independently audited certification in the way SOC 2 is. The signable data instruments that are published are unusually complete. A Data Protection Attachment for Docusign Services governs processing, incorporates Binding Corporate Rules approved by EU data protection authorities as both processor and controller, and incorporates the EU Standard Contractual Clauses with Module 2 applying to controller-to-processor transfers and Module 3 to processor-to-subprocessor transfers, the optional docking clause included and general written authorisation selected for subprocessors. A stated order of precedence puts the Binding Corporate Rules first, then the Standard Contractual Clauses, then the body of the attachment, then its schedules, then the agreement. Clause 7.2 incorporates the subprocessor list by reference and commits to notification of new subprocessors through a subscription mechanism, with an email objection route on stated grounds. Certification behind all of it is extensive and independently verifiable: ISO 27001:2022, ISO 27017, ISO 27018, SOC 1 Type II and SOC 2 Type II, PCI DSS 4.0, C5 Type II, IRAP PROTECTED, DoD IL4, APEC PRP, Government of Canada Protected-B, and FedRAMP and GovRAMP authorisations that name IAM in scope. An annual CSA STAR CAIQ is publicly downloadable from the registry.

Note: Commercial mechanics read from the Docusign Sites and Services Terms and Conditions, last updated 13 January 2025, and product packaging read from the Agreement Manager product page, both on 13 September 2026. entryPriceUsd is null and entryPriceDisplay is empty per R10 and R19, because no figure for this product was established: Agreement Manager is not sold standalone but is stated to be included in select IAM plans, so its price is a function of which plan carries it and that mapping was not read. The row is written under R17 rather than R10 because the published charging mechanics and the existence of self-serve published plans lift Commercial Transparency above D to B, and the mechanical test is that where pricing evidence lifts the axis off the floor a row is owed even with no figure. Recorded so the null is read correctly, because it is not the usual reason: this is not a vendor that hides its numbers behind a sales conversation. The Terms state at clause 4.4.1 that subscription plans may be generally published on the website, self-serve plans and pricing pages exist at the ecommerce subdomain for both eSignature and IAM, and the product page offers Explore IAM Plans alongside Contact Sales. **The IAM rate card was not opened.** That is a limit on this pass rather than a finding against the vendor under R85, and it is the single thing that would move Commercial Transparency to A and put a figure in this row. Enterprise customers contract on a separate Master Services Agreement, published in versioned archive form and not opened.

Legal Signals

What each signal means

A signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.

Confidentiality and Privilege

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Opt out

Training occurs unless the customer turns it off.

Training is on by default with a published mechanism to switch it off, which is this value, and the value turns on a conflict between two of the vendor's own surfaces that R37 resolves. The marketing surface reads as consent-first. The AI Trust page states that data is only used for AI or ML training with the customer's consent, that the customer has the flexibility to manage that consent, and that where consent is given the data is aggregated and anonymised before use.

Read alone, that is an opt-in. The agreement reads the other way. Clause 4.3 of the Sites and Services Terms provides that services using AI are subject to the AI Attachment for Docusign Services, which may include consent to use Customer Data to improve Docusign Services and AI Services, including without limitation to train artificial intelligence algorithms and machine learning models, and then tells the reader how to opt out of that consent by reference to the AI Data Controls Settings guidance.

Consent that arrives with the contract and is removed by a setting is an opt-out, whatever the marketing calls it. R37 rule 1 governs where marketing and the agreement conflict and the agreement wins, which is the same shape as Clio at R43. Two things belong on the record. The control is real and named, not theoretical, and the aggregation and anonymisation qualifier is a genuine mitigation. And the AI Attachment itself, which is the instrument that would settle the scope, is published and was not opened; R43(1) is therefore run but not discharged and a reading could move this row in either direction.

Source: Vendor PublishedTo opt out of this consent, please refer to the AI Data Controls Settings FAQAs of Sep 13, 2026Evidence

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Not addressed

No located public material states how long prompts and outputs are retained.

No located public material states how long prompts, extracted provisions or agent outputs are kept, which is the floor, and the note records precisely why that verdict sits alongside an otherwise strong data estate. What is published concerns protection rather than duration: data is encrypted in transit and at rest when Iris is used, and where a customer has consented to training use the material is aggregated and anonymised first.

Neither is a retention statement. On the contract side the Terms address the end of the relationship in general terms and route personal data handling to the privacy notice and the Data Protection Attachment, and the effect-of-termination clause deals with accrued liabilities and licence termination rather than with the disposal of uploaded content. Nothing states a period, a deletion trigger, or an export or return obligation for the AI material specifically, and nothing states what any of the three named model providers may retain of a prompt or a document sent to them.

The instrument that would answer this is identified and published, and it was not opened: the AI Attachment for Docusign Services is linked from clause 4.3 of the Terms and governs AI Services. That is named here rather than left implicit, because it is the single document that would move this row, and because it also carries the training question graded separately. Recorded and not credited as retention: the Terms reserve Usage Data, meaning diagnostic and usage-derived insights, to Docusign indefinitely for benchmarking and product development, which is a different object from the content this signal covers.

Source: Vendor PublishedAs of Sep 13, 2026Evidence

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Own model, documented

The product maintains its own permission model, documented, requiring the firm to keep it aligned.

A permission model is described as a product capability rather than asserted as a security posture, which is this value. Access controls and audit features are one of the six named features of the product, and the description is functional: the right users are enabled to reach the right agreements through flexible permissions, and built-in activity tracking keeps the account audit-ready. A separate feature statement extends the same idea outward, describing agreement data being made available across vetted tools and AI ecosystems while governance and security controls are enforced, which indicates the permission model travels with the data rather than stopping at the interface.

A screenshot on the product page shows an interface for selecting a level of agreement access for others, so the control is exposed to administrators rather than being configured by the vendor. On the vendor's own side the Terms restrict disclosure of Customer Confidential Information to a need-to-know basis among parties under equivalent obligations. What is not published is the model itself. No roles or permission levels are enumerated, nothing describes how a grant is made, reviewed or revoked, and nothing states whether an account administrator can read agreements they were not granted.

Nothing addresses walls between matters or clients as a legal concept, which is the framing a law firm would need and which matters here because a law firm appears among the published customer stories, though the product's centre of gravity is a company's own agreement portfolio rather than client matters.

Source: Vendor PublishedEnable the right users to access the right agreements with flexible permissionsAs of Sep 13, 2026Evidence

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Notice committed

Terms commit to notice where lawfully permitted. No transparency report located.

The agreement commits to notice before compelled disclosure and adds an assistance obligation, which is this value. Clause 5.3 of the published Terms provides that a party required by law to disclose the other's Confidential Information will give prompt written notice before making the disclosure, unless prohibited from doing so by the legal or administrative process, and will assist the other party in obtaining, where reasonably available, an order protecting that information from public disclosure.

Customer Data is expressly deemed the customer's Confidential Information at clause 4.7.1, so the protection reaches uploaded agreements rather than only account records. Notice before rather than after, coupled with a duty to help obtain a protective order, is materially stronger than the discretionary formulations that dominate this signal. It is not the top value because no reporting obligation accompanies it: no transparency report is published and nothing commits to periodic disclosure of demand volumes.

One qualification is recorded rather than left for a reader to find, because it pulls against the clause above. A separate access and disclosure provision at clause 4.7.2.1 reserves a broader discretion, allowing Docusign to access, preserve or share information where it believes in good faith that doing so is reasonably necessary to investigate or act on possible illegal activity or to comply with legal process, and in situations involving threats to physical safety or violations of its terms, with sharing contemplated to law enforcement, government agencies and courts. That provision carries no notice commitment of its own.

Source: Vendor Publishedgive the other party prompt written notice before making the disclosure, unless prohibitedAs of Sep 13, 2026Evidence
Accuracy and Authority

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Not addressed

No located public material identifies the corpus behind the product’s answers.

No located public material identifies a source corpus, and R15 governs the weight, so the note sets out the position rather than leaving it to inference. This product answers from no body of law. The AI reads the customer's own executed agreements, extracting parties, dates, financial terms, renewal conditions and governing law from documents the customer uploaded, and the vendor's own framing is that the models are grounded in the customer's legal language, counterparty history and policies.

There is therefore no licensed legal corpus whose provenance this signal would ordinarily test, and the vendor is not withholding something its product class implies. What is genuinely unaddressed, and why the value is recorded rather than treated as inapplicable, is the provenance of the training material behind the extraction models. Nothing states what the models were trained on. The question is not academic here: the vendor operates a consent-based programme under which customer agreements may be used for training after aggregation and anonymisation, so at least part of the training corpus is other customers' contracts, and nothing published describes the scope of that pool, how consent is recorded across it, or whether a customer that has opted out nonetheless benefits from models trained on those that did not.

Nothing addresses licensing of any third-party corpus behind the named model providers. The surfaces read on the date shown were the product page, the Iris overview, the AI Trust page, the Terms, the subprocessor list and the certifications page.

Source: Vendor PublishedAs of Sep 13, 2026Evidence

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Not addressed

No located public material addresses whether authority is checked for subsequent history.

No located public material addresses whether authority is checked for subsequent history, and on this product the question does not arise. Nothing in Agreement Manager cites law. The repository holds a company's executed agreements and the AI extracts provisions from them, reports across the portfolio and tracks obligations and renewals; the only citation that occurs is internal, the traceability of an agent's answer back to the clause in the customer's own contract that supports it.

No proposition about the state of the law is produced whose treatment a lawyer would verify in a citator. R15 governs and the limb is recorded as inapplicable rather than failed. One adjacency is named so it is not mistaken for the thing, because it is the closest this product comes to a currency question: extracted provisions such as governing law and renewal terms go stale when an agreement is amended or superseded, and nothing published describes how the repository detects that a later document changes an earlier extraction, or what happens to an obligation the system is tracking when the underlying clause is renegotiated.

That is a data currency question rather than a good-law question and it is not graded here. The surfaces read on the date shown were the product page, the Iris overview and AI Trust pages, the Terms, the subprocessor list and the trust centre certifications page.

Source: Vendor PublishedAs of Sep 13, 2026Evidence

Refusal and Uncertainty Behaviour

What does the product do when the answer is not in the corpus?

Not addressed

No located public material addresses what the product does when it cannot ground an answer.

No located public material describes what the system does when it cannot produce a reliable answer. What the vendor publishes addresses the rate of bad output and the customer's ability to catch it, not the system's behaviour at the moment of uncertainty. On rate: diverse datasets and thorough checks are stated to correct skewed outputs and ensure quality before model deployment, and content filtering is applied for harmful outputs, with the subprocessor list independently naming Google's Model Armor as an AI security and content moderation service in the IAM stack.

On catching it: the customer has the final say to approve outputs, and agent answers are described as traceable to cited sources. Neither says what happens when an extraction is doubtful. Nothing states that the system declines to extract a provision it cannot locate confidently, marks a low-confidence extraction for review, reports that a requested term is absent rather than returning a nearest match, or behaves differently when an agent cannot complete a delegated task.

That gap has weight on this product because of what the output feeds: extracted provisions populate reports, obligation tracking and renewal alerts, so a silently wrong extraction becomes a missed renewal or an untracked obligation rather than a visibly wrong answer a reader would question. Nothing published indicates which way the system errs. The surfaces read on the date shown were the product page, the Iris overview, the AI Trust page, the Terms, the subprocessor list and the certifications page.

Source: Vendor PublishedAs of Sep 13, 2026Evidence

Fabricated Citation Record

Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?

None located

No court order, opinion or disciplinary record addressing fabricated or hallucinated legal citations produced by this product has been located as of the date shown. This is a statement about the public record on that one subject, not a finding about the product, and this signal is not a litigation history.

Searched on 13 September 2026 against the company name, the product name, the AI engine name and the acquired brand, across reporting and trackers covering decisions on AI-generated fabricated citations in the United States and elsewhere. None located. No decision, sanction or disciplinary referral names Docusign, Agreement Manager, Iris or Lexion. Context is recorded because the field searched is now large rather than empty, so the absence was tested against something: reported instances include a first published California appellate opinion imposing a 10,000 dollar sanction and a State Bar referral for briefs replete with fabricated citations, a federal sanction of three litigators from a national firm over five fabricated citations, a show-cause order requiring patent counsel to identify which AI platform produced nonexistent quotations, a Delaware Chancery letter ruling on fictitious citations and hallucinated legal propositions, and an Oregon Court of Appeals notice warning that fabricated authority is grounds for striking a filing and imposing sanctions.

General-purpose assistants rather than agreement platforms are what those accounts describe. Under R119 this signal records fabricated legal citations in filings and nothing else, so no other proceeding involving this vendor would appear here. One point of product context: this product does not generate citations to legal authority, extracting provisions from the customer's own agreements instead, so the exposure this signal tracks is structurally low.

Source: Bar Guidance or Court RecordAs of Sep 13, 2026
Professional Responsibility

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Not addressed

No located public material engages with bar or ethics guidance.

No located public material engages with bar or ethics guidance, in general terms or otherwise. No bar opinion is cited, no rule of professional conduct of any jurisdiction is named, and nothing maps the AI or the agents to the obligations of a lawyer who relies on their output. Nor is professional responsibility engaged generically: no statement was located requiring customers to use the product consistently with their professional obligations, and the Terms restrict use by reference to the vendor's own acceptable use rather than to the customer's duties.

The regulatory engagement that does exist is extensive and runs entirely to data, security and sectoral regimes rather than to conduct: ISO, SOC, PCI DSS, FedRAMP, GovRAMP, DoD IL4, IRAP, C5, HIPAA, 21 CFR Part 11 and the NIST AI framework. Those bind the vendor as a processor, not the customer as a lawyer. The gap is worth naming precisely rather than generally, because of who buys this product. Docusign publishes dedicated material on agentic contract workflows for in-house legal teams and sells IAM to legal departments alongside sales, procurement and HR, so agents that review, redline and draft agreements are being placed in the hands of both lawyers and non-lawyers inside the same customer.

Guidance on where the professional line sits in that arrangement is exactly what a general counsel would want and none is referenced. The eSignature Legality Guide is recorded and not credited: it addresses the legal validity of electronic signatures by jurisdiction, not the use of AI.

Source: Vendor PublishedAs of Sep 13, 2026Evidence

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Not addressed

The product sits inside a lawyer to client fee relationship and no located public material addresses billing, fee or disclosure treatment, with no savings claim published either.

Nothing published addresses what happens to the bill when AI-assisted work takes an hour instead of six, which is the floor. The product's centre of gravity is the in-house side of the relationship, where there is no client bill: the buyer is a company's legal, procurement, sales or HR function managing its own agreement portfolio, and the published efficiency claims are framed as internal productivity, being an 81 per cent faster contract turnaround, a 75 per cent productivity boost and legal teams saving 37 per cent more time on review and risk evaluation.

Those measure the customer's own time rather than time billed onward. The value is not outside-fee-relationship, however, because the product is also sold to law firms and one appears among the published customer stories, so some buyers will use it on client matters and pass the time or the cost on. For those buyers nothing is published: no per-matter record of AI-assisted work is described, nothing marks an extraction or an agent output as machine-generated for the purposes of a bill or a fee note, and no guidance on fee or disclosure treatment appears anywhere.

Recorded and expressly not credited under R21 and R24, because subscription cost is a different object from AI-assisted work: the Terms publish entitlement units, overage fees billed monthly in arrears and per-unit overage rates, which would let a customer attribute platform cost to a period, and say nothing about a client's invoice. All the higher values being false, this is a gap and the summary carries it.

Source: Vendor PublishedAs of Sep 13, 2026Evidence

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

Disclosure pack published

A subprocessor and model provider list plus client facing disclosure material is published or available without an agreement in place.

All three artifacts exist, are published and are forwardable, which is this value and the strongest instance of it located in this corpus. The subprocessor list is current and dated 11 August 2026, published both as a web page and as a downloadable document, and itemised per Docusign Service so a firm reads only the IAM section rather than filtering an undifferentiated list. The model provider statement is not merely present but mapped feature by feature under an Artificial Intelligence Suppliers heading: Microsoft Azure OpenAI Service for extractions, agents and AI-assisted review; Azure AI Document Intelligence for extractions and Agreement Desk agents; Google Gemini for extractions, with Model Armor for AI security and content moderation; and DocuSmart trading as Lexion for extractions.

Each carries the countries of service provisioning and a contact address. The third limb, client-facing material a firm can forward, is satisfied in the form R29's IPRally condition specifies: a published Data Protection Attachment which at clause 7.2 incorporates the subprocessor list by reference and describes the notification mechanism, sitting alongside Binding Corporate Rules approved by EU data protection authorities as both processor and controller and the EU Standard Contractual Clauses at Modules 2 and 3.

So a firm answering a client's AI clause can forward a signed-form data instrument, name every model provider touching the client's agreements, say which feature each powers and in which region, and point to an RSS notification feed and an email objection route for changes. Nothing in the set is gated.

Source: Vendor PublishedAzure OpenAI Service: AI extractions in Agreement Manager; AI agentsAs of Sep 13, 2026Evidence

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Not addressed

No located public material addresses court disclosure or verification certification.

No located public material addresses disclosure of AI involvement in legal work, which is the floor, and the note distinguishes that from the traceability the product genuinely provides. Two features come close and neither is a disclosure instrument. Agents are described as returning answers traceable to cited sources, so a user can see which clause in which agreement supports a given answer; that is provenance for the input, not a record that a machine produced the output.

And built-in activity tracking is published as an audit feature, described as keeping the account audit-ready, which is an access and administration log rather than a record of what the AI did. Neither is presented as something a customer could produce to a third party, and nothing states that either survives export or identifies AI involvement on the face of an extracted provision, a report or an agent-drafted document.

What is absent is everything the higher values describe: no per-matter or per-query record of AI use a customer could produce, no export designed to evidence machine involvement, no certification template, and no guidance on when or how AI assistance should be disclosed. The exposure is real but indirect for this product class: its output is a report, an obligation record or a redline rather than a filing, so the likely forum is a counterparty, an auditor or a regulator rather than a court, and nothing published would let a customer show afterwards which terms in its own agreement record were machine-extracted rather than human-entered.

Source: Vendor Publishedanswers traceable to cited sourcesAs of Sep 13, 2026Evidence
Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 61 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 13, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746