Per clause, with a timestamp on each.
Forty initials with forty timestamps answer a question a single signature image cannot: what did this patient actually acknowledge, and when.
Each mark is its own row, written once and never updated. A correction is a new document rather than an edit, because a consent edited after signature has destroyed the only thing it was for.

None of these facts implies another.
A document that was sent is a claim that a send returned. It is not a claim that anybody received it, opened it, read it or signed it. Each of those is recorded on its own, and staff see them on their own.
| Recorded | How it is held |
|---|---|
| Each initial | Its own row and its own timestamp, in the order the patient made them. |
| Each election between techniques | The option chosen, timestamped the same way an initial is. |
| Every mark, not only the signature | IP address and browser captured per mark, because a document is contested as a whole rather than one line at a time. |
| The wording | The rendered document is stored with the signature and never re-rendered from the template. |
| The values merged into it | Held beside the wording, so a name or a date corrected later cannot rewrite what was signed. |
| The template version | Stamped on the document, so which wording a patient signed is answerable from the document itself. |
| Opened, completed, voided | Three separate timestamps. A voided document keeps the reason it was voided and stays readable. |
Editable where it should be, fixed where it must be.
Reword a clause and only that clause changes. Everything you leave alone keeps following the standard wording, and keeps improving when the standard does.
- An override changes a clause's text. It cannot change the clause's key, its type or its position in the document.
- It cannot add a clause and it cannot remove one, so a risk disclosure is not deletable through a text box.
- A merge token with no value renders as a visible gap, never as a blank line somebody signs straight past.
- Overrides are resolved when a document is issued. The next patient signs the new wording and the last one keeps theirs.
The patient is not always the only signature.
Patient
Signs through a single-use link that expires. No app, no account, no password.
Witness
A witness block is part of the document rather than a note about it, and carries its own timestamp.
Physician
A countersignature, and the fields a physician completes in the room, are blocks on the same document.
Intake lands on the record as fields, not as a PDF.
What the patient said is kept verbatim and append-only, forever. The current value is written onto the record beside it. So when staff correct a medication or a date later, both facts survive and the record can say which is which.
A skipped question writes nothing at all, which is what stops an intake from blanking something a coordinator typed.
- The provider opens the visit with a composed brief rather than a transcript. It is assembled from the answers, deterministically, with no model behind it.
- A flag is a fact the record holds, never an absence. "No nicotine" prints only where the question was actually asked and answered.
- Ten hair questions, taken from a working hair-restoration intake. Adding a specialty is rows in a table, not a rebuilt form.
- The patient can stop halfway and come back. Answers autosave against the link.
- Outstanding intake separates never opened from opened and abandoned, because one is a message that may not have arrived and the other is a patient who started.
Two things this page will not imply.
A coordinator issues each link from the record. Sending intake automatically by service type, and chasing anything unsigned on a schedule, are not built.
Consent documents run on the demonstration tenant. The database refuses a template or a signed document to a practice until our own agreement covering patient data is in place, which is a fence in the schema rather than a policy in a document. Timing to be confirmed.