Replaces the placeholder agreement stub with the full Stirling Enterprise
Agreement (MSA + Order Form + DPA, one signature), served from a new
versioned legal-document registry, and captures a real signature record.
Versioned legal registry (backend-owned)
- app/saas/.../resources/legal/manifest.json + legal/<id>/<version>/*.md for
the agreement (MSA + DPA), EULA, SLA exhibit and subprocessors, cleaned of
internal counsel markers. Publishing a new version = drop a markdown file +
bump the manifest; no code change.
- LegalDocumentRegistry loads the manifest and fills {{token}} slots.
Agreement rendering + signing
- AgreementAssembler builds MSA + a generated Order Form (Part B, from the
quote) + DPA, filling every token; provider signatory is Matt Joseph, CEO.
- GET /procurement/agreement/document serves the filled markdown; the portal
renders it (react-markdown) with a scroll-to-sign gate and typed legal
name / signatory / title / authority.
- POST /procurement/agreement/sign records an immutable signature pinned to
the document id + version + a SHA-256 content hash + the variable snapshot,
then the flow accepts the quote as before.
Signed PDF
- AgreementPdfRenderer dogfoods Stirling's own Markdown->HTML->PDF path
(commonmark + common FileToPdf/WeasyPrint); resilient — the signature is
recorded even if the render runtime is unavailable, and the PDF is served
from GET /procurement/agreement/signature/pdf when stored.
Storage: procurement_agreement_signature (V38 + Supabase twin). Read-only
pricing accessors added for the Order Form (effective rate/PDF, term
discount %); no billing behaviour change. Pricing reconciliation (25 MB
data-processing model) is intentionally out of scope. Legal text is DRAFT,
attorney-review-required — surfaced with a draft badge.